Live data from Hacker News

Okta and Auth0 Blocking Cuba, Iran, N Korea, Syria, Crimea, Luhansk, Donetsk

support.okta.com

101–110 of 170 posts

Re: Okta and Auth0 Blocking Cuba, Iran, N Korea, Syria, Crimea, Luhansk, Donetsk

#101

Wow, and here I thought Okta had split up their service into US and non-US, like many other big companies, but seems they have not, so now just because the US has some arbitrary list of who can be a user, everyone using Okta needs to follow that... Seems like the laws are a bit outdated and haven't really been updated for a global internet, hope we see some changes in that direction.

It does not matter. If there is business presence ini the US of a company (direct or indirect), this business will be used to punish unwanted operations outside the US.

If you have a US-Okta and a non-US Okta and both ultimately are "Okta", then if the non-US Okta does not follow US regulations, the US-Okta will take the whip.

Re: Okta and Auth0 Blocking Cuba, Iran, N Korea, Syria, Crimea, Luhansk, Donetsk

#102
post #70

My view on this from the United Kingdom: I have no vested interest in any of the territories listed nor do I support them in any way, but my business should not be subject to the whims of overseas powers and foreign policy. In response to this announcement I've closed down my Auth0 experiments. I refuse to be held to US enforcement when I operate outside US jurisdiction. I know other SaaS will follow suit, but we hav…

But isn't Auth0 a US-based company? In that case, they are obliged to implement US sanctions, regardless where their customers are located. That applies of course to any US-based company, so in that case you would need to avoid touching anything that is based in the US. That may be possible in some cases, but if you rely on the third parties, it's almost inevitable to completely avoid US.

Possibly until they grow to a point where they have divisions in UK or EU, which I think is how Facebook/Google/Microsoft are set up but I could be wrong.

There's some choices in the market, and beyond the behemoths it is still possible to avoid the US. The challenge is finding one that isn't owned by a US company and will end up with the same restrictions (like Gigya is now owned by SAP) - but any company serious about security will do the due diligence and know who own who.

Re: Okta and Auth0 Blocking Cuba, Iran, N Korea, Syria, Crimea, Luhansk, Donetsk

#103
post #97

Earlier quoted context omitted.

> is suddenly portrayed as being an achievement It's not an achievement. It's a sign of how hard the USA-based bullying had come so that a country cannot export goods or services so it has to export people.

> (...) so it has to export people. It's indentured servitude. It's exploitation that treats the fellow man as nothing more than an exportable good whose role in life is to be abused to cater to the whims of despots. You cannot deflect the blame of these subhuman practices onto foreign regimes just because you feel a specific oppressive regime that you support could use some extra cash.

I'm not defending Cuban regime, merely saying that USA had no problems dealing with other repressive regimes, and that Cuban regime would likely improve if it wasn't pressed in the corner by the USA.

Re: Okta and Auth0 Blocking Cuba, Iran, N Korea, Syria, Crimea, Luhansk, Donetsk

#104
post #70

My view on this from the United Kingdom: I have no vested interest in any of the territories listed nor do I support them in any way, but my business should not be subject to the whims of overseas powers and foreign policy. In response to this announcement I've closed down my Auth0 experiments. I refuse to be held to US enforcement when I operate outside US jurisdiction. I know other SaaS will follow suit, but we hav…

But isn't Auth0 a US-based company? In that case, they are obliged to implement US sanctions, regardless where their customers are located. That applies of course to any US-based company, so in that case you would need to avoid touching anything that is based in the US. That may be possible in some cases, but if you rely on the third parties, it's almost inevitable to completely avoid US.

The USA has a recent history of imposing extraterritorial legislation. USAians are apparently unwelcome at UK banks; transferring money from the UK to the USA risks unwelcome attention from the IRS, even if you've done nothing wrong.

This damages US businesses more than it does overseas businesses. Sure, UK banks lose some US customers. But actually they didn't have to lose those customers; all they were required to do was exercise enhanced diligence over the sources of funds transferred to USA. The UK banks chose to eject those US customers, because it was cheaper.

I don't know what to do about this. I think US legislators like extraterritorial legislation because it looks strong, and because it has a certain flavour of "fixing the world". Most USAians don't have overseas financial interests, so aren't impacted. But, for example, my US half-sister declined her share of my late father's legacy, because importing it to the USA would have been too costly as well as too much hassle.

Re: Okta and Auth0 Blocking Cuba, Iran, N Korea, Syria, Crimea, Luhansk, Donetsk

#105
post #54

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/And_you_are_lynching_Negroes Feel free to start a discussion on US aggression, if you honestly feel strongly about it. Otherwise you're blatantly trying to whitewash decades of systematic oppression from totalitarian bloodthirsty regimes, and in the process support all the human rights violations they're continuously subjecting their population to.

