@hypha@cafe.mycelium.locahlo.st what i meant with the first part is that instead of having to attach individual applications you only have to (successfully) attack the SSO provider and then that would allow you access to all the applications connected to it, right?if its only for private use, i.e. there is only one user, then yes, my 2nd point is moot.