In short
Podcast Summary: Over the Top Auth Strategies (Friends)
Podcast Details
- Title: The Changelog: Software Development, Open Source
- Episode Title: Over the Top Auth Strategies (Friends)
- Description: Dan Moore from FusionAuth discusses modern authentication strategies including magic links, OTP, MFA, passkeys, and password managers.
Key Participants
- Hosts: Jared, Adam
- Guest: Dan Moore (FusionAuth)
---
Episode Overview
In this episode, the hosts and guest Dan Moore engage in a deep and insightful discussion about modern authentication strategies in software development. Dan brings his expertise as an employee at FusionAuth, focusing on authentication, user management, and security solutions.
Introduction
- The conversation begins with light banter among hosts and a guest introduction, transitioning into the main topic: authentication methods.
Guest Background
- Dan shares his background and experience with FusionAuth, emphasizing his focus on customer identity access management and the various authentication protocols he has encountered (OAuth, SAML, OIDC, JOTS).
Main Discussion Points
- Magic Links
- What Are They? A method that allows users to log in by clicking a link sent via email.
- Advantages & Disadvantages:
- Pros: Users are not required to remember passwords, reducing the risk of password-related security issues.
- Cons: Issues with email deliverability and link expiry can frustrate users.
- Real-life Challenges: Users often face problems with corporate link checkers and delayed email receipt.
- One-Time Passcodes (OTP)
- A six-digit code sent to users for authentication.
- Benefits:
- Reduces friction compared to magic links as users can enter the code from any device.
- Avoids some of the issues linked with magic links, such as link expiry and email delivery problems.
- Passkeys
- A new approach that replaces passwords with device-based authentication (utilizing biometrics like Face ID or Touch ID).
- Pros:
- Strong security as they are tied to a specific device and domain.
- Provides seamless user experience once set up correctly.
- Cons:
- Initial user experience can be confusing and inconsistent across different services.
- Certain user demographics may still prefer traditional methods (passwords) over passkeys.
User Experience and Security Balance
- The challenge of balancing security and user experience is central to the discussion. The group addresses how companies can simplify authentication methods while maintaining security integrity.
- Dan emphasizes the importance of offering multiple options for user authentication (e.g., email/password login, social logins, passkeys) to accommodate different user preferences and security requirements.
Developer Insights
- The conversation shifts towards practical advice for developers when implementing authentication systems:
- Build vs. Buy Decisions: Consideration of whether to build an in-house authentication system or leverage existing frameworks and services (e.g., FusionAuth, Auth0).
- Adapting to User Needs: How authentication methods should evolve based on user feedback and changing technology landscapes.
Conclusion
- The episode wraps up with reflections on the evolution of authentication methods and their impact on user experience and software security.
- Dan Moore is encouraged to continue sharing his expertise, and the group acknowledges the ongoing challenges faced in the authentication landscape.
---
Key Takeaways
- Magic Links: Easy to use but can suffer from deliverability issues and corporate email checks.
- OTPs: Provide a more reliable alternative to magic links, albeit still with challenges.
- Passkeys: The future of authentication, offering enhanced security and streamlined user experience, though still facing usability hurdles.
- Diverse Authentication Options: Essential for accommodating user preferences and enhancing the security posture of applications.
- Build vs. Buy: Important consideration for developers when crafting authentication solutions.
---
Additional Resources
- Dan Moore's Blog: [Letters to a New Developer](https://fusionauth.io) (for further insights on development and auth strategies).
- FusionAuth: [FusionAuth Official Site](https://fusionauth.io) (for tools and services around authentication).
Closing Remarks Listeners are encouraged to engage with the hosts through reviews, feedback, and sharing their own authentication experiences. The episode ends with a reminder to explore the various tools discussed for improving software authentication strategies.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:14Welcome to changelog and friends, a weekly talk show about arm wrestling truckers. Thanks, as always, to our partners at Fly, the public cloud with push-button deployments scaling to thousands of instances. Learn all about it at fly.io. Okay, let's talk auth.
0:41Well, friends, before the show, I'm here with my good friend, David Hsu, over at Retool. Now, David, I've known about Retool for a very long time. You've been working with us for many, many years. And speaking of many, many years, Brex is one of your oldest customers. You've been in business almost seven years. I think they've been a customer of yours for almost all those seven years to my knowledge. But share the story. What do you do for Brex? How does Brex leverage Retool? And why have they stayed with you all these years? So what's really interesting about Brex is that they are an extremely operational heavy company.
1:14And so for them, the quality of the internal tools is so important. because you can imagine they have to deal with fraud. They have to deal with underwriting. They have to deal with so many problems, basically. They have a giant team internally, basically just using internal tools day in and day out. And so they have a very high bar for internal tools. And when they first started, we were in the same YC batch, actually. We're both at Winter 17. And they were, yeah, I think maybe customer number five or something like that for us. I think DoorDash was a little bit before them, but they were pretty early.
1:42And the problem they had was they had so many internal tools they needed to go and build, but not enough time or engineers to go build all of them. And even if they did have the time or engineers, they wanted their engineers focused on building external physics software because that is what would drive the business forward. Brex mobile app, for example, is awesome. The Brex website, for example, is awesome. The Brex expense flow, all really great external physics software. So they wanted their engineers focused on that as opposed to building internal CRUD UIs. And so that's why they came to us.
2:12And it was honestly a wonderful partnership, but it has been for seven, eight years now. Today, I think Brex has probably around a thousand Retool apps they use in production, I want to say every week, which is awesome. And their whole business effectively runs now on Retool. And we are so, so privileged to be a part of their journey. And to me, I think what's really cool about all this is that we've managed to allow them to move so fast. So whether it's launching new product lines, whether it's responding to customers faster, whatever it is, if they need an app for that, they can get an app for it in a day, which is a lot better than, you know, at six months or a year, for example, having to schlep through spreadsheets, et cetera.
2:51So I'm really, really proud of our partnership with Brex. Okay, Retool is the best way to build, maintain and deploy internal software, seamlessly connected databases, build with elegant components and customize with code, accelerate mundane tasks and free up time for the work that really matters for you and your team. Learn more at retool.com. Start for free. book a demo again retool.com we are joined once again by dan moore who we first met because of his awesome blog letters to a new developer what i wish i had known when starting my development career we did that episode with you dan about a year ago now that one's called dear new developer and now you're back welcome back man yeah thanks for having me back thanks for coming adam's also here adam welcome back man i'm so glad to be back i love this show it's so awesome to be part of it you know all those things recovered from your flu uh you know it's all gone you know n-a-c gotta take the n-a-c i don't know what that means uh well if you're a if you're a weirdo you would you would know uh dan laughed so you must know what he's referring to n-a-c i don't i just when I don't know what's going on.
4:10That was a pity laugh, Adam. You've missed us both with this. Not another character? I don't know. What's NAC? It's an acronym, obviously, and I cannot pronounce it, but it's... So there's a lot of speculation in the medical industry because there's a lot of suppression of what will actually heal you and what will not actually heal you. And so NAC is an acronym. I think it stands for... I don't even want to try, honestly but it replenishes your glutathione it's it like zaps a virus pretty quickly okay it's it supports immune health essentially got you so this is a shot you take is this food is it minerals it's a versions of that it's like uh it's a pill you know uh similar to like maybe like magnesium might be like in terms of pill form like that size it's pretty big but it zaps a cold so yeah now you know reduce inflammation zap your cold support your immune health nac check it out awesome also pronounced an acetyl cysteine there you go you didn't want to try it but i didn't want to try it yeah i was like nah jared's not afraid too many letters pronounce things all the time not going there heck on our last news episode i said it was 2024 so i'm not afraid to embarrass myself publicly yeah this is the problem with templates you know you build yourself a template and then you use a template and the template probably supports inter string interpolation or some sort of logic where you could like have the current year but i don't got time for that so i just had it say 2024 and i reused my template and forgot to change one thing well we're back in time it rolled off the tongue too it sounded real good so i just i bet i bet it did you're like yes this sounds familiar oh yeah 2024 yeah Yeah.
6:01Anyways, Dan, you are here to talk auth. So not letters to new developers, but maybe letters for all developers out there. We have a fun conversation teed up and you have some expertise in this area, right? Maybe tell everybody what you do on a day to day, what you're up to. I know authentication, authorization, I don't know what's all involved there, but give us a little bit of your context. Yeah, so I've been for the last about four years, I've been working for an auth provider called FusionAuth. And I've done a variety of roles there. And spend a lot of time talking to customers about how to implement auth, a lot of educational content.
