SAML sucks, but it still has a bunch of features for its specific narrow enterprise SSO use-case that OIDC lacks - most notably IdP-initiated flow. OIDC is a constellation of specs with inconsistent support across products, whereas the commonly-implemented subset of SAML is more-or-less stable in its mediocrity.
OIDC will eventually displace SAML, but if you're selling to enterprises you should really support both. Both will pale compared to the amount of time you spend dealing with SCIM inconsistencies between IdPs anyway.
Does Tailscale support SAML? If not: why would any other enterprise product need to? Tailscale is like the sine qua non of modern enterprise products, and I believe it's OIDC-only.
I don't believe it's plausible for any non-specialist firm to implement SAML without grave vulnerabilities. I'm not sure I've ever seen it done well. It's been a minute since I've looked (I haven't consulted in several years, but, more importantly: most firms avoid SAML now), but I'm guessing that assertion still holds.
> Tailscale is like the sine qua non of modern enterprise products, and I believe it's OIDC-only.
I think you're drastically overstating Tailscale's share and ubiquity in the market. Maybe it's heavily represented in tech companies or those in The Valley but among rank and file normal companies not dominated by developers, they've never heard of Tailscale
I think you're wrong about this, that basically every F500 with an access VPN setup has heard of Tailscale, and further, despite their penetration being much bigger than "tech companies in the valley", my point was that Tailscale is a modern business that exists to make (at this point) large amounts of money, and they're not doing SAML.
(It is good that they're not doing SAML, because SAML is the worst security specification ever written, and very few organizations have ever implemented it safely).
There are a lot of smaller providers that will eschew some features, require a fairly limited integration surface (was the case with a lot of things with Slack integration before Teams' COVID explosion, for instance) to keep their support and development costs down
The best estimates I could find have TS at a 1-2% market share. And that was my point: You suggested "well if Tailscale can get away with not supporting SAML, anyone can!" and I think that's wrong. 98% of the market already is buying Tailscale's competitors, they can hardly do worse
I'm sure they can juice that a good deal more, but eventually they'll have to start picking off features that they have been avoiding to this point. Will that be SAML? Maybe not, most companies are on Entra ID which supports OIDC. The real tell will be when Tailscale either goes public or sells to private equity. When their backs are to the wall and they need to squeeze out another percent or two in growth and they have a big customer that must have SAML, then they'll do it
You're overestimating the importance of Tailscale, underestimating the importance of SAML to enterprises and completely skipping over the fact that the customer base that Tailscale has restricted itself to, probably doesn't use SAML to begin with.
Here, I'll share you my thoughts on Tailscale:
I don't use Tailscale. I don't care about Tailscale. I don't know what Tailscale is and I don't really care to know, but I know what SAML is and I know that I will keep using SAML for the foreseeable future, and I know I won't be using Tailscale.
Pretty much every large enterprise (inc. half a dozen non-tech F500s) I've seen in the past 5 years has used either GlobalProtect or AnyConnect. Slightly further down the scale, you start to see some Prisma, Fortinet, or F5 as well. All of them support SAML, and market it as being a key feature.
Personally, I'd love to see Tailscale being deployed more widely, but I've only ever seen it deployed by tech companies.
cameronh90 · · focus · HN ↗
OIDC will eventually displace SAML, but if you're selling to enterprises you should really support both. Both will pale compared to the amount of time you spend dealing with SCIM inconsistencies between IdPs anyway.
tptacek · · focus · HN ↗
I don't believe it's plausible for any non-specialist firm to implement SAML without grave vulnerabilities. I'm not sure I've ever seen it done well. It's been a minute since I've looked (I haven't consulted in several years, but, more importantly: most firms avoid SAML now), but I'm guessing that assertion still holds.
mixdup · · focus · HN ↗
I think you're drastically overstating Tailscale's share and ubiquity in the market. Maybe it's heavily represented in tech companies or those in The Valley but among rank and file normal companies not dominated by developers, they've never heard of Tailscale
tptacek · · focus · HN ↗
(It is good that they're not doing SAML, because SAML is the worst security specification ever written, and very few organizations have ever implemented it safely).
mixdup · · focus · HN ↗
The best estimates I could find have TS at a 1-2% market share. And that was my point: You suggested "well if Tailscale can get away with not supporting SAML, anyone can!" and I think that's wrong. 98% of the market already is buying Tailscale's competitors, they can hardly do worse
I'm sure they can juice that a good deal more, but eventually they'll have to start picking off features that they have been avoiding to this point. Will that be SAML? Maybe not, most companies are on Entra ID which supports OIDC. The real tell will be when Tailscale either goes public or sells to private equity. When their backs are to the wall and they need to squeeze out another percent or two in growth and they have a big customer that must have SAML, then they'll do it
imtringued · · focus · HN ↗
You're overestimating the importance of Tailscale, underestimating the importance of SAML to enterprises and completely skipping over the fact that the customer base that Tailscale has restricted itself to, probably doesn't use SAML to begin with.
Here, I'll share you my thoughts on Tailscale:
I don't use Tailscale. I don't care about Tailscale. I don't know what Tailscale is and I don't really care to know, but I know what SAML is and I know that I will keep using SAML for the foreseeable future, and I know I won't be using Tailscale.
"sine qua non" is hubris.
roryirvine · · focus · HN ↗
Pretty much every large enterprise (inc. half a dozen non-tech F500s) I've seen in the past 5 years has used either GlobalProtect or AnyConnect. Slightly further down the scale, you start to see some Prisma, Fortinet, or F5 as well. All of them support SAML, and market it as being a key feature.
Personally, I'd love to see Tailscale being deployed more widely, but I've only ever seen it deployed by tech companies.