Curious... Soviet union were completely right when criticizing US for lynching black people... But it is interesting how propaganda works... It's like nowadays when you point hypocrisy in the Internet, but people just yell "whataboutism" as a way to always ignore criticism and do not accept responsibility for double standards and hypocrisy in the propaganda that they spread. Of course, this happens only for criticism…

Yes this is an incorrect use of “whataboutism”.

It is supposed to mean the rhetorical trick of using other’s faults to distract from and normalize one’s own wrongdoing.

It is not a general defense against accusations of hypocrisy leveled by a third party.

Re: Okta and Auth0 Blocking Cuba, Iran, N Korea, Syria, Crimea, Luhansk, Donetsk

#106
post #97

Earlier quoted context omitted.

> (...) so it has to export people. It's indentured servitude. It's exploitation that treats the fellow man as nothing more than an exportable good whose role in life is to be abused to cater to the whims of despots. You cannot deflect the blame of these subhuman practices onto foreign regimes just because you feel a specific oppressive regime that you support could use some extra cash.

I'm not defending Cuban regime, merely saying that USA had no problems dealing with other repressive regimes, and that Cuban regime would likely improve if it wasn't pressed in the corner by the USA.

> I'm not defending Cuban regime (...)

Well, except you are. You're trying to shift the attention away from Cuba's track record on human rights abuses by arbitrarily picking distractions that frankly you care nothing about, as if pointing out these distractions justified Cuba's long history of oppression and abuse.

Re: Okta and Auth0 Blocking Cuba, Iran, N Korea, Syria, Crimea, Luhansk, Donetsk

#107
post #14

One thing I've always been curious about is why the opportunity created by this sort of thing doesn't seem to be taken advantage of. To take Iran as an example: when US sanctions prevent Boeing or Airbus from selling to them, I can understand why Embraer doesn't step in and offer to supply planes, because they are afraid of secondary sanctions affecting their business with the rest of the world. But tech isn't like a…

> building a GitHub, Okta or Auth0 clone

Because it is is not necessary. Setting up something like Github onsite takes 1 hour. Network effect really is overrated.

Where it hurts are payment systems, credit cards etc.. And there are alternatives.

Re: Okta and Auth0 Blocking Cuba, Iran, N Korea, Syria, Crimea, Luhansk, Donetsk

#108

Earlier quoted context omitted.

But isn't Auth0 a US-based company? In that case, they are obliged to implement US sanctions, regardless where their customers are located. That applies of course to any US-based company, so in that case you would need to avoid touching anything that is based in the US. That may be possible in some cases, but if you rely on the third parties, it's almost inevitable to completely avoid US.

> so in that case you would need to avoid touching anything that is based in the US This does not change much: a, say, French company is bound to follow US regulations anywhere (including in France, not to mention abroad) because the US would punish any interests of this company in the US. This was the case with Iran, and with others. If you are mid-to-small compared to the US/China, you are bullied. If you are very…

I don't think the French government care much because the EU gives them more bargaining power. If they were bound beyond political pressure then we'd have French or EU embargos against Cuba for the last 60 years. France doesn't stand alone nor does the UK despite leaving the EU, which is why I object to US foreign policy spilling over political borders via internet-based tech companies.

Re: Okta and Auth0 Blocking Cuba, Iran, N Korea, Syria, Crimea, Luhansk, Donetsk

#109
post #22

It's sad that people in occupied regions of Ukraine are punished twice, by Russian government and by US government too.

I’ve seen videos where captured Russian soldiers are actually conscripts from the contested regions. I would think they have a lot more to worry about than okta authentication.

Depending on the region, this may not be a problem. I (casually) saw that the Russian approval is big (>50%) in the eastern regions, so these conscripts may still be "the good ones" for the population of this region.

Re: Okta and Auth0 Blocking Cuba, Iran, N Korea, Syria, Crimea, Luhansk, Donetsk

#110

Don’t offload authentication to third parties… People didn’t learn their lesson from Facebook etc etc.

This is very different than Facebook. This isn't a company that also happens to provide auth to get more tracking for their main product. The auth is the main service for okta and it's used by people making decision about whether they want to build this in-house or outsource it.

There are two problems here

1) let a third party handle authentication (Code)

2) let a third party handle authentication (SSO)

Number 1: don't do that Number 2: Only do that if you are in control of SSO, or if you are very certain you won't have problems contacting the provider. (so not google in this case)

Post reply on HN