4 ms·
Authentication is webdev 101. If you can't roll your own you're in the wrong industry. I really can't think of any good reason to hand crucial control of a sit
by new_guy 6y ago
Authentication is webdev 101. If you can't roll your own you're in the wrong industry.
I really can't think of any good reason to hand crucial control of a site over to any third party, much less user authentication where one breach will potentially cost you millions and land you in jail.
The whole business model seems to revolve around being a crutch for people not capable or competent of running their own services.
- tschellenbach 6y agoWell, if you look at how many sites break auth, or something in the login flow... This is clearly not the case for most companies. Auth is definitely simpler than most problems, but plenty of teams get it wrong.
- chickenpotpie 6y ago> I really can't think of any good reason to hand crucial control of a site over to any third party, much less user authentication where one breach will potentially cost you millions and land you in jail. Because Auth0 and other providers have security experts specializing in prevent hacking attempts and there is no way you can do a better job than them unless you make it your full time job.
- yannoninator 6y agoor, you could just do passwordless email auth and not have any security issues whatsoever.
- mynameisvlad 6y agoSure, because “do passwordless emails” is just a snap of the finger away, right? The point is that doing auth properly is hard. Sending an email might be easy, but creating and managing the session in a secure fashion is hard, even if you’re “just doing passwordless email auth”.
- yannoninator 6y ago> Sure, because “do passwordless emails” is just a snap of the finger away, right? uh, yes? https://magic.link/ https://magic.link/ > The point is that doing auth properly is hard... it works just like password reset no? there's not much state with passwordless email auth as opposed to passwords.
- mynameisvlad 6y agoThis whole comment thread is about not outsourcing your user management stack to a third party and your intended suggestion is.... A different third party? I don't think I understand exactly what your argument is.
- yannoninator 6y agoYou said: > Sure, because “do passwordless emails” is just a snap of the finger away, right? And I showed it literally is. The choice is yours to reimplement this authentication system, but in terms of "a snap of the finger away", You can do that, That is all. I've done these type of systems before at scale and it took minutes to do (works just like a password reset mechanism) and it is very trivial. In your original comment above, I think you are projecting this a bit too much.
- chickenpotpie 6y agoTop comment: why would you trust a 3rd party with accounts? Next Comment: Because they are better at security Your comment: Or you can do passwordless yourself and have no security problems Next comment: You can't just do passwordless with a snap of the finger Your comment: Yeah just use a 3rd party You're incorrect about the thread
- mynameisvlad 6y agoOk it’s not just me then. I felt like I was taking crazy pills when reading the replies, and the ones to the sibling comment thread where they pivoted to talking about personal security with magic links when this entire conversation has been about companies implementing user management solutions.
- chickenpotpie 6y ago“Not have any security issues whatsoever” is literally impossible. Passwordless auth is the security equivalent of putting all your eggs in one basket. If someone hacks a users email account, now they have access to your service too. Now I’m pissed that you didn’t let me enable 2fa to prevent that or have multiple secure passwords to isolate the hack to my email. You could have just shelled out the 10 cents it would have cost to have my account in auth0 and prevent all of this with 2fa and fraud detection.
- yannoninator 6y agojust use a fake email? you don't have to use your real email for everything, even google has forwarding addresses. and apple has private/forwarding emails as well, so this is a moot point.
- chickenpotpie 6y agoForwarding email increases risk of being hacked. They only have to get one of the emails to get into my account.
- yannoninator 6y agoSo you hack apple's private forwarding email service right, how would one get in? I've even used G Mail's forwarding email for 6 years and I've never been hacked. If you're concerned about this just use a fake email.
- chickenpotpie 6y agoYou’ve gone off on a personal tangent about how I as a user can increase my security. The topic of discussion was you claimed passwordless security had no security issues and I pointed out possible security issues. An individual can mitigate them, but they still exist
- yannoninator 6y ago
- tootie 6y agoBuilding a form and hashing a password is webdev 101, but go look at the feature set offered by Auth0 or other CIAM platforms. Passwordless auth, MFA, compliance management, customer profiling, workflows, threat detection, analytics. And then think about how much they charge for doing this all for you out of the box versus hiring a dev team and running them forever to support it.