6:40And when I say auth, you know, it's authentication, authorization, and user management. There are some other aspects of the authentication or user lifecycle that we don't really focus on, like identity verification or kind of workforce-oriented stuff. We're much more focused on customer identity access management. So that's my expertise. And that, you know, learned about OAuth and SAML and OIDC and JOTS, you know, basically alphabet soup in terms of jargon. But yeah, I spent a lot of time decoding that and taking it, rewriting it or rewriting my understanding in such a way that developers would actually be able to apply it kind of in their day to day life.
7:27Auth is one of those things that is so interesting. We even use it as a base case for like build versus buy decisions because at its simplest, it's completely a build thing. Like it's a solved problem at its simplest case, right? Totally. But then the thing is, there's this sprawling concern that happens over time with it where just the simple case isn't sufficient over the course of time. And so all these other things come in, SSO, MFA, more alphabet soup. And now you find yourself kind of reinventing lots of little different wheels in order to stay in the build camp on that particular thing.
8:04And this is back in the developer zeitgeist right now because there's been some conversations around Magic Links, one-time pass codes or passwords, pass keys. Yep. Our password's dead. We got excited about pass keys, Adam, you and I, last year speaking with 1Password folks. Is that right? It was. Yes. And didn't actually roll them out for our site, but have been longtime Magic Links users. So I know all the drawbacks of magic links. Yeah. I've hit them all. And I was pretty excited when I implemented them back in 2016 for our website. And, you know, we have not that many people signing in and technical users.
8:49And so it seemed to make sense. But still have hit all kinds of things that are just little. Sand in the gears, huh? A little bit of little friction. Yeah, just like, oh. Yeah. You know, and so ultimately we're all trying to either augment or replace password based auth, you know, because of the security concern. It's just like so prevalent. And I actually want to ask you, like back in 2016, was that the main reason, the main impetus for doing Magic Links was security concerns? Basically, it was like, I can't lose what I don't have. Sure. And I don't have any reason to store your password if I can get away with it.
9:26I had realized, I had this little epiphany. I think other people were starting to realize this as well, that the forgot password flow is what most people end up doing when they don't visit a website very often. And our kind of website is the one where you're not going to visit all the time. Like you're going to come in, you know, subscribe, unsubscribe, comment. Once every couple of years, maybe. Yeah, exactly. And so every time you come back, unless you live in password manager land, which admittedly a lot of our people do, you're doing the forgot password flow anyways. and so what if we just only did the forgot password flow it's just as secure only better because now I don't have to have passwords in my database anywhere ever and there's just nothing I can lose and that was basically the reason and I still like it for that reason but yeah there are all kinds of little like you said sands in the gears that you run into with magic links the most of which for us has been delayed email.
10:22It's just like, even if you get the email right away, it's a little bit slower than a password manager. Enough time for people to be distracted, right? And like, like move away, go back to Hacker News or listening to the changelog or whatever they're doing before. And then they forget why they, why was that on this site? Yeah. It breaks the flow. It does break the flow just slightly, but it really breaks the flow if that email isn't delivered immediately and it's delayed two, three, five. Sometimes, you know, if things get circling up there in the ether and not landing 15 minutes, 30 minutes, now you're basically like, I can't sign into your website.
10:57We've had that issue over time for sure. It's interesting because the bigger issue we've seen around magic links actually is corporate link checkers and expiring the links. and we've gone to some pretty extensive lengths to try to fix that problem. But it's kind of the same kind of thing, right? Like you're doing something that's a little bit out of band and you don't have kind of control over that whole experience, right? Whether it takes a while for the email to be delivered or the email is being read by something else and it's expiring a one-time code or something like that. I actually hit that as well.
11:33What do you guys do about that? We require like a post. So I think we do a JavaScript post of the, so you take, you're taking a page and then the JavaScript on the page executes in posts, which is what actually logs you in. So those link checkers aren't smart enough to do that yet. And so that kind of means that when the user clicks, they're opening a browser and that browser's able to do that post. That's exactly how I handled it as well. I had specifically, I think, Outlook, certain versions of Outlook or maybe Live 365. It's a Microsoft product. We'll pre-click on links for you in order to do malware checks and blah, blah, blah, blah.
12:13And so they would use, just the GET request would use that one-time password. And then you'd hit it yourself and it wouldn't work anymore because it's been used. And I had enough people complain about that over the years. I mean, we've been, it's been nine years. So, you know, we don't have that many Outlook users, but enough where like, I don't want anybody to have a bad experience. And so every time I'm like, I, for a while, I was like, please don't use crap software. No offense. No offense to anybody who uses it, but to the software itself, it's just not good email software. But then I'm like, well, you can't, you can only say that a couple of times.
12:45And then like the sixth, seventh time, I'm like, I got to solve this problem. It can't be that hard. And so it's like, well, I guess I just require JavaScript. You know, I just changed that till you land on the page. And then the page itself does the post and that's what gets you in. And that solved it. But again, one of those little wrinkles that you don't think about until it's deployed out there and people start to complain. So you expired after a bit then you expired after the first click. Is that the common case? Well, it's a one-time magic link. And so once it gets used, you can't, you don't want it to still work.
13:15I mean, you could go in some kind of like slop factor, right? Like let it happen two times or three times, but it is, you know, the entry point is your application and there's definitely some worries around that right so we we definitely ours is still one-time use for sure that makes sense but i mean i think there's an interesting point in kind of what you were saying jared is like you as the authentication system is kind of unique among like like sometimes i think of an authentication system like a database or a queue or something else like that, where it's kind of part of an application and it's foundational, but it's undifferentiated.
13:58And then at the same time, it is so user facing, right? So unlike your data, like you can swap out a database behind changelog if you wanted to, it sounds like it wouldn't be very much fun, but you could do it without ever affecting the user experience. Whereas changing out your authentication system would definitely impact users. and because it's in the user flow, you really need to meet users where they are, right? Like you said the first four or five times, you're like, hey, can you please use different software? And after a while, you're like, well, I really want you to log into my system.
14:29Therefore, I need to be the one to change, right? Like you need to adjust to where the users are coming from. Yeah, absolutely. It's just this balance between optimal security and usability, which is so hard to strike. and because everybody kind of wants to do it their own way. I mean, there's people who are like SSO for life, right? Like, just let me log in with my Google account. I'm actually the opposite. I don't want to use any of that junk. Very much so, yeah. Unless the service specifically connects to a thing. So, like, if I'm going to use a piece of software that's going to use my GitHub account's information in order to augment my GitHub experience, fine.
15:11I'm happy to log in with my GitHub. cal.com right I'm going to sign in with my google account because that's where our calendar is it has to have it anyways but other than those things like I just want to enter my email address and add them you're the same way even so like even with the github whenever you get to that second stage where it says this is what it's accessing I feel like that's just such a weird like if you're listening to github that's a bad page like it needs to it's it's always overwhelming and confusing and I feel like I have no control over what I can and cannot share right just off it's nice that it's there because you can stop and decide versus it just going through for sure but i agree like if you could have check boxes that you could uncheck like you know yeah not granular not granular at all you can see it but you can't control it it's overwhelming all orgs read writes like all this all this access it feels very thick like tail scale i use tail scale and that uses github for a good reason i use github as my I don't know what they call it actually, what their terminology is, but it's not built on my Google SSO.
16:15It's built on a GitHub SSO. So it's built on that auth. And I don't know how to describe it. Like the whole entire tail net is built on my GitHub auth account, essentially. So that makes sense. And giving it access to things might make sense. But at the same time, it's accessing zero repos. It's literally just my network. It's not GitHub related at all. And it's a little annoying, honestly, because now you have access to something else that, you know, it could be your code. It could be different things that matter to you, and you've forgotten what you've given it access to. And it's like, why murky those waters?
16:54Like, it's my repo place. It's where I do open source. It's where I do proprietary code. It's where these potentially sensitive items could be. you know it could be accidentally committing an api key and then now i'm you know that's terrible don't do that but then also like whatever else i've connected to my github account might somehow be able to access it too if there's a fault in the system so adam sorry like i haven't used tailscale myself personally i've read about it but like is it when it when you're logging with github it's prompting you for a bunch of different permissions it's not just saying hey i just want his email address?
