Elektrine lite

← Feed

@encthenet@flyovercountry.social

Post #4275648

2026-07-30 19:51 UTC

At a previous work, I implemented a SAML login flow and once I found out how easy the back end is, it really made me wish that more websites would allow you to enter your own SAML provider instead of locking you into the big ones. If you could, I'd likely run my own, but it also would mean that your password manager company could instead be your SSO provider because that's really what a password manager is. They use a normal local auth/master password unlock and approve it. But I can say that none of the big corps want that because it'll add competition. They'd rather have a limited set of big corps that they can colude with to keep competition limited than service their users. > https://flyovercountry.social/users/encthenet/statuses/117010461171912976

Replies (1)

  • @vees@jawns.club 2026-07-30 20:04

    @encthenet@flyovercountry.social As a site owner I'm not going to validate randomauthbox.win just so one or two users can hop on my service. Anything it "attests" to is no more credible than what you write in a form box. What does self-provided SAML SSO provider give you any more than a passkey (hardware or virtual) does?

    Open ##4277866