5 ms·
I really don’t understand why a big company would continue to trust Okta with the most critical parts of their security infrastructure (identity) after multiple
by eigenvalue 3y ago
I really don’t understand why a big company would continue to trust Okta with the most critical parts of their security infrastructure (identity) after multiple huge security breaches. And not just breaches, but ones where the company appears to be dishonest (or at least not very forthcoming) in their responses to those breaches, where they attempt to minimize the severity and their own culpability. Why not just use Microsoft or Google for this, which seem to have better recent security track records and certainly more overall security capabilities? How is Okta still a $10b+ market cap company? I don’t get it.
- emodendroket 3y agoOkta has tie-ins with a bunch of different systems that won't interop normally, right? I think that's a big part of it. Who wants to do their own SAML integration or whatever.
- eigenvalue 3y agoThat makes some sense, but that hardly sounds like a $10b+ value proposition, right?
- faeriechangling 3y agoThe switching costs are immense because you often need to weave their identity stack into all the software you write to allow for single sign on. These companies can milk their customers dry because their customers allow these providers to hold a gun to their head. You can sell a company like this to Broadcom and make megabucks as companies take 5 years to switch away.
- toomuchtodo 3y agoWe need the non profit idp equivalent of Lets Encrypt for this function. Otherwise, the cycle continues (accumulate customers, sell out, shareholders squeeze the customer base, customers churn to new orgs, etc).
- mooreds 3y agoIsn't this by default what governments are doing? The USA has login.gov, etc. Or do you want to see this as a privately funded enterprise?
- afandian 3y agoI’m still sad that Mozilla killed Persona. It had a lot of promise. https://en.wikipedia.org/wiki/Mozilla_Persona https://en.wikipedia.org/wiki/Mozilla_Persona
- TheNewsIsHere 3y agoThe best bet for that right now is something like Keycloak. There are a multitude of challenges in running any non-profit, but one that provides higher-touch services like an IdP to other businesses has some particular challenges. With something like Let’s Encrypt, there exists a single set of standards being implemented, and if you don’t like those standards and the way they’re implemented you walk away. With an IdP, there is a huge amount of ongoing support you have to provide to users. “Why is the ‘aud’ attribute not making it through to this one application?” “Why did my directory sync suddenly stop working and the logs are blank?” and so on. You would end up effectively needing to run a privately funded foundation, and that would require the political desire within businesses to fund and operate it.
- yaleman 3y agoRun your own Kanidm instance for free ^_^
- emodendroket 3y agoHaving dipped my toe in some of this stuff I think it absolutely sounds like a ten-billion dollar proposition to offer a turnkey solution to the problem.
- mooreds 3y agoThat's why there are dozens of startups in the auth space. Turnkey is harder than you think, though, because authentication, while undifferentiated in general, does get tied up in business logic. A multi-tenant B2C SaaS has different needs than B2B on-prem deployed software, to name just two use cases. Source: I work for FusionAuth, an auth provider.
- joering2 3y agoIts politics. Good luck trying to convince someone in larg corp they don't need Oracle with other open source databases out there. There is just too many people in line on both sides that job and salary and bonuses depends on the deals to continue, no matter how terrible, expensive, or useless they are.
- eigenvalue 3y agoSo the person who recommended using Okta after a big process is now too embarrased to admit that they were wrong? Isn't it even worse to stay on a sinking ship?
- joering2 3y agoYou NEVER want to admit you were wrong. See: Donald J. Trump.
- JohnFen 3y agoOTOH, I personally freely and quickly admit when I'm wrong or have screwed up. It's been one of the things that has increased my professional success, because it's an indicator that I'm trustworthy.
- Nextgrid 3y agoThere are parallel worlds out there. One world is based on skill, facts and deliverables. That's the world you're talking about. Another one is based on bullshit, nepotism and politics. That's the world in which Okta thrives, alongside large consultancies, etc. Unfortunately your success in the first world doesn't really negate that the second world is also very lucrative, and might be easier to succeed in as long as you don't have much morals.
- landemva 3y agoLarge corps have site licenses and support, so an additional Oracle instance has minimal cost. Corps that pay by CPU typically will consider alternatives.
- vasco 3y agoThe department that controls changes to this is IT in most companies. Also in most companies, asking IT for anything is the equivalent of writing your requests and pressing delete instead of send. In any big enough company where using Okta makes sense in the first place, the likelihood of decisions being made to minimize bureaucracy or make use of some enterprise discount is way bigger than the decision being made on factors that actually matter like actual security.
- faeriechangling 3y agoI have influence on buying a product like Okta and they’re scaring me away because they… appear to have lower security standards than myself? I don’t sign the dotted line but I could probably veto Okta. I have this idea in my head that a cybersecurity company should have more resources than I have to keep things locked up right as a drum? Appearantly not, Okta thinks they can run their company like they’re a school district or startup and thinks they aren’t risking killing the golden goose? One error they made could have been prevented by applying a security standard to Google Chrome… that’s not hard to do or very sophisticated even.
- sleepychu 3y agoI'm currently implementing some OAuth stuff and reading a lot of RFCs and specifications. Came across this gem which really made me think "I bet I would come to regret writing that one" https://openid.net/wg/connect/ https://openid.net/wg/connect/ How does OpenID Connect improve security Public-key-encryption-based authentication frameworks like OpenID Connect (and its predecessors) globally increase the security of the whole Internet by putting the responsibility for user identity verification in the hands of the most expert service providers. ...
- JohnFen 3y agoYes. That section just screams "you can't really trust this".
- cal5k 3y agoNot only that, but now that Okta has its paws in Auth0 they're doing really shady crap like jacking up rates by 30% on contract renewal.
- libraryatnight 3y agoA lot of companies are locked in from before the incompetence started showing. They're really pushing up against that line where it's worth it for people to move away, though.
- sangnoir 3y ago> I really don’t understand why a big company would continue to trust Okta with the most critical parts of their security infrastructure (identity) after multiple huge security breaches Who will they replace Okta with? Everyone in security space worth mentioning has been breached - including nation-state agencies. > Why not just use Microsoft or Google for this... Didn't Microsoft recently have an egregious security lapse on Azure?
- scient 3y agoNot just one... And Google is trying to push their identity products, but they are very far from being mature enough for enterprise needs. I generally suspect folks making comments like this are really not familiar with the products and their uses.
- nogridbag 3y agoCan you elaborate further on what some of the shortcomings of Google Identity Platform are? Cognito is abandonware, Auth0 and Okta are too expensive, and keycloak requires self-hosting. Google Identity Platform seemed like a decent option.
- mooreds 3y agoDisclosure: I work at FusionAuth, an auth provider. Most of the folks we see are moving from Firebase rather than Google Identity Platform. Wait, I'm confused. Are they the same thing? https://cloud.google.com/identity-platform/docs/sign-in-user-email https://cloud.google.com/identity-platform/docs/sign-in-user... uses them interchangeably. Ah, another search turns up https://cloud.google.com/identity-platform/docs/product-comparison https://cloud.google.com/identity-platform/docs/product-comp... So Firebase auth is built on Google Identity Platform.
- nogridbag 3y agoI was referring from a technical perspective. I agree they have a branding/marketing issue. I did consult other groups using Google Identity Platform at our company and some things came up: * SMS / email templates not customizable * Undocumented user auth rate limiting with hacky workarounds Otherwise our devs have been quite happy with it. I've primarily settled on it because it already has approval at our org, it's simple, and fairly well documented - especially compared to something like Cognito.
- frosting1337 3y agoAnd use... who, exactly? Attackers know the identity provider is the foot in the door, so it'll get attacked no matter who you use.