March 2023 Summaries
3 posts from Ory
Filter
Month:
Year:
Post Summaries
Back to Blog
The SSO Wall of Shame is a list highlighting companies that treat single sign-on (SSO) as a luxury feature rather than a fundamental security necessity, often using it as a revenue-generating tool by charging exorbitant prices, as exemplified by Hubspot's 6300% markup. This practice raises questions about the ethics of profiting from essential security features, especially in a climate where security and privacy are paramount. In contrast, the SSO Wall of Fame celebrates companies like Grafana and Sumo Logic that provide SSO without exploiting customers, emphasizing the importance of supporting businesses that prioritize integrity over profit. The challenges faced by startups in differentiating their enterprise pricing tiers are acknowledged, as implementing and maintaining SSO can be costly and complex due to the intricacies of protocols like SAML and the demands of supporting large enterprise clients. The text suggests alternative pricing strategies, such as charging for other enterprise features or basing prices on user numbers, to avoid the negative implications of the so-called "SSO tax."
Mar 30, 2023
643 words in the original blog post.
In recent years, software companies have increasingly adopted strict compliance measures, driven by factors such as security, product development, compliance, and supply chain risk management. A key element in this shift is the Software Bill of Materials (SBOM), which functions like a recipe detailing all dependencies and components in a software product, essential for managing complex software ecosystems and identifying vulnerabilities. With rising cyber threats, companies must prioritize security, often using SBOMs to track and patch vulnerabilities promptly. The U.S. government's 2021 mandate requiring software companies to provide SBOMs for government dealings underscores the importance of transparency and security in supply chains, prompting similar measures globally. SBOMs also enhance product development by ensuring up-to-date, legally compliant components, thereby facilitating better risk management, transparency, and faster time-to-market. Tools like Cosign, incorporated by companies such as BoxyHQ (now Ory), help companies in regulated industries meet these new standards, emphasizing the growing importance of SBOMs in modern software development and security practices.
Mar 22, 2023
717 words in the original blog post.
Open-source companies, which freely offer their software's source code, have successfully monetized their offerings through various business models despite the code being accessible for free. Successful examples such as Elastic, HashiCorp, and RedHat demonstrate how open-source organizations can generate significant revenue. Monetization strategies include soliciting donations, providing paid support or premium care, licensing with different terms for smaller and larger organizations, offering cloud-hosted services, and utilizing the open-core model where the core software is free but additional features are paid. While open-source software is primarily viewed as a development model, these companies have creatively commercialized their offerings without compromising the open-source ethos, allowing businesses to thrive while maintaining community collaboration and innovation.
Mar 13, 2023
986 words in the original blog post.