17:31Let me log out and see what happens, what it actually accesses, because I just personally find that screen a little overwhelming. Every time I see it, I'm like, okay, this is a lot of stuff. Okay. So now I'm actually on this page. It says authorized tail scale. And at the very top, it says tail scale by tail scale. This wants to access your Adam stack account. It's existing accesses, read org and team membership and read org projects. So I'm like, okay, why do you need to have, like if you just want to off me to Tailscale, why do you need to list my team memberships, my org projects? Like why do you even need to know anything about my GitHub database basically?
18:07So honestly, I wouldn't blame GitHub for that. That's actually on Tailscale because Tailscale asks for permissions. All right, Tailscale, fix this. Yeah, yeah, Tailscale, come on, man. Come on, you don't need all that. Access user email addresses read only. So if I have multiple email addresses in my GitHub account, it's like, well, okay, maybe. And then organization access, and it checks every single org. Every single org. And I can't uncheck it. So my feedback on that is... That is a GitHub thing, though. That's a flow. That's common for everything. It's not just tailscales. Every time I go to some sort of GitHub auth, it's giving me organizational access that I can't revoke.
18:46And all I want to do is auth. Well, and so my guess is that it's probably a combination. I haven't delved deeply into this. It might be the GitHub API too, you know, but that's just how it works. It's like, yeah, how coarse-grained does GitHub allow permissions to be asked for? And then what permissions is Tailscale asking for? And my guess is this happened, like, this is probably a little bit like the Magic Link experience that Jared was talking about, where it started out and Tailscale asked for, like, very small amounts of data. And then there was a use case. And then they needed to ask for a little bit more.
19:14And there was another use case. They needed to ask for a little bit more. And then they can't differentiate between whether you're doing the simple use case where all they need is the email and password or not your password. Sorry, just your email or the complicated one. That's my guess on what happened based on kind of what I've seen over over the years is best of intentions. But GitHub having coarse grained permissions makes it really tough to like ask for just what they need. Right. And sometimes the other strategy, I can, I can rationalize the other strategy, which is like, I don't know, let's just ask for as much as we, we might need it eventually anyways, just ask for more.
19:51And that way we don't have to come back and like re-ask later if we decide we need this thing. And so especially certain people who are like data miners are like, we may need, you know, the other thing about it, just collect all the data. We may need it in the future. That's easy to sell that in a meeting, I think. Totally. For sure. Ask for more than you need. Come back later. Never. Right. I always felt like GitHub auth was, it felt, anything authorized with GitHub, it always felt like whatever was being asked of the authorization process was more than I thought was necessary in the authorization process.
20:23In almost every case. And Adam, your reason of disliking it is actually, I guess, deeper than mine. I'm a simpleton. Mine was just like, I don't want to have to go to every website and think, which provider did I create an account with? Because you end up with like two accounts on different places because you try this, then you try your email and you're like, oh. And so I'm like, if I just use email everywhere, then I never have this problem again. Exactly. That's my basic premise is that. But Tailscale requires you to use an auth provider or some sort of SSO because it hinges your tail net upon that username and how you authenticated.
20:59So in that case, that's where I had to. So I'm by force of SSO with GitHub or like you had said with cow.com, for example, like that totally makes sense. I'm cool with it there. In almost every case, my default is I'm going to email authenticate and password authenticate by default because that's what makes the most sense to me as a user. Because I don't want to ever think like, how did I auth to this? and then I go back to the thing and I'm like I think this actually happened with Neon when we first set up Neon their original flow I believe only had SSO and then when I went back again it had email I'm like okay my default is email because that's how I do it and I couldn't log in I'm like what happened to my Neon account here okay now I can't get in oh yeah I must have authed with GitHub because that's how it originally was you know six months ago when they first roll it off.
21:56But I'm with you. You know, I think that, uh, you ask for too much. The flow is weird. I prefer just to know my email. If it's a work account, it's a work email. If it's personal, it's a personal email. And I keep those words. Well, it's very, there's a lot of people who have one email inbox for all their life. And I'm like, how do you do that? How do you, you know, I may not be an inbox zero guy, but I'm a definitely a segregated and separated inbox based upon disciplines in life or categories in life. Right. I separate the accounts, but I do read all the emails together. So I'm kind of on the fence there.
22:34But I'm also inbox zero, so they're relatively taken care of unless I'm actually behind. Dan, what is your opinion on people saying, well, just knock it off with all this fancy magic links, one-time passcodes, like just email password, like forget the SSOs. If we all just did email password, like the old days, life would be better. What's your opinion on that? I would love if we would do that if everyone was using a password manager. And I think, depending on your audience, that could be a viable path. But for a lot of customer-facing organizations or applications, that's just not reality. My wife is a relatively smart person, has more degrees than I do is not super technical and gets super frustrated with your password manager.
23:28And I have one that I've been using for years that I love that is fantastic, but I would never wish it on anybody else because it's kind of, it's old school, right? So really, it's called a password safe. Mark's not, I think who's the Schneier guy, Bruce Schneier recommends it and it's open source and just kind of super dumb. But it's not like integrated with any external systems because that's the other worry that I have with password managers, like 1Password or LastPass we've seen is they are super valuable targets, right? Because they have everything. For sure. I think you should always offer username and password as an option because I think you're going to have some subset of people who are going to be more comfortable with that.
24:16But I don't think that it should be the only solution. I feel like it's the email of the internet in insofar as that good luck erasing the protocol email from just the way humans do internet totally i say humans because we now have non-humans doing internet we're also good at email yeah they're getting better at email so you're saying passwords not just they aren't going anywhere but you think they shouldn't go anywhere i mean here's the nice thing about a password, right? Like the, the strengths of the password and the weaknesses of the password are very similar. One is that it is something that can be shared really easily, right?
24:57And that can be shared with family or friends, or any costs will be shared, you know, or discovered by an attacker. I think you need to, as someone holding passwords, right? Any of the systems you need to make sure you take care of passwords, you make sure that you hash them appropriately, you make them hard enough to use for an attacker that you can avoid a credential stuffing attacks. Um, but easy enough for users to, to use. And I think that just the reason is that it's, it's lowest common denominator, right? Like I have definitely like tail scale Adam, but this was a different, different company that all they offered was social login.
25:34And that is frustrating to a certain class of people, to a certain set of people who don't want to necessarily tie things to third-party providers, or maybe they don't want you to know that their particular email, they want to use a username, right? You can't use Magic Links with username-based solutions. And for certain kind of sets of folks, right? Like, or even class of applications, like games are a perfect example. Like games don't need to know your real identity. That's a dumb thing. So I don't think they're going away. I think that there are great solutions that you should offer. And each solution you offer kind of increases your marginal kind of market size of people who are willing to kind of log in.
26:20And that includes what we talked about, Magic Links. We talked about social login. I think we're going to talk a little bit about pass keys. And it's a yes and rather than a, you know, we're going to move entirely from this solution to that solution. But certainly bolsters the, I would say the new trend over the last, I don't know, Is it new if it's past five years? I don't think so, but it's newer. I would say over the last five years, you've got like WorkOS. You've got obviously Fusion Auth. You've got Auth0. And I'm sure there's like at least one other major, major brand that I'm totally forgetting right now.
26:58Dan probably knows. Oh, I can give you a list, right? Like, I mean, Keycloak, Clerk, Citadel, Ori. I mean, there's PropelAuth. There's a ton of these folks out there doing that. Totally. So there's not a cottage industry of startups that are well-funded, probably even well ARR'd and doing well. Well, even the IPO didn't Auth0 or Octobah Auth0. Octobah Auth0 for$6.5 billion. So that's past the startup phase. And it was like 20x their ARR. Right. Yeah. So yeah, I mean, from startup to scaled up. Totally. Yes. Yeah. point is is that now it's so complex to do auth that we now need to off load it to a paid service in order to even get it right or to avoid from having our developers waste time building something that's been built and can be serviceable or turn into a service and then it makes more sense to buy it versus build it and mainly it's not because they couldn't build it it's like why would you build it and then the ongoing security security concerns around auth now get offloaded handled by a third party hopefully in quotes trusted or well trusted sure you know and now we've got different places you can get attacked thankfully those players have done pretty well i don't know it just seems like now we got such a complicated situation well you also end up in the same situation with one password and last pass when these providers become huge targets of course they probably have their security teams you know staffed up because if i can hack into okta or fusion auth or whatever it's not just one company's stuff i'm gonna get you know it's like a smorgasbord well so i want to i actually want to push back on that a little bit because and this is one of our kind of unique selling propositions which is the only reason i interrupt adam is that with FusionAuth, you're actually getting dedicated database and compute resources.
