3 ms·
Does anyone on the inside know, when people talk about login services being down, what’s the actual technical bottleneck? I’d hope we’re not talking about them
by compumike 2y ago
Does anyone on the inside know, when people talk about login services being down, what’s the actual technical bottleneck?
I’d hope we’re not talking about them simply not having enough CPU to bcrypt_compare() everyone’s passwords as they try to log in…
In-house service-wide rate limits that are too low?
Two-factor auth steps? (Third party providers may be rate limiting?)
Anti-fraud things? GeoIP lookups? Etc
Writing out logs of logins? Some login audit DB?
(Or is it not actually some login-specific service that is down?)
- shermantanktop 2y ago“Login” is such a misnomer. It sounds like a password check (==read) but includes write activities of various kinds and complex can’t-skip logic. It’s the step where the system first sees the user and must establish identity, of course. But it’s also an attractive place for system designers to frontload complex logic that result in cache-priming or context-priming which the rest of the system depends upon. And then there’s DDOS, device status, account status, anti-fraud, throttles, etc.