Live data from Hacker News

Auth0 Down

twitter.com

51–60 of 78 posts

Re: Auth0 Down

#51

What alternatives to Auth0 are worth looking into? Between this P0 (with no ability to check the status or file a ticket) and the Okta acquisition, I hesitate to continue using Auth0 as the default when spinning up new web apps.

AWS Cognito works but it is a far cry from how usable Auth0 is.

Agreed! just got done replacing Cognito across the board with Auth0, glad we hadn't pushed it to prod yet.

Re: Auth0 Down

#52

Wow. The whole point of paying someone like Auth0 is to _not_ have this happen. This is basically their whole point, is it not? Really looking forward to the post-mortem, but I won't ever forget just how down this thing is right now.

> The whole point of paying someone like {insert cloud provider} is to _not_ have this happen.

Being in the cloud doesn't mitigate potential issues.

Re: Auth0 Down

#54
post #42

Don't forget to request your credit per their SLA[0]. You have 10 days to request your credit, which by my calculations should be 10% of this months' charge. Not a fair trade for leaving us dead in the water for 4 hours, but SLAs in general are worthless. [0]: https://auth0.com/docs/support/services-level-descriptions

I'm willing to bet we can get at least the 20% return, they're still "officially" down. I bet it'll be a few hours till they say we're good. Everyone make sure you've got detailed tickets into their service queue. Get your creds!

[deleted]

Re: Auth0 Down

#55

What alternatives to Auth0 are worth looking into? Between this P0 (with no ability to check the status or file a ticket) and the Okta acquisition, I hesitate to continue using Auth0 as the default when spinning up new web apps.

You can try Azure AD B2C.

Re: Auth0 Down

#56
post #45

Wow. The whole point of paying someone like Auth0 is to _not_ have this happen. This is basically their whole point, is it not? Really looking forward to the post-mortem, but I won't ever forget just how down this thing is right now.

The whole point for me is that I don't want to be responsible for user credentials. I don't trust the security of my app.

If you don't trust your app with credentials how can you trust your app with what those credentials are used to access?

Re: Auth0 Down

#57
Their status page is pretty depressing to read since all it really says, repeatedly, is "we're really sorry" and "we're working as hard as we can." You can just feel the abuse the person writing that must be getting from customers. I feel bad for them since they have no power to fix this and didn't cause the issue.

No root cause or resolution yet and it's been 4 hours. Doesn't bode well for getting this resolved soon.

Re: Auth0 Down

#58

This type of incident is exactly why I dislike identity federation as a service. Yes it's difficult to get right, and you open yourself up to additional risk and technical complexity to do the federation yourself, but simultaneously how many businesses are currently completely down and just sitting on their hands waiting for Auth0's engineers to fix their systems?

But how will you ever succeed if you don't outsource all but your core competencies while your core competencies simultaneously converge on banking/investment/midde-manning?

Re: Auth0 Down

#60

This type of incident is exactly why I dislike identity federation as a service. Yes it's difficult to get right, and you open yourself up to additional risk and technical complexity to do the federation yourself, but simultaneously how many businesses are currently completely down and just sitting on their hands waiting for Auth0's engineers to fix their systems?

While this protracted outage has prompted some plans to get rolling with a self-hosted Auth0 substitute, bear in mind that this can't address users wanting to sign in with Google, Microsoft, LinkedIn, etc., where you'll still depend on their authentication service to work correctly, not ban your client ID, and so on.
Post reply on HN