29:07So it's totally separate. It's not a multi-tenant solution inside there. How separate is it? Like different locations? It depends, but we can deploy to any of the AWS regions. And you can run it yourself too, right? So you can run it in your own data center. But the idea there is that, you know, if you escape a competitor who has a multi-tenant SaaS, you know, depending on their security posture, you may be able to kind of access other users' systems, but you can't inside FusionAuth because it's like separated. It's a separate database. Yeah. But I do want to talk to, I mean, Adam was talking about like the complexity of it.
Read the full transcript
29:45To me, it feels like the evolution, it's the same evolution as email, right? It used to be, you were sending emails, you stand up like post fix or I don't remember those, you know, send mail. and then SendMail came along and other mail providers came along and email deliverability became a more complex issue. And so it became something that was outsourceable. And a lot of people have made a lot of money doing that. And a lot of apps have been built on top of it. And it's a trade-off, right? And if you are, you know, super bare bones and you're a Linux gearhead and you know how to set up SendMail, you can still get by by doing that.
30:23But the vast majority of the world has changed and people have just acknowledged that it's not worth it. And I think auth is kind of undergoing that transition too. So I agree with that comparison, Dan. Having done both, I can tell you that rolling your own auth is considerably easier than operating a post-fix server with SpamAssassin and these other things on the public internet. Also, there's a step in between. You have, I build my own auth system with my own first party code. And then you have auth providers on the other side. And in the middle, you have open source solutions, which many frameworks tackle this head on because it's hugely valuable and can't have pooled resources there.
31:06So there's a nice middle ground with auth, whereas with email, you're kind of doing it yourself or doing it with somebody else's. Fair enough. Well, friends, you can now build invincible application thanks to Temporal, today's sponsor. You can manage failures, network outages, flaky endpoints, long-running processes, and so much more, ensuring your workflows and your applications never fail. Temporal allows you to build business logic, not plumbing. They deliver durable execution and abstracts away the complexity of building scalable distributed systems and lets you focus on what matters, delivering reliable systems that are faster.
31:42An example of this is Masari. They are the Bloomberg for crypto. They provide market intelligence products to help investors navigate digital assets and they recently turned to Temporal to help them improve the reliability of their data ingestion pipeline. This pipeline collects massive amounts of data from various sources and then they enrich it with AI. This process previously relied heavily on cron jobs and background jobs and queues and the design worked well. However, these jobs were difficult to debug at scale because they needed more controls and more observability. And as they looked to rethink this ingestion flow, they wanted to avoid cron jobs, background jobs, queues.
32:23They didn't want to create a custom orchestration system to oversee and to ensure these jobs and work was being done reliably. Here's a quote. Before temporal, we had to code for dead letter queues, circuit breakers, et cetera, to ensure we were resilient to potential system failures. Now we eliminate these complexities. The headache of maintaining custom retry logic has vanished by using Temporal, end quote. So if you're ready to build invincible applications and you're ready to learn why companies like Netflix, DoorDash, and Stripe Trust Temporal as their secure and scalable way to build and innovate, go to Temporal.io.
33:00Once again, Temporal.io. You can try their cloud for free or get started with open source. Once again, Temporal.io.
33:13So let's go back to Magic Links and talk about OTP because this is kind of, to me, seems like maybe a evolution of Magic Links and an improvement. So the idea here is, is that I'm still going to send you something that you can then confirm that you have. But instead of just making it a link, which in our case, it's like a long, it's not like an MD5 sum, but it's, you know, it's like a hash value that you would not be able to just rattle off. It's shorter and time-based and usually it's six numbers that are provided. And so the one-time passcode is sent to the email or whatever way you can send them.
33:53So you can push notify it or whatever. And there's a click provided, so you can still just click on it and it's just embedded in the URL in that case. Or you can just read these six characters and type it back out and that really solves one particular bummer about magic links is the shareability aspect and the like switching context aspect which a lot of people run into is like hey i'm on my phone i send myself a magic link and i don't have that email app on my phone or there's like all these different weird things where it opens in a app specific browser inside of my email client and so it logs me in inside of Gmail app, but I go back to my other app and I'm not signed in.
34:36Well, with these one-time passcodes, you know, you can solve that by just either copy pasting the six digits or just remembering them for 10 seconds and typing them on the other side. So that seems like a nice evolution. It's like a constantly rotated password, really, right? Like the OTP is constantly like, it's like you set the password every single time and you email it to them and it's time-based. So it's like, that is a cool method i prefer i like that method it doesn't bother me you still have the trappings of it getting to them in an abnormal way versus yeah stored there in their password manager or remembered in their brain like they have to fetch it every single time but at least you're not stuck to like it has to be and if you're dyslexic like i am sometimes i read it backwards i i will misremember I like I will literally read it and have to say one six zero five eight zero like whatever right and I feel like that's also an attack vector because like maybe somebody's sitting next to me and I'm I'm like lightly whispering this password that is only on my screen one six zero five eight zero you know I don't know yeah I always feel uh concerned about that if I'm alone it's just my pup with me my dog then I'm cool with it right but if I'm at starbucks or coffee shot then you could be you could be trying to get me yeah it's a good i mean otps are a great solution for sure i mean they they still share some of the issue with magic links right like in terms of the deliverability um like time frame and a little bit of discontinuity there but um they definitely step around a lot of the the other complexities yeah whether it's like browser-based stuff or the the link checkers or whatnot yeah absolutely so you still run into that stuff.
36:18Pass keys, however, you do not have to send a pass key to somebody every time they have to sign in because it's a pass and hold, right? You get the pass key, you hold the pass key, and as long as you have the pass key, you're good to go. In fact, they are integrated to a certain extent inside of autofills on phones, whether you're on Android or iOS, if you're using the right first party pass key stuff. I'm not sure we're going to get into that because this is where passkeys get weird. It's like, who's got the passkey? But as long as it's in there, like on iOS, for instance, if it's stored inside your Apple passwords app, it will autofill or face ID or touch ID just like your password would.
37:01And so it's instant once you have it there. But it's also complicated. It's more complicated than that, isn't it, Dan? Yeah, I mean, there's definitely, there's a couple of kind of things to think about with passkeys. um one is like how you set them up first of all um kind of the the registration process is a little bit weird and can kind of differ and depending on a pass key it might be tied to a physical device it might be tied to an account um you know if you're worried about people correlating things across like oauth or oidc you know the same thing is happening with pass keys that are shared or if it's device specific, then now you're kind of tied to the device.
37:43And then kind of, I think the user experience is, uh, for actually logging in is pretty good. Um, it does, you don't have as much control as, uh, the, the thing that you're logging into the app you're logging into doesn't have as much control over like the, the look and feel or the messaging or anything like that. And that can be problematic too. But the beautiful things about pass keys are, they are locked down in two ways, right? They're locked down to the device or the system that holds the private key that is actually kind of generating the challenge and like solving the, basically, I can walk through kind of how passkeys work if that'd be helpful.
38:25But anyway, there is a private key that is held someplace. And that is what's used to kind of authenticate you. And they're also locked down to the domain, right? They're associated to a domain, which is really, really great too because it removes all kinds of phishing problems, right? Like because you're trusting the computer to recognize the domain rather than the user looking at the UX or looking at the URL bar. And computers are much better at comparing, you know, character by character and making sure that things are all correct. So there's two kind of security benefits for PASCIs, for sure.
39:00And yet people don't seem to like them for some reason. So... I have had nothing but positive experience with passkeys as an end user. And I should say that my stack is basically Apple stack. I want iOS and macOS. And I use the passwords. It's now its own app. It used to be Keychain and inside the settings of the iOS stuff. But it will handle both your passwords and your passkeys for your domains. and it will even allow you now, I think this is new last year, to share those with your family, which has been, in my experience, seamless as well. I can share a password. I can share a passkey. I can create little subgroups in my family, like just my wife and I, or my kids and us, and I can share them there.
39:53And I have to say, I've been just tickled with how well that's gone, but I think I'm very rare in this, because a lot of people are just not happy with the way things are going. And Adam, you're not sold on passkeys, so what's been your experience? Did you see my title change? Yeah, that's why I said your title is not sold on passkey, so I knew you weren't. I think it's mainly, it's less about the protocol and what the attempt is. It's more the seemingly rogue implementation every single time I experience a passkey scenario. I also find that services are defaulting to passkeys, and it bothers me.
