24 ms·
Okta and Auth0 Blocking Cuba, Iran, N Korea, Syria, Crimea, Luhansk, Donetsk
- aborsy 4y agoThey probably don’t draw much revenue from those countries anyways. The dollar is pretty expensive there. Well, let’s send a gesture to the relevant customers then (including governments).
- benjaminjosephw 4y agoSo it turns out that when you outsource auth, you also outsource some of the governance on who can access your platform. Isn't access control a set of patterns rather than a service? When did it stop being a core competency of web applications?
- pelagicAustral 4y agoI’m curious to know if there are any oss alternatives for similar services.
- viraptor 4y agoI think you're missing the point of okta. It's not for access control to your specific application. It's for companies to deal with many groups of users and on/off boarding easily. It transforms "Andy is andy@foo on service A, AndyA on service B, aaaandy on service C, maybe has two factor enabled on some of them and hopefully hasn't joined other groups to give them access" into "Andy is andy@company in Okta and we can turn services on/off and set policies as needed".
- mschuster91 4y ago> When did it stop being a core competency of web applications? Turns out, login is surprisingly hard. It will be the first and most important focus point for attackers - SQL injections, DDoS attacks, captchas, griefers intentionally using wrong passwords to lock someone else out... with Okta and other products of its kind, all an application developer needs to do is to check some token. Another huge part is that in the "old" world there was only one player for any kind of centralized authentication: LDAP. While there were and are multiple LDAP server implementations (OpenLDAP, MS AD, Samba and a bunch of smaller ones), only Microsoft's AD has a somewhat comfortable and usable management application - but even that is using old-school Windows UI and you need a MS desktop to manage it. Everyone else? Either use Apache Directory Studio, some barely working web management UI (phpldapadmin, GOsa) or heaven forbid plain LDIF files. In contrast, working with anything of the "modern authentication" solutions is a breeze.
- novolunt 4y ago
- throwaway4good 4y agoWouldn’t these export control rules also apply to Microsoft AD?
- capableweb 4y agoWow, and here I thought Okta had split up their service into US and non-US, like many other big companies, but seems they have not, so now just because the US has some arbitrary list of who can be a user, everyone using Okta needs to follow that... Seems like the laws are a bit outdated and haven't really been updated for a global internet, hope we see some changes in that direction.
- kube-system 4y agoThere’s nothing “outdated” here. The OFAC Controls being applicable to business done over the internet is not an unintended effect.
- Nextgrid 4y agoI think the reason he calls it outdated is the definition of "business" becomes murky when it comes to online services and SaaS companies. Does servicing an HTTP request that appears to come from a sanctioned country (based on unreliable GeoIP data) actually count as "business" for sanctions purposes?
- kube-system 4y agoThe specific prohibitions vary by sanctions program, but there are some that prohibit companies from providing “services” and the answer as to whether that includes SaaS is right there in the name. Companies are required to do due diligence to determine that they aren’t engaged in activities that are sanctioned. GeoIP is less than 100% accurate… but so is comparing first and last names. Unreliable data is not something inherently unique to the internet.
- vertis 4y agoMulti-nationals have to exist in the Venn diagram of laws. Which is problematic in a bunch of scenarios: - US foreign policy (note: I don't really want to stick up for a bunch of the countries/regions on that list). - Chinese (and other countries) with censored internet. - GDPR reaching far further than the EU borders. - Badly written cryptography laws[0] I don't really see a solution to this problem though. It's more of a problem when there is no transparency or ability to provide feedback and move democratic mechanisms toward "correct" solutions. In the case of Okta/Auth0, however they've segmented their business (I use their EU region) they're still at the end of the day a US company with US board and directors. They can make a "service region" that respects EU laws because they don't contradict US laws (mostly), but there is nothing in EU laws mandating offering services to these regions. ¯\_(ツ)_/¯ [0]: https://www.eff.org/deeplinks/2018/09/australian-government-ignores-experts-advancing-its-anti-encryption-bill https://www.eff.org/deeplinks/2018/09/australian-government-...
- myth_drannon 4y agoIt's sad that people in occupied regions of Ukraine are punished twice, by Russian government and by US government too.
- trhway 4y agoNot for long now. Just look at the large military successes Ukraine has achieved in the last few weeks.
