24 ms·
Writing a SSO system is very hard. They have very high up time requirements and very high security requirements. 1Password might select a different vendor or
by StressedDev 3y ago
Writing a SSO system is very hard. They have very high up time requirements and very high security requirements.
1Password might select a different vendor or self-host an open source or commercial SSO system. Still, there are no perfect answers, and each choice has tradeoffs. Even worse, the new system is not guaranteed to be any better than the old system.
One thing which frustrates me when reading a lot of these posts is a lot of people assume that security is easy, organizations should be perfect, and breaches only occur if an organization or service is terrible. None of these are true.
- m1keil 3y agoTrue, but in this case we are literally dealing with a company that claims they are really good at data security and it is the reason why the users are paying them. It is one thing to outsource a monitoring solution. But outsourcing your SSO to a third party? They can only guarantee how well 1Password works, they cannot guarantee how well Okta works.
- pantulis 3y agoI am also baffled by this. It's not like 1Password doesn't have the chops to roll their own SSO in a secure way specially given that resorting to use Okta puts you just on top of their attack surface.
- clwg 3y agoYou're absolutely correct. Identity and SSO are hard and require a high degree of competency to do well, and they're massively impactful when they go wrong. I think the problem is trust. So the question is, why would 1Password trust Okta?
- smileybarry 3y agoWell, one example of that is Cloudflare, the first Okta customer reported to be hit by that breach, and they literally sell Cloudflare Access, an Okta replacement.