Hacker News new | ask | show | jobs
by xenophonf 3301 days ago
You misunderstand: OneLogin is a web SSO implementation, not a password manager. By necessity they have access to customers' authentication services because OneLogin functions as a SAML/OIDC identity provider. It's no different than if you ran AD FS or Shibboleth yourself.