- wil421 4y agoI’ve seen videos where captured Russian soldiers are actually conscripts from the contested regions. I would think they have a lot more to worry about than okta authentication.
- rpgfugees 4y ago
- myth_drannon 4y agoYes, so these people will be more isolated and in information bubble of RU. They can't get messages from others to stay out of the streets/work where RU army grabs them and sends them as cannon fodder. From the videos I saw they are just pure cannon fodder for UA artillery positions identification.
- BrandoElFollito 4y agoDepending on the region, this may not be a problem. I (casually) saw that the Russian approval is big (>50%) in the eastern regions, so these conscripts may still be "the good ones" for the population of this region.
- qwerty456127 4y agoThey had plenty of time to move to whatever they prefer - unoccupied territories of Ukraine or legitimate territories of Russia. As far as I know they traveled both ways routinely but returned voluntarily every time.
- ClumsyPilot 4y agoOh, nice, my company is just integrating Okta. Is Cuba still being punished for daring to host Soviet missiles? I think the way we've treated them is really terrible.
- ceejayoz 4y agoAt this point, Cuba is stuck being a chip in presidential politics to win Florida’s electoral votes.
- O__________O 4y agoMeaning if commerce with Cuba was not ban it would be a threat to Florida’s economy?
- hx833001 4y agoMeaning there are many Cuban refugees living in Florida who hate the Communist regime and will not support a President who does not continue the sanctions. No political party wants to lose Florida, therefor politicians have a good reason to continue US policy.
- Sebguer 4y agoFlorida's days of being a swing state will likely be over by the next presidential election. Desantis won by tight margins, but he seems to have done a great job attracting exactly the sort of people who'd vote for him to the state and has consistently worked to gerrymander and restrict voting rights for those who'd vote against him. Crist couldn't even beat Rick Scott for the Senate, and Scott was one of the least popular governors in the country at the time of the election. Edit: It was actually Bill Nelson who lost to Scott in 2018, my bad. Crist has been hiding out as a US Rep in Saint Pete since losing the governor's race to Scott.
- pixel16 4y agoBill nelson ran against Rick scott not charlie christ.
- jhugo 4y agoOne thing I've always been curious about is why the opportunity created by this sort of thing doesn't seem to be taken advantage of. To take Iran as an example: when US sanctions prevent Boeing or Airbus from selling to them, I can understand why Embraer doesn't step in and offer to supply planes, because they are afraid of secondary sanctions affecting their business with the rest of the world. But tech isn't like aircraft production — building a GitHub, Okta or Auth0 clone is a chunk of work but hardly infeasible — hell, most companies routinely built a partial Auth0 clone in-house until not that long ago. Many still do. So why don't we see alternatives pop up that don't block Iran? It's a niche, but you get the whole niche to yourself, and Iran is not a small market. From a legal perspective you would set up somewhere like UAE where they have a good climate for business but regularly do business with Iran, so that part shouldn't be an issue. Network effects are a factor, but when you're blocked from the popular platform, you have a bigger incentive than usual to consider the less-popular one.
- k__ 4y agoThere are alternatives. Problem is, that people think they are a grift.
- pritambarhate 4y agoMost of the time these sanctions are global in nature and various treaties that US has with different countries prevent companies in those countries also doing business with sanctioned nations.
- jhugo 4y agoSanctions are absolutely not global in nature. Iran trades extensively with countries in the region.
- greendesk 4y agoTheoretically, anyone can do that. Why would people in Iran spend money on such a bespoke solution? Anyone who does that has to pay off other people too.
- aljgz 4y ago
- jbverschoor 4y agoDon’t offload authentication to third parties… People didn’t learn their lesson from Facebook etc etc.
- wil421 4y agoI’ll take SSO over manually logging into 8-10 company apps I use. If the team implementing an onprem SSS/IDP solution has deep domain knowledge and sys admin skills go for it. Had issues before and cloud based providers like Okta were much better, IMHO.
- Nextgrid 4y agoIf Windows didn't turn into a shit-show post-Windows 7 I would prefer Active Directory over all of this mess. Log in once with your password or smartcard and that auth magically works across all applications without ever seeing a login screen or dozens of redirects to do the SAML flow, at least for internal tools. For external stuff, SAML/OIDC is kind of a necessary evil I think (I'm not sure if there's anything preventing external tools from interoperating with Kerberos).