40:33When I want to be a email password person, it's constantly just slapping me in the face like, where's your passkey? And I'm like, nah, man, I'm doing email and password, okay? And it just seems like always want to default to this thing. Adobe does it. I sign into the document cloud a lot for like different agreements and stuff like that. So I'm in there doing stuff frequently. And I like to log into the actual online service. And so I'm logging into Adobe's web services frequently and they, that's their flow. And I'm cool with passkeys. I actually like them except for I think the flow and the way the UX is still implemented seems to be just not the same across the board, whereas email password is pretty much the same across the board.
41:18I feel like that's the holdback for me. And whenever I don't want to be password first or sorry, passkey first that I want to do email password, just anything else, that service is sort of like force feeding me pass keys. And I'm like, you know, nah, man, email password. Okay. Now I do use one password though, as a, to just identify my stack. So unlike Jared, Apple, simple, free, you know, with it kind of thing. And I don't think that's not his only reason for using it. I know Jared well enough. He likes to keep his stack simple and I have to have other extra services if he doesn't want to kind of thing.
41:57And I think that's cool. That's how they use it. That's cool. I use 1Password for a lot more than passwords. Like I've got secure notes in there. I've got like, I mean, I don't want to tell everybody what is my attack vector. It's a lot, okay? Sure, sure. It would be really bad. It would be really bad if 1Password was not a good long-term security solution and they were attacked on my behalf. I use it for more than passwords. So, Adam, I'd love to probe that a little bit more because to me, some of this just may be because of growing pains of passkeys. Usernames and passwords have been around for a long, long time.
42:34And even now, there's still some wrinkles. Sometimes people will ask for your username first, right? And that's so they can direct you to the right identity provider if you're whatnot. But like past keys, it feels like it, you know, they were just codified in like 2019. Right. And so that is not new, but it's still being kind of rolled out. So you think some of us just can get shaken out in terms of like the right UX or. I sure hope so. Like I'm, I'm, I'm long on what it can offer, but I think that. Let me try to define some of the other user flows that have bugged me. And I'm, I think I'm a pretty patient user because I get it.
43:14I'm in this space. I'm not your typical user where I understand where the technology is going. I understand the benefits of pass keys. I understand the implementation for the most part. And so I get it. But what ends up happening is because it's potentially a newer, potentially more secure way to authenticate with a service, they're injecting it where normally it would just be email password. And I would not have any other interruptions in my flows with authenticating. and so now it's like well after i have authenticated with username and password they're like hey do you want to store a passkey no i just want to go through the door and shop i want to get what i came here for right exactly yeah don't ask me do i and don't be secretive about it and and say do you want to authorize next time with your fingerprint or your face id like they hide it or they masquerade it as this not passkey to me that's not masquerading that's actually promoting it in a way that's of a benefit to you because don't you want to wouldn't you rather just face id than your password i don't think so no i i'm explicit you know i like to it's back to that potentially with um and maybe this is where my psychology is with this or the way i'm thinking of it is is because i don't want to think about how did i authenticate with the service and maybe next time it's just so automated because the way one password works the way apple passwords works maybe i won't care but something in me says no adam the way you authenticate is this way and you got to keep it the one way versus like sprinkle your sso's around and then also your potential email and passwords so i'm like nah you know i'll just keep it the way i want to keep it and stop bothering me about paskies i will say to caveat all this is just to give fodder for a conversation because I truly am enjoying it insofar as that I've enabled pass keys usage on my Adobe login.
45:10The flow is kind of weird though, because I would, I will authenticate with the pass key, but the, there's not a good feedback loop. You can't see a spinner. You have to know it's going to authenticate because if you click that, you basically wait two and a half seconds. In my case, it's about two and a half seconds. Then I'm in. It's not a lot of user experience visually to say the passkey is being exchanged something's happening here and so i do authenticate that way and it is pretty magical that i just click one link or just one one interaction essentially and i'm in but it's about three-ish seconds later roughly i didn't want to say like i don't think it's just for security that's the that's not the only reason that that um new orgs or or that passkeys are getting kind of pushed i think it's also a user like they've done studies that it just gets you into the app faster.
46:01There was something I'll share the length, but this person referenced a Microsoft study that said that the average time to log in went from 69 seconds with username and password slash MFA to eight seconds with pass keys. And so if you can get someone into Adobe quicker, especially someone who doesn't like, doesn't have your depth of experience, Adam, right. And like, doesn't really understand kind of the big thing. and they just want to get to Adobe and you can, you know, decrease it by 10 X, that's, that's a big win for everybody. Right. So. I don't know. I feel like my email password logins have been pretty fast.
46:39I will say that 2FA MFA scenarios, slow it down a little bit, adding that into. So one thing I like about one password is that it allows you to 2FA OTP MFA inside of your one password. so you can actually let 1Password do that coding, I suppose, like getting those codes back and forth. And it automates it in its autofill process too, so it's pretty quick to my knowledge. There's times when it's slower. The other cool thing I like about that flow, not that it's better than passkey, I feel like you're going to always have every way to log in. That's why I feel like Fusion Off has such a long game here because you're never not going to have one of these other scenarios.
47:20There probably isn't a silver bullet because you always have all the ways, essentially. But if you have a shared 1Password record, let's just say. So if you have a multi-user 1Password org or an account, and you have a password or an authentication that's shared with somebody else, it could be to a shared email even too. So email password is now shared between two users, but that 2FA, MFA, OTP code that gets manifest on a cycle is inside of 1Password and accessible to all the users of 1Password. This is probably the same with Bitwarden and others too. I'm sure it's a common user experience, but the cool thing is that even with that multi-factor authentication scenario, you have this shared truth, this shared sorts of truth that allows you to authenticate even with these other security measures like OTPs, 2FA, MFA.
48:18I will say that I totally understand the user experience benefits of that. It scares the crap out of me, right? Because the whole point of MFA is that you have a separate, and my guess is one password kind of segregates that stuff inside their own system, right? So that an attacker coming in and getting access to the passwords would have a hard time getting access to the the totps i have a really hard time getting access to my own one password okay like if to to add one password onto a new device i it's not easy it actually makes you think quite a bit it goes against everything steve krug said way way way back in the day with user experiences like don't make me think like no they're making you think i think it's by design like it's really hard to authenticate a new device and sometimes even into itself like the password itself can be very long it can obviously be if you're on a new m mac kind of thing you do your touch uh touch id into which i love i mean i think just touch id authentication one password to me is like the way i mean every linux user bow down to the way it's just now you i mean like maybe you could do that on windows and linux but i just experienced again today and i'm like this is the way okay everyone else has just like lost in comparison to mac os's abilities to do this.
49:35Again, just to push on this a little bit, it doesn't worry you at all that this thing that is supposed to be a separate factor is all wrapped up in one place. Let's see. How worried am I on a scale of one to 10? Well, and obviously it depends on your account, right? There are probably accounts that you don't care about, right? But let's say your bank account, how much does that worry you on a scale where 10 is like, I better go change this right now. My hair's on fire and zero is like, eh, you know, I don't really, I trust everything's fine. Well, okay. Um, now that you've said this, thank you very much.
50:10I, I guess my, my concern is elevated and I think it goes back to the level of trust that I give to one password or whatever supplants it in the future. If that's ever a case, I think it concerns me in this conversation that that it's true that I have a large footprint, a large attack vector in one service. That being said, I've had many conversations with the people behind 1Password, and even a trusted security professional that's a close friend of ours, love their protocols. I'm speaking of Farras, Jared, back in the day when he was doing wormhole and all that stuff, he was really praising their security measures.
50:53That being said, obviously anything is attackable and you can get past it. So I think I put a lot of faith in 1Password security measures, really. And I just hope that in the future, my bet on that security measure remains valid and true. And if they ever get attacked ad nauseum, I guess I'm just screwed. I don't know. I guess at that point, I'm not that worried about it, honestly. Five, maybe. Five. Okay. And I just want to disclaimer, I don't know anything about 1Password, right? Like I'm not like attacking them in general. It's like the general principle of like, I think we should, I think they should be scrutinized.
51:31I think we should hold them. I know I do. I really do. I think they actually, I think they welcome it. Cause like if you're in security and you are that kind of attack vector, you should 100 % desire scrutiny, not because you're scrutinizable because you should be your security place with so much wealth of knowledge on people. You should be scrutinized and they should welcome it. My opinion. well i'm wondering what a good multi-factor auth segregation would look like in terms of you're trying to sign into your bank you're on your phone what could your bank do that would be better than having your a password and an otp code in a singular password manager would it be multiple password managers would it be like what would that look like yeah i mean i think that it it does depend.
