Hacker News new | ask | show | jobs
by grajaganDev 505 days ago
It is outrageous and irresponsible to charge for MFA.

It show a cavalier attitude toward the greater security of the internet.

1 comments

Same for OIDC (and even traditional SAML SSO).

If every stolen or potentially stolen credential was billed to the breached provider at even $100/account*, SSO would become free so fast your head would spin.

Every credential in the provider's DB would be correctly seen as a liability.

* Arguably the number should be higher and contribute to a infosec response, detection, and preventative measures warchest. Though, ultimately, this would probably just enrich cybersecurity insurance firms.

Agreed.

Another example is Microsoft charging extra for enhanced logging. This came to light during the SolarWinds debacle.