- philliphaydon 4y agoWindows 11 is so much superior to 7 in every way.
- Nextgrid 4y agoModern Windows has great improvements at the kernel level and OS internals but both the UI and general direction of the product (more focused on media consumption, services and the “attention economy”) is a massive downgrade.
- wil421 4y agoSheesh the redirects. My HSA bank has the most I’ve ever seen, even Safari screams sometimes about too many redirects. Can you use AD on Chrome in Windows to login to a web app? Would it be for internal apps only?
- mdrzn 4y ago"In support of our customers’ and Okta’s existing contractual obligations with respect to U.S. export control laws, Okta customers are not permitted to access the Okta Service (including the Auth0 Platform) from Cuba, Iran, North Korea, Syria, the regions of Crimea, Luhansk or Donetsk without prior approval from the U.S. Government. This restriction applies even if a User is temporarily visiting any of the aforementioned regions."
- fefe23 4y agoNote how Russia is not on the list.
- dvfjsdhgfv 4y agoI don't understand the reason for that. Somehow it is OK to do business with Cuba which are not threatening anyone but not with Russia that is killing people en masse?
- practice9 4y agoMost still hope for return to "business as usual". Which IMO won't happen this decade, and probably next decade as well. see Roblox, Valve (Steam), Cloudflare, Patreon and many more who didn't leave Russia: https://som.yale.edu/story/2022/over-1000-companies-have-curtailed-operations-russia-some-remain https://som.yale.edu/story/2022/over-1000-companies-have-cur... ^ Not on the same level as IBM working with Nazis, but still morally questionable
- curiousgal 4y agoIf killing innocent people is where you draw the line then you should stop doing business with the U.S. Inb4 cries of whatboutism, no I'm just pointing out the hypocrisy.
- mugivarra69 4y agolow market cap out of those , high reward for okta/auth0. the fact that they use this to showcase their power is abhoring.
- perihelions 4y ago- "The Office of Foreign Assets Control ("OFAC") of the U.S. Department of the Treasury administers and enforces economic and trade sanctions based on U.S. foreign policy and national security goals against targeted foreign countries and regimes, terrorists, international narcotics traffickers, those engaged in activities related to the proliferation of weapons of mass destruction, and other threats to the national security, foreign policy or economy of the United States." That last clause has also encompassed things like Hague prosecutors [0]. If your interpretation of these regulations depends on your assessment of the trustworthiness of the regulator, this is a very relevant datapoint. Imagine major tech companies geoblocking United Nations offices. Is that far-fetched fantasy? [0] https://www.hrw.org/news/2020/12/14/us-sanctions-international-criminal-court https://www.hrw.org/news/2020/12/14/us-sanctions-internation... ("US Sanctions on the International Criminal Court")
- atemerev 4y agoE.g. United States have withdrawn their signature from International Criminal Court and will refuse (and actively oppose) being bound by ICC sanctions.
- collegeburner 4y agogood. America answers to no one save herself.
- atemerev 4y agoAbsolute hubris corrupts absolutely.
- guelo 4y agoI am generally pro-regulation in my politics (police for the rich and powerful) but I agree that the power can be and is often abused. Just like regular police, firewalls should be built to prevent politicians from abusing regulations for political purposes.
- imwillofficial 4y agoAnd so the fractured internet continues apace
- nickfromseattle 4y agoI run a USA based SaaS and was mistakenly caught up in Auth0's 'sanctions'. 0. Production servers deleted 1. No logs, notifications or any indications of the issues 2. Can't get ahold of support on the free plan 3. Spend 1-2 weeks frantically trying to restore access to our customers 4. Find a random Auth0 support thread of someone who had the same issues 5. Auth0s response was to submit an affadavit to their legal team indicating I'm not sanctionable 6. Access restored after ~3ish weeks of downtime Why was my SaaS caught up in sanctions? I had a Russian developer deploy Auth0 two years ago (and hadn't logged in for 18+ months) That was enough to get my production servers deleted with no warning.
- qwerty456127 4y agoAutomated enforcement is evil and must be banned (except in situations when the violations themselves mostly are automated and come in unbearably huge quantities).