52:21Like I've actually wrote a blog post about this, about the different kinds of MFA for customers, right? Again, employees are a different world because you can force them to do all kinds of stuff and you can spend money on it. Right. Carry this Yubaki around. Totally. Totally. But for customers, you know, I think the, an important thing is that it is going to at least a different piece of software, right? So, you know, using them in passwords, being pulled from password manager and then using a different software authenticator app like google authenticator off the um there's some open source ones out there um you know even sending sms like i know sms has is is problematic in some ways because it's attackable in certain circumstances for high value accounts but it's still landing in a different place on the phone So, you know, email address, like one thing that I think I wish everybody who allowed email as MFA would do is have the multiple email addresses and have those email addresses not be tied to the email address you use to log in.
53:26Right. So I could set up, you know, Dan at Fusion.io is my login identifier. And then Dan at example.com is my MFA. And again, you're just separating things out and you're not, you know, every step you take to do this makes things just a little bit harder for attackers. right and so that's the whole goal is you know it's not to if there's a state level attacker out there hi anyone who's listening from a state level you know actor like they can probably get access to my accounts because they have those resources but I'm just trying to make it difficult enough that they kind of that normal attackers move on yeah that makes total sense I think having multiple pieces of software but unless you are an employer that's really on the end user, isn't it?
54:12Like if you're a bank, I guess if you do SMS, you're kind of forcing them into their SMS app or something like that. Whereas with a passkey, I mean, really that might be a downfall of a password plus passkey MFA because now they both are going to be stored in the exact same place. Whereas, and if you have your OTP codes in there, like how could you as the bank, not with employees, but with end users kind of guarantee them the best chance of having that segregation would it be sms which is like you said kind of has some problems with security i mean i i assume sms or email right like anything that's deliverable is probably going to be outside of your app um you know you could there's always this right we talked about the tension around the friction around like login method.
55:03And that same thing is true with MFA, right? And so there's always a tension between making things as easy for Adam to log in, right? As possible. Or Adam, to be honest with you, like taking control of his own destiny and using tools out there like 1Password or Bitwardner, et cetera. So yeah, so you definitely can help foster things by using deliverable methods. That's really the only way you can force that. And honestly, I don't know if 1Password has this or anybody else has this, but it wouldn't surprise me if there was a Gmail plugin that would go and look in your Gmail and pull out the code, right?
55:44That Adam could probably install as an extension to 1Password. And then he's just kind of circumvented that whole thing again, right? Right. And he's the one, by the way, paying the bank, right? He's the bank's customer. So you can't push them too far. But you can, I mean, education is kind of the canonical answer to this. It's like you say, we really suggest that you take these steps to secure your accounts. And if someone wants to ignore all the pieces of advice and they're still paying you money, that's a really hard question to solve. Yeah. You can enforce it with weird passwords, length, which I think is always good and bad.
56:26I've experienced where I'm like, okay, for example, my Traeger smoker, I can put it on my Wi-Fi and there's an app that lets me control it from far away. Well, apparently it can't do a Wi-Fi password that's longer than 30 characters. And so obviously my Wi-Fi password is probably like at least 32. I think it might be 64, honestly. It's crazy. I don't give it out. It's, you know, I will hand type and my wife hates it. it's not 64 characters but it's probably 32 and it's it's a it's a mess i'm not saying it's the best solution ever but my trigger will not do it so it it enforces this this limit there that's not actually a password it's like acceptance of a password but there's other scenarios where you try to you know redo your password or something like that and then when you go to that flow it yells at you oh not only did you not have this special character in the uppercase and lowercase and whatever, you know, you've got to meet these criteria.
57:26And some of them are just like, wow, they don't tell you. Like the UX of that flow is like kind of strange, right? Until you're done. And they're like, no, that one doesn't work. I mean, NIST actually recommend, they have the latest digital identity guidelines and they actually recommend that you don't enforce that complexity because it's frustrating to end users and they end up picking something that may not be that complex, right? Like they'll just add like the one exclamation point at the end of a normal word or something like that. Yeah. So I think minimum length is pretty much the only constraint you should have.
58:00Like it can't be less than eight or whatever it is. And then anything else, like as long as you want, as crazy as you want. But like we have to have a minimum amount. And check the corpus, right? Like there's a bunch of corpuses of passwords out there and check that it's not in there. And other than that, I'd say, yeah, go crazy. What's up friends, I'm going to give you a peep behind the scenes here. We love Notion here at Change Law. We use it so extensively. We do a lot of stuff externally from our internal core team. And we have to organize a lot of stuff, a lot of workflows, a lot of statuses, a lot of writing, a lot of informing.
58:38And Notion is just so infinitely flexible for us on creating workflows, standard operating procedures, basically. And it's just such a cool thing to build a workflow, a way of doing things inside of of Notion. And now they have Notion AI and it's saving us so much time. I'm writing with it. I'm finding things with it. I'm summarizing things with it. I don't have to kind of think, where is this in my massive Notion workspace or many team spaces that we have? I just Notion AI it and it comes up. It's so cool. And if you're uninitiated, you may know Notion. I'm pretty sure you know Notion, but they combine docs, notes, projects, all into a single space that you can design yourself and it's beautifully designed mobile desktop the web shareable on the web it's just so powerful it is your one place for your team to connect with your tools your knowledge and you're empowered to do your most meaningful work and unlike other tools out there that make you bounce from one thing to the next to the next notion is seamlessly integrated infinitely flexible and it's beautiful and easy to use so notion.io helps us work faster we're writing better thinking bigger.
59:48We're doing tasks that normally take hours and we're doing those things in minutes, sometimes even seconds. And yes, we're not a fortune 500 company, but notion is used by over half of fortune 500 companies and teams that use notion like us send less emails. They cancel more meetings. They save time searching for their work and they reduce their spending on tools, which helps everyone stay on the same page. So try notion for free today. When you go to notion.com slash changelog. That's all lowercase letters, notion.com slash changelog and try the powerful, easy to use notion AI today. And when you use our link, of course you are supporting this podcast, which you love and we love that too.
1:00:30So notion.com slash changelog.
1:00:37So here's a, I'm not sure this is a hot take, but I would say this is a take. Let's just say this is a lukewarm take. I feel like password managers or some sort of password management, and maybe Apple solved this to some degree, is the new SSL in the fact that we had Let's Encrypt happen more than a decade ago, and now a large part of the internet is now encrypted, right? Because of all their efforts with Let's Encrypt. I feel like passwords are so crucial, and there's only so many more users of software, and you go and find any given person that is just accessing web services in normal humanity, just normal life.
1:01:2050, 100 services or more, right? Like it's just so many. And the fact that I'm surprised that OnePassword doesn't have a free tier because you would think that would be a phenomenal attractor. And the fact that like Apple has already done it in replicating most of the goodness of password management, not so much other things like identity and SSH keys you could put in one password, lots of cool stuff. But I feel like password managers or password management is the new SSL and the fact that we just have to have the best, everybody uses it, free-ish way or a freely accessible way to so many people because there's so many people who just literally write down their passwords or have the same exact password across every possible service ever.
1:02:10and I won't name any names because I know a few. I'm torn. I want that world. I want that world. I'm not sure we're there because Let's Encrypt the big lever there was Chrome, right? And the scary warning messages in the URL bar and things like that. And I don't know if we have I mean, maybe you have that with the operating system vendors. So maybe that's the lever. but it feels like we're not there yet but yeah i would love a place i love a world i mean and honestly this is it's interesting to me because the more we talk about this conversation like password managers and pass keys are both kind of two sides of the same coin or they're two approaches to the same problem that both believe that computers are better than people at keeping track of, you know, verifiers of identity.
1:03:08And Paskies do it in a way that's a little bit more opaque and not maybe as compatible, but is a little bit stronger, right? Because it's private, public key encryption. Whereas password managers are more like designed to like fit in with the world we currently live in and have all these nice add-ons that you mentioned, Adam. But I just don't say whatever that is. The basics, man. Just password management. It would be great. Doesn't have to be the OTP, you know, 2FA kind of integration, the one password. Just let me, let the world have access to what I would, maybe I'm going to even agree with this.
