https://openid.net/wg/connect/
How does OpenID Connect improve security
Public-key-encryption-based authentication frameworks like OpenID Connect (and its predecessors) globally increase the security of the whole Internet by putting the responsibility for user identity verification in the hands of the most expert service providers.
...I have this idea in my head that a cybersecurity company should have more resources than I have to keep things locked up right as a drum? Appearantly not, Okta thinks they can run their company like they’re a school district or startup and thinks they aren’t risking killing the golden goose? One error they made could have been prevented by applying a security standard to Google Chrome… that’s not hard to do or very sophisticated even.
There are a multitude of challenges in running any non-profit, but one that provides higher-touch services like an IdP to other businesses has some particular challenges. With something like Let’s Encrypt, there exists a single set of standards being implemented, and if you don’t like those standards and the way they’re implemented you walk away.
With an IdP, there is a huge amount of ongoing support you have to provide to users. “Why is the ‘aud’ attribute not making it through to this one application?” “Why did my directory sync suddenly stop working and the logs are blank?” and so on.
You would end up effectively needing to run a privately funded foundation, and that would require the political desire within businesses to fund and operate it.
Or do you want to see this as a privately funded enterprise?
Turnkey is harder than you think, though, because authentication, while undifferentiated in general, does get tied up in business logic. A multi-tenant B2C SaaS has different needs than B2B on-prem deployed software, to name just two use cases.
Source: I work for FusionAuth, an auth provider.
One world is based on skill, facts and deliverables. That's the world you're talking about.
Another one is based on bullshit, nepotism and politics. That's the world in which Okta thrives, alongside large consultancies, etc.
Unfortunately your success in the first world doesn't really negate that the second world is also very lucrative, and might be easier to succeed in as long as you don't have much morals.
Who will they replace Okta with? Everyone in security space worth mentioning has been breached - including nation-state agencies.
> Why not just use Microsoft or Google for this...
Didn't Microsoft recently have an egregious security lapse on Azure?
And Google is trying to push their identity products, but they are very far from being mature enough for enterprise needs.
I generally suspect folks making comments like this are really not familiar with the products and their uses.
Most of the folks we see are moving from Firebase rather than Google Identity Platform. Wait, I'm confused. Are they the same thing? https://cloud.google.com/identity-platform/docs/sign-in-user... uses them interchangeably.
Ah, another search turns up https://cloud.google.com/identity-platform/docs/product-comp...
So Firebase auth is built on Google Identity Platform.
I did consult other groups using Google Identity Platform at our company and some things came up:
* SMS / email templates not customizable
* Undocumented user auth rate limiting with hacky workarounds
Otherwise our devs have been quite happy with it. I've primarily settled on it because it already has approval at our org, it's simple, and fairly well documented - especially compared to something like Cognito.> I've primarily settled on it because it already has approval at our org, it's simple, and fairly well documented
Those are great reasons to select a product. If it works for you, it works for you!
> especially compared to something like Cognito.
I was half expecting a new CIAM solution from AWS at Re:Invent. I don't understand why they don't invest more in Cognito. Such an own-goal.
When I read through the details of Microsoft's hacks, it will be talking about some obscure exploit against the security professional that had a background check done of them who uses hardened locked down secure access workstation to do their tasks
https://arstechnica.com/security/2023/09/hack-of-a-microsoft...
There is a difference in the degree of egregiousness. I doubt the average business has better security practices than Microsoft, whereas I'd be pretty confident saying many businesses have better security practices than Okta. What shocks me about Okta's breaches is how easy they would be to prevent from happening if Okta cared just a little.