4 ms·
For 99.9% of businesses, don't roll your own auth. Just don't do it. Use an auth service.
by _0o6v 6y ago
For 99.9% of businesses, don't roll your own auth. Just don't do it. Use an auth service.
- dgb23 6y agoI think you are assuming a certain _type_ of business? Most web applications have moderate requirements... 1 code repository, 1 server, 1 database, dozens or maybe hundreds of users. This service is dealing with stuff like OAuth, SAML, two factor, logging, monitoring, scaling and apparently even does authorization (from skimming) and more. In other words, tons of stuff that many businesses don't need or want.
- _0o6v 6y agoThere are certain fundamental security requirements that don't change, regardless of whether you have 10 users or 10m. If you have a breach, you have a breach. Numbers of repos, databases, servers have very little (nothing) to do with the security requirements of storing personal data.
- dgb23 6y agoYes and no. Complexity, source code volume, data volume and amount of users naturally introduce failure states that are not found in a simpler system. They also reduce your facility for reasoning about the whole, and the amount and type of assumptions you are allowed to make. Google, an indie game, a SaaS, or a custom web app shop all have different security engineering requirements, including authentication, often per project. Also outsourcing auth and not having full control over it is not feasible or even allowed for some domains or projects for a multitude of reasons. Not to mention that using an external service has at least a constant complexity cost. That said, these kind of services are definitely worth considering for many. There is something to be said about advantages of specialization and cost-benefit as well. Reliability is not optional for an auth system, and I'm sure these engineers are really good at what they do. However the challenge would rather be convincing business, not engineering.
- dgellow 6y agoIf there is something I would not delegate it’s my authorization/authentication flow. That’s just too much of a risk to depend from an external service for such a critical part of my systems.
- _0o6v 6y agoThis is an attitude that makes absolutely no sense to me. Ask yourself - can I afford to get this wrong? The risk of your home-rolled auth, with all the edge cases and requirements that go with it, vs. outsourcing to a company who's entire reputation relies on doing it properly with an army of experts, running on enterprise-grade architecture, with round the clock support/updates/ops? Are you seriously saying that you can roll your own auth better than Auth0, Fusion etc. can do? And that the hours startups spend on setting it all up vs. an afternoon wiring in an auth-as-a-service provider is time well spent? If you're a small company, don't risk it, don't invest time in it, just buy it it and plug it in and know that it's all enterprise-grade under the hood and you're covered (far more than you could ever afford to be). If you're a big company, and you've done the maths and figure that the risk/effort vs. expense is worth it, fine.
- dgellow 6y agoI don’t need all the features Auth0 offers. And I can for sure implement an auth system, that’s a well known and solved problem since a while.
- pdimitar 6y agoI don't think your parent poster wanted to roll their own auth library. They were disagreeing with using a SaaS for it, that's how I read them at least.