1:03:46Like email password login is probably not going to go anywhere. Except for on changelog.com. Like you're going to, like it's still there in a way. Like you still have email in the flow. You've got this magic link flow. and so I don't ever concern myself with with change logs login for myself with that because like I don't need to store it there's nothing to store but insofar that so many services out there never get rid of it just having basic email password secure ways to not have the same password across all the different ways I feel like the world needs a version of that and it's totally you know maybe to Apple's credit it's an operating system level potentially concern or leadership concern in the fact that they've done seemingly the impossible which is give it to I mean that's free right Jared you're not paying for that well that's all I was going to say because I feel like between iOS and Android I feel like that's kind of a solved problem right because Android has a built in password manager and I'm sure there's places you can go to to get better ones and ios is built in password management and like has been there for a couple years now i don't know what windows does because i haven't used windows in this new millennia but i assume they got password management built into windows don't they let's google that real quick uh i don't believe there's a free one in windows what i can tell you is the user dan are you a windows user not currently i was until a couple years ago until a couple years installed windows 11 as an example so i've been exploring behind the scenes this idea of a creator pc i i like to build machines but then the operating system i'm going to put on there and do all this work is windows and that's just like the sadness of my life i would never want to do that and i know that because i literally went down the road i'm like hey it's been a decade or more since i've even played with windows aside from somebody saying hey you're an it can you help with this problem?
1:05:49I'm like, sure, I'll look at your windows. I have no idea what I'm even clicking on here. Yeah, right? I love it. And I install Windows and I'm just so sad for Microsoft that they can't get that right. They have the largest installable base of a computer user on the planet. And that's their best effort. I'm just sad for them. It's a mess. They installed so many softwares that are just not necessary and it's just disgusting. Maybe it's their fault. Maybe it's not their fault. I feel like they can solve the problem. They're not solving the problem. But, you know, they're not. I don't believe there's a default free password manager in Windows.
1:06:28I Googled it. PCMag disagrees. They say that there's other ones, so they haven't selected like this default installed for Windows. But, you know, somebody's got to do this. And who's going to leave that effort? It can't be one password because they're of service. They're a software company trying to make money. I mean, I think giving away 1Password for free is not very smart, although it could be the Xerox of 1Password, or I guess the Xerox of password managers is that they could give it away for free to everybody to a certain limit and attract a lot of people. And they're already on all the platforms, so maybe that's a good way for them.
1:07:06But there is no let's encrypt for password managers out there where it's just free to everyone and accessible. I would also say, like, I think that you kind of hit or you alluded to one of the issues with this, even if it gets installed in Apple, in Apple's operating systems, and it's installed in Microsoft operating systems and installed in Android, like you still have some people who use an iPhone and have to use a Windows PC, right? And so you have this cross operating system solution that Chrome, again, the big lever that moved Let's Encrypt, that was cross platform. And it had significant market share.
1:07:46Maybe there's some kind of consortium who could help that. I don't know. Again, I'd love to live in that world. There's an article from The Verge in 2020 about Microsoft's new password manager that works across Edge, Chrome, and mobile devices called Microsoft Authenticator. And so this was coming out then. This is an app that you would install on your iOS or Android device, and you would cross that chasm basically, syncing with your Windows-based Edge browser. I think it's actually not Windows-level password management. I think it's inside of Edge, which seems like a weird silo. And that could be wrong.
1:08:21That could be outdated. But there are people obviously trying to tackle that particular cross-platform thing, at least from the Microsoft side. I don't think Apple has any interest in tackling that, as they've historically had no interest in those kind of things, which is a shame. And obviously, and Google with Chrome. I don't know. I think that there are options for everybody, and I think that there are probably free options for everybody. It's different than Let's Encrypt because it's more of an end-user concern than it is a server operator concern, right? Like all of us nerds got our free certs and upgraded our stuff to HTTPS, and they made that palatable and free and they made the case for why you should do it and that worked.
1:09:06But when we talk about end users around the world, varying levels of technical expertise, it's just a much taller order. But I do think that Apple and Android have not solved it but provided something, a baseline for a lot of people. I mean, if you want to call Microsoft the Finicade, I'm looking at it. Baseline. It is a line beneath the base. I don't think, I mean, given their prowess on the compute platform across the globe, Apple is the best effort. And I would not consider that an effort. I don't think Microsoft is investing in Windows like they used to. I think they're investing in Azure and cloud and AI and all these other things that have like up and to the right opportunities.
1:09:55and Windows is just kind of like last millennia's thing. It's just there. I don't know how they get away with that. Large installed base that, what are you going to do? You wrote an app, you have like an old app that you're not going to rewrite. Entrenched. So you have these services like Azure and then those services have what? Users. What are those users running? iOS or Android? I think a lot of them are running Windows. I don't think so. Like, what do you mean? What kind of users? I mean, okay, you talk to a gaming PC person, a gamer. Large, I mean, huge community. Gamers are huge communities.
1:10:32Steam is on Linux now, man. Let's go. I mean, maybe it's diversifying, but still, by and large, they're building Windows-based PCs, sometimes very reluctantly. Yeah, but gamers have one password. Maybe. Or LastPass or Instant Viewer Password Manager here. Like I said, I think, so my argument is more so less like a direct comparison to Let's Encrypt, but more so the fact that the security of email password login for many, many people is paramount. And there's nothing out there like Let's Encrypt that's freely available to everyone. And that's what I mean by that. I think that if we had that, that was like one unified brand, one unified application like Let's Encrypt is.
1:11:11It's a single unified brand to say SSL for everybody. If we had a version of that for email and password, I think we would have a better, a more secure world. maybe not so much less breaches, but certainly less people who have the same password across 17 services or just some layer above current state of art for security for everyday users. Amazing call to action, Adam. Yeah, that is good. Here's a lukewarm take. I think in 2025, which is the year that we are currently in, unless you listen to Changelog News, then you might still be in 2024. We shouldn't think about Windows and macOS and Linux very much at all.
1:11:53I think that Steve Jobs was right. These are trucks. We drive trucks because we're truck drivers. But the world at large, the operating systems at large in 2025 are on smartphones. And iOS and Android are the operating systems of this decade. And so that's where it matters. And I think that those people for passwords are being taken care of. I can't speak to the quality of Android's implementation, but I know there's stuff there. And so I just think that we shouldn't even be thinking about desktops when we talk about mainstream consumerism, mainstream computerism, because almost everybody in the world is using a smartphone as their primary and in many cases their only computing device.
1:12:32Is that lukewarm? Is that hot? Is that cold? I mean, I don't disagree that a lot of people, a large majority of people consider computers or today's modern computer being a mobile device. It could even be as far as an iPad. Similar to this conversation with Dan and the fact that email password login will be around for the foreseeable future, I feel like some version of the desktop will be around for the foreseeable future. It is the platform where you have control of the compute, control of the operating system. You know this, Jared. You're a developer. That's my argument. You will have a version of that for people.
1:13:12I'm not saying you won't, but those are the truck drivers, and truck drivers have specific tools they use in order to drive their trucks better you know like remember that guy who's got the uh sylvester stallone you know he had that built in over the top what is this oh yeah yeah dan knows gotcha or i was just about a cdl right like like well that yeah you have you have you know specified knowledge right and you have a higher expectation of a truck driver than you would have uh someone who drives a car yes so that's a more practical example i was going for the movie reference remember over the top guys where sylvester stallone he's got this built into his truck he would like he was an arm wrestler and he would use one hand and all day long while he drove he would just be making that one arm strong you know take my strong arm and he would take my strong and he would become the best arm wrestler it was basically a rocky ripoff like rocky was really successful he's like let's do it again with arm wrestling and so he had a very specific thing in his truck where he could just like work out that was over the top jared i did i missed that movie that was a good i mean the way he i I mean, so many people try to replicate.
1:14:13We've got to get this on the screen. I mean, he would be armresting them, and then he would just do this movement and then take them down. He would just curl his wrist a certain way.
1:14:33He would get serious all of a sudden, and he would move his hands. It was like his killer move. You seen this movie, Dan? Yeah, he would change his grip. This is my favorite conversation about authentication, though. I'll be honest with you. Well, we aim to blaze around here. I love the movie reference. That's amazing. But yeah, yours is a much more salient reference, which is specific tooling and testing and training that truck drivers receive in order to drive trucks well. And everybody else, you know, we just, sure, we got driver's licenses, but we just hop in a car and drive, you know, we don't care about trucks.
1:15:06So that answer, like to kind of add on to the lukewarm take, your response to Adam is, I don't care about, I mean, we don't need a universal solution because we have one that is near universal for most of, for the current platform of the century, basically, or at least decade, maybe not century. And specific skilled users have their options as well and better education and they should know their choices of password managers and they should know this kind of stuff. And the people driving the trucks today, the desktop CCs and the MacBooks and stuff are sophisticated users who are usually working.