- pjc50 4y agoBanning automated enforcement is also the end of free and maybe even cheap services on the Internet.
- qwerty456127 4y agoOkay, I don't mind. I am not rich but I would agree to double and triple on my internet subscription if the Internet would be made significantly better (scarce and exclusively curated non-intrusive ads, no tracking, no DRMs, no forced/nudged "engagement", no automated enforcement, no paywalls, everything easy to download and or syndicate, etc.). In fact I would already pay Google and Facebook if they would seriously stop treating me as a product and would consider me a client whom they would act in best interest of. Yet they don't even offer, even those who actually pay them get blackholed routinely. I understand there are poor countries where people really can't pay so I don't insist the business model has to change for everybody everywhere.
- 4y ago
- chinathrow 4y agoSo here's a good reminder for devs/startups on their free plans (I am using Auth0 on their free plan): - Have a copy of all your users e-mail within your own infrastructure (DB) - Have proper backups in place - Verify regularly that your backups function correctly (backup AND restore) In case your account get's deleted, you can rebuild from these.
- mkl95 4y agoTangentially related, but lately Okta's sales people are cold messaging random engineers on LinkedIn with spammy garbage. Fix your OKRs
- antonyh 4y agoMy view on this from the United Kingdom: I have no vested interest in any of the territories listed nor do I support them in any way, but my business should not be subject to the whims of overseas powers and foreign policy. In response to this announcement I've closed down my Auth0 experiments. I refuse to be held to US enforcement when I operate outside US jurisdiction. I know other SaaS will follow suit, but we have to oppose this somehow. As far as I'm aware, the UK does not have any sanctions imposed against Cuba for example, so Auth0's active stance on this is inappropriate for those outside US border.
- tut-urut-utut 4y agoBut isn't Auth0 a US-based company? In that case, they are obliged to implement US sanctions, regardless where their customers are located. That applies of course to any US-based company, so in that case you would need to avoid touching anything that is based in the US. That may be possible in some cases, but if you rely on the third parties, it's almost inevitable to completely avoid US.
- BrandoElFollito 4y ago> so in that case you would need to avoid touching anything that is based in the US This does not change much: a, say, French company is bound to follow US regulations anywhere (including in France, not to mention abroad) because the US would punish any interests of this company in the US. This was the case with Iran, and with others. If you are mid-to-small compared to the US/China, you are bullied. If you are very small (like a blog or local newspaper) you may not give a fuck.
- antonyh 4y agoI don't think the French government care much because the EU gives them more bargaining power. If they were bound beyond political pressure then we'd have French or EU embargos against Cuba for the last 60 years. France doesn't stand alone nor does the UK despite leaving the EU, which is why I object to US foreign policy spilling over political borders via internet-based tech companies.
- lakomen 4y agoThe national hate coming from the US is getting out of hand
- cpursley 4y agoI don't get it. If we're insisting that Crimea, Lugansk and Donetsk are Ukraine and the people are Ukranian, then why block/sanction people there who have no control over the situation?
- isbvhodnvemrwvn 4y agoTo make it unattractive to the current occupier.
- tiagod 4y agoAren't companies just going to ban the entirity of Ukraine, due to it being easier than finding out if your clients are connected to Russia or in a Russia-controlled area, resulting in an outcome undesired by the Ukrainian gov?
- _kbh_ 4y agoMy understanding is that the occupied areas of Ukraine generally have Russian telcos come and take over, so it would be as simple as blocking Russia the majority of the time.
- temp-dude-87844 4y agoTwo reasons: - To inconvenience the institutions of the occupier just in that area (Why just there? To avoid removing their incentives to change and to avoid crippling your own companies who provide a service there. If you sanction the occupier fully, they'll double down, perceive it as an escalation, and your own companies will be significantly hurt. They'll find an alternative, and once they do, they won't need your service any longer, so you lose leverage.) - To frustrate the local populace so that even the milder ones have additional incentives to oppose the occupying regime.
- geraneum 4y agoImagine if Russia occupies Ukraine by force. Following this logic, Ukrainians should now be persuaded (punished) so that they they find the will (as if they don’t already have it) to throw Russia out. The same people that we are helping and sending money and weapons to right now.
