Additionally, customers have also requested their own private Warrant service deployments/on-prem so that's something we may offer more broadly in the future.
Even if you have an On-Prem deployment, if Warrant goes belly up, you're still hosed. Unsupported code is a recipe for disaster. What if it has a critical security vulnerability and it can't be patched? Is it legal to keep the code deployed once the contract expires and can't be renewed?
As a former Security Engineer that worked alongside the SRE team, we would never be able to justify this dependency for a production system. We'd rather build it ourselves or live with the crappier version than deal with a black box that can take down the business.
The flip side of this is an Open Source project. We regularly built around Open Source projects instead of starting from scratch when we could.
Have y'all considered moving to a license like BSL or AGPL for what you're building?
I'll definitely be looking at this for my current project.
That being said, BSL/AGPL looks interesting but I'm not that well-versed in them so it's something we're going to look into more.
Similarly it would behoove you to read on the “relicensing” issues of the last few years. Many companies start small with open source to drive adoption, then discover that business model also explicitly enables others to use the same work and compete in the same space. Much heartache ensues.
If it were a a product you would only merely be at the mercy of the product's source code being securely written. But as a service, you are constantly at the mercy of the entire SaaS organization's security culture. Now you have to worry about every single employee with any access at the SaaS organization getting phished. About every sysadmin at the SaaS organization accidentally screwing up a config that opens up a door into their network. About how hardcore every support person at the SaaS organization is about resisting social engineering. Yeesh, it's exhausting to think about.
You've exploded exponentially the number of things that could go wrong resulting in a security hole. All for what? Nothing, because there's nothing about this product that inherently benefits from a service model technically. There's no large data in the cloud to crunch, nothing from other customers that could benefit a different customer somehow. It ain't napster, it's just authorization. It's a damn simple solved problem and you're making it harder just so you get subscription instead of one time revenue.
If promising your customers your service is secure and/or reliable is in no way a part of your value proposition, this is an ok option, but if it is, you're crazy to put yourself in such a vulnerable position like this
Should products like Gmail, Auth0, Duo, PagerDuty, or Okta not exist because if their infra fails, the business operations would grind to a halt?
if we are taking authz as a need in your org and also a single point of failure for your entire services (as you said in your comment), are you suggesting you would instead build / host your own Zanzibar like authz service, and that your in-house solution would do better in terms of availability than this external solution?
leaving aside how much you'd lose on productivity, I would guess your in-house solution will break more unless you spend a lot of time making that a highly available service (and you'd depend on other SaaS for that as well, which may also break).
An in-house AAA solution.
> and that your in-house solution would do better in terms of availability than this external solution?
It won't go broke and cease to exist nor does it traverse the wild wild west that is the Internet.
I don't understand why this is a SaaS and not just a software product you buy and run on prem. (In terms of business risk, buying this as an on prem product seems perfectly reasonable -- after this startup is bought by someone like Microsoft that can actually guarantee the features will stay around.)
This kind of business sort of makes sense for customers you know having a single sign on sort of like use Google to login but I agree there's big risks for companies.
I probably don't understand a whole lot about it or about how you mitigate those risks or about what people really value there.