1:15:45I mean, most people are creating, even today, a lot of creation is happening on device, but on smartphone, but are actually like, this is the working class people. And it's not that I don't care about them. It's that I think that they are educated in ways that they can, they can listen to the changelog and just know all this stuff. Or frankly, like the employer might, you know, if they're an employer, there's going to be like. Exactly. There's companies out there who specialize in this stuff. Yeah. We should, we should do a survey. And maybe our audience is not the best audience, but I don't know who else we would survey besides our audience.
1:16:20It's like, are you using a password manager? We should survey someone else's audience. Gosh, I mean, like, I really want to know this because I feel like when I talk to everyday folks, if I even mention 1Password, like, what is that? Sure. And that's a failure on 1Password part, in my opinion. Like, I'm not their marketing department. I'm not even their leadership. but I think if you're running 1Password you want everyday users to recognize who you are because there's only so many as Jared's saying there's only so many truck drivers but isn't the money an enterprise? yeah, right I know businesses that pay for 1Password and they're thrilled to pay for 1Password for all those reasons that you mentioned Adam for sure, yeah, because you get everybody on the same platform you get a unified source of truth I'm not selling it but all the reasons why you choose it is really good well you know it's a hard fight here you know it's a hard fight let's uh your lukewarm take though is is interesting all right good i feel like linux windows and mac os still matter that's because we are the truck drivers of the of the software world yeah and uh we can even be a little over the top every once in a while dan if you were starting a software business today and you wanted people to authenticate against your website in order to do stuff and you make money once they're signed in and you want to make sure that they can get it in and they can get their stuff but also their stuff secure and like what would your solution look like for a developer trying to build today yeah and so this is a great question because i think this goes back to that spectrum you talked about a while ago, right?
1:18:00And I think that if you have one single app, and you have relatively simple software needs, I think that like going with the framework that is the base of your app is the right solution, right? So with Rails, that'd be devise with Node.js, it might be like a passport, or maybe like a service like a Firebase, you know, because if you're kind of a single developer, you're just, you're just trying to get people into your app. right? And safe and secure. And a lot of these big services will take care of that, where I think it makes sense to kind of introduce something like Fusion Auth or Auth0 or any of those other kind of solutions we talked about is when it gets a little bit bigger, right?
1:18:41When you have more than one app or when you have, you know, there's that trade-off between build and buy. And you always are kind of riding that tension of like, well, yes, our engineers could do this, but should they? And at some point the answer is no, because they're better off writing features and, um, and not writing kind of undifferentiated login functionality. So that, does that make sense? I mean, I, I, I appreciate the question because I'd love to be able to say like, here's an answer for everybody and every, everything, but I just don't think that's the truth. So there is no silver bullet.
1:19:17I was hoping you'd just give us one. You can just tell us what to do. Dan Moore told me to do this and so I'm going to do it. But no, I had to actually think about my own use case and apply thought processes. That's no fun. Well, that even gets back to the way that people are offering to authenticate, right? Like, I think that, you know, as much as Adam hates GitHub login for tail scale, I think that's a great example of something. I don't actually mind it. Let's be clear. I don't mind it. I don't know. You seem pretty upset earlier. I think the screen presented is a little overreaching and I think it's overwhelmingly confusing.
1:19:46Fair enough. Fair enough. Fair enough. Fair enough. I don't mind it. But I mean, I think if you are writing an app that is targeted for like small, medium business users in Germany, you should use Zing, right? Which is like a German social business network, right? Or if you're writing something that is going to be deployed to China, you should use WeChat. Or if you're writing something that's going to be aimed at business users in the US, you should use LinkedIn. And I think you should always have username and password as the baseline. And I think that you should offer other solutions that are going to reduce friction that let people choose.
1:20:20Because at the end of the day, again, this is from the lens of customer identity access management. You don't really care how people get in, right? You just want people to get in as quickly as possible so that you can get them to the value that they're actually hopefully going to pay you for. So you think that we're wrong because we don't offer email password as a base. I mean I would love to actually that would be a great thing to survey your listeners as well are losers Dan no he was going to say listener and user he's going to say listener and he's going to say user and he called them losers never invited back Dan thank you very much well to be clear Dan is a former listener now guest he's been on twice but he's listened to the show prior to being a guest So he's in that bucket he's claiming.
1:21:11Go on, Dan. We're done joking. I mean, I think that there's probably a chunk of folks that do want to just use username and password, right? They want to put it into one password. And there's probably a chunk of folks who'd be happy to use Google too because they have one personal Google account that they kind of hang everything off of. So that gets back to effort, right? And so how much effort would it take for you to add those additional login methods to ChangeLog? And this is why we paid the big bucks, right? Because we're just guessing on what features are needed for the future. We can do surveys and ask people and whatnot, but you don't know.
1:21:55But Gizem and Passport is such a baseline that it's hard for me to imagine not offering it. And I've definitely been turned off of places that didn't. what's funny that you say that with the google account i didn't really consider it that i guess in this whole conversation because i don't like think like others too frequently about this i'm not an auth provider i'm not a product manager for fusion auth so i'm not thinking about the way the product gets implemented but i i bet there's a lot of people out there who's like you know what adam you're an idiot the whole time you're having this conversation i'm listening but I love to hang every authentication off of my Google account because that's, they are my, they are my password manager because I know how to get there and it's literally one password to get into Gmail or whatever they're choosing.
1:22:44And they, they're effectively this free authentication provider or free one password manager or free password manager because they've logged into their email and everything is hinged off of SSO. And it's almost like, Hey, if you don't offer for SSO with Google, then I can't, then I don't even want to consider your service. Maybe there's people out there like that. And that maybe is the free version of it that's available to everyone. I mean, I, for my work, we use Google workspace and I prefer that, right? Because that way it's just, it's super tied. And I know that I will always have access to my Google account as long is I'm an employee and I can always, if I get, if I lose access to it somehow, um, you know, Google locks me out or something, at least I have recourse to my IT admins.
1:23:36Um, personal is a little bit different. You hear horror stories about people losing access to their Google account and then losing access to like, you know, years of, of photos and memories and documents etc but um i loved for my professional accounts if it's tied to my company i love to hang it off my google account there is no one way to log in basically jerry like that's the thing i think is is we can we can bet on in 2025 and beyond is that there is no one way unless you make only one way that's right like we have you go to change.com and you get your magic link here's the nice thing about it is we never expire that cookie baby so do it once just keep your browser you know not flushed and you never have to do it again unless you're switching to a different context every time you switch a machine like every that should be the first thing you do when you set up a new machine right is logging to changelog.com and then and then you're good that's right and then you're just good to go for the good to go for the remainder of that machine bam well we didn't have time for it on this particular show but there is a very interesting article out on fusion auth's blog by Dan called building a self hostable product.
1:24:45If you want more Dan, more expertise, we'll link that up in the show notes for folks to go and listen to. Aside from that, Dan, what's the best place to connect with you on the internet? Yeah. So I'm on a blue sky. It's moreds.com on blue sky. I'm on LinkedIn, uh, Dan Moore, um, in Boulder is probably the easiest way to find me and fusion out.io. And, uh, really appreciated the conversation, appreciated the movie reference. Maybe I should go check out Over the Top. You should, man. Gosh. That's an 80s movie, right? It's a classic 80s. Yeah, it's got all the 80s. 85, 88. I'm going to guess 88. Yep.
1:25:20Riding Sylvester Stallone's Rocky coattails, you know. After Rocky, he was kind of invincible there for a minute. Let's see how accurate I was. 87. I was so close. Oh, man. I'm re-watching that. That's on my list now. That's a good one. Thanks, Dan. All right. That's all we have for today. Bye, friends. Thanks. Bye, friends.
1:25:44Did you know we now ship full video episodes to YouTube in addition to our award-worthy shorts and clips? So you can watch us have these conversations if that's your kind of thing. Like and subscribe today at YouTube.com slash changelog. And share the channel with your friends, especially if they like to get their pods on YouTube like animals. One more thank you to our sponsors of this episode, Fly.io, Retool, Temporal, and Notion. Don't forget to check out their wares and support them because they're awesome and they support us, which is awesome. And of course, thank you to the one, the only, the Beat Freak, Breakmaster Cylinder for these dope beats.
1:26:26Next week on the Changelog, news on Monday, Burt Hubert talking long-term software development on Wednesday, and another banger of a Changelog and Friends on Friday. Have a great weekend. Hit us up with a five-star review if you dig it. And let's talk again real soon.
From the publisher
Dan Moore from FusionAuth joins us for a wide-ranging discussion about modern auth strategies. We talk magic links, OTP, MFA, passkeys, password managers & so much more.