- throwawayacc2 4y agoAt the start of this year, I was in Cuba. While in Cuba, I opened my bank app to check my balance. Just that, not to make any transactions. I am a EU citizen. I only have EU bank accounts. The app I used was of a EU bank. There are no EU sanctions against Cuba at this time or at the time I was there. I also have no relation to the USA, I was never there or have business there. A few days after opening my bank app ( again, read only, no transaction ) I received a threatening email from my EU bank saying I might be in violation of sanctions and it is prohibited to use the bank in a list of jurisdictions ( basically the ones mentioned in the post minus the last thee ) and the bank reserves the right to terminate my account. As you can imagine, this was very concerning. Fortunately nothing came of it. But still, I find it ridiculous the bank threatened to close my account just for being in a country that, at least for the jurisdictions that concern me, is a normal country. I have no doubt this was an automated message. The only thing that prevented my bank account from being terminated was the suspicious activity flag triggered the email handler and not the delete account handler. I find this to be utterly dystopian.
- Melchori 4y agoDo you know that or do you assume that? There are global trade and sanction contracts between USA and eu fyi and the financial sector is even more strongly regulated.
- cmrdporcupine 4y agoOn the Cuba issue specifically the EU and Canada many years ago basically told the US to "f off." Way back in the 90s in the beginning of the Helms Burton act days. I know the US occasionally makes threatening but unenforceable noises, but I'm pretty sure the EU drew a firm line on US overreach on Cuba. The mechanisms behind the US trade blockade of Cuba are considered to breach the sovereignty of other nations. (As a Canadian I've been to Cuba many times with no issues; however a friend's father worked for a nickel mining company and spent time there overseeing their operations in Cuba and he can no longer travel to the US among other things.)
- 4y ago
- jbirer 4y agoThat just hurts the businesses and people who're trying to find a way out of there. Okta and Auth0 will not be used by rogue state actors.
- SaintSeiya 4y agoI'm a victim of communist Cuban regime and won't name here all my family has to suffer and endure under that system. People, companies and countries should not do business with dictatorial regimes, period. Regardless of any mental justification, is immoral and only support those regimes to continue exploiting and abusing its own people with your aid, greedy businessman. Then you go on with your life hypocritically saying that you care for others and care for the planet and blah blah. You only care for you and your money, you worth nothing.
- npc54321 4y ago[flagged]
- ahelwer 4y agoIt's a pretty easy defense when you look at the alternatives, as in who came before (Batista) and what the alternate-world versions of Cuba look like - it's doing incredibly well compared to other island nations in the Caribbean, despite being isolated from the entire world by the US blockade for the past 70 years. They even made their own coronavirus vaccine! P.S. Fidel is dead, don't know if you've heard.
- smcl 4y agoI think if you want to take part in discussions like this you should either inform yourself a bit beforehand, or enter them with an open mind. Otherwise you’re going to blunder in with clown shoes on and make yourself look like a conservative talk radio show caller
- npc54321 4y ago
- smcl 4y ago(you forgot to switch to your alt for the second comment btw) No you're missing the point. You don't have to choose a side and go to bat for it. You don't have to defend Batista and reject Castro and what he originally wanted for the Cuban people (or vice versa!). You can understand what each side wanted during the conflict, read into what they did and who they were supported by (note: the Cuban population supported Castro). It's not binary - Castro wasn't a universally good person to be worshipped, far from it. That kind of flawless person never exists. Take George Washington (yes yes, whataboutism I don't care). He stood up to the Brits, and kicked the fuck out of them. That's good! As a Brit I can say that's a fucking good thing to have done. And yet we can acknowledge he was a slaver who likely did a lot of shitty things in his life. That doesn't mean the USA is bad - it just shows you can't draw a nice clean good/bad line, it's messier than that.
- lykahb 4y agoThe terrorist state of Russia should be blocked too.
- alam2000 4y ago
- fithisux 4y ago"Pharoah Tutmoses III was the Pharaoh of the Exodus and deleted Moses from the Egyptian history" our new Tutmoses is AUKUS + EU. But the story repeats itself.
- buzzwords 4y agoDoes anyone know Iranians real cyber attack capacities? There are a lot propaganda on both sides. Do these sections even slow them down? (Real question, please don't start a flame wars, I don't want this account to be disabled)