PageSourceSearch

https://goauthentik.io/assets/js/d7907765.beccce6f.js

js goauthentik.io collected 2026-09-24 08:37:28 UTC 22,634 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunk_goauthentik_www=self.webpackChunk_goauthentik_www||[]).push([["24223"],{9853(e,t,n){n.r(t),n.d(t,{assets:()=>l,contentTitle:()=>r,default:()=>u,frontMatter:()=>s,metadata:()=>i,toc:()=>h});var i=n(31761),a=n(94686),o=n(23191);let s={title:"Let\u2019s make identity fun again (whether we build it or buy it)",slug:"2023-08-16-lets-make-identity-fun-again",authors:["jens"],tags:["build-vs-buy","SSO","third-party software","identity provider","vendors","security","authentication"],hide_table_of_contents:!1,image:"./image1.jpg"},r,l={image:n(23735).A,authorsImageUrls:[void 0]},h=[{value:"How identity became boring and the big players became defaults",id:"how-identity-became-boring-and-the-big-players-became-defaults",level:2},{value:"Build vs. buy and its extremes",id:"build-vs-buy-and-its-extremes",level:2},{value:"Third-party software is a market for lemons",id:"third-party-software-is-a-market-for-lemons",level:3},{value:"Buy vs. build as a false dichotomy",id:"buy-vs-build-as-a-false-dichotomy",level:2},{value:"Differentiation is not always obvious",id:"differentiation-is-not-always-obvious",level:3},{value:"Security is 90% execution and 10% innovation",id:"security-is-90-execution-and-10-innovation",level:2},{value:"Let\u2019s make identity fun again",id:"lets-make-identity-fun-again",level:2}];function d(e){let t={a:"a",blockquote:"blockquote",em:"em",h2:"h2",h3:"h3",img:"img",li:"li",p:"p",ul:"ul",...(0,o.R)(),...e.components};return(0,a.jsxs)(a.Fragment,{children:[(0,a.jsx)(t.p,{children:"Identity \u2013 whether we\u2019re talking about internal authentication (think Auth0) or external authentication (think Okta) \u2013 has become boring."}),"\n",(0,a.jsxs)(t.p,{children:["Little else proves this better than the fact that Okta and Auth0 are now the same company and that their primary competitor, Microsoft AD, survives based on ",(0,a.jsx)(t.a,{href:"/blog/2023-07-07-Microsoft-has-a-monopoly-on-identity",children:"bundling and momentum"}),". Identity has become a commodity \u2013 a component you buy off the shelf, integrate, and ignore."]}),"\n",(0,a.jsx)(t.p,{children:"Of course, taking valuable things for granted isn\u2019t always bad. We might regularly drive on roads we don\u2019t think much about, for example, but that doesn\u2019t make them any less valuable."}),"\n",(0,a.jsx)(t.p,{children:"The danger with letting identity become boring is that we\u2019re not engaging in the problem and we\u2019re letting defaults drive the conversation rather than context-specific needs. We\u2019re not engaging in the solution because we\u2019re not encouraging a true buy vs. build discussion."}),"\n",(0,a.jsxs)(t.blockquote,{children:["\n",(0,a.jsx)(t.p,{children:"My pitch: Let\u2019s make identity fun again. And in doing so, let\u2019s think through a better way to decide whether to build or buy software."}),"\n"]}),"\n",(0,a.jsx)(t.p,{children:(0,a.jsx)(t.a,{href:"https://pixabay.com/users/jplenio-7645255/",title:"Image by jplenio on pixabay",children:(0,a.jsx)(t.img,{alt:"Image1",src:n(64701).A+"",width:"1280",height:"720"})})}),"\n",(0,a.jsx)(t.h2,{id:"how-identity-became-boring-and-the-big-players-became-defaults",children:"How identity became boring and the big players became defaults"}),"\n",(0,a.jsx)(t.p,{children:"There are one million articles about build vs. buy because it\u2019s one of those problems that won\u2019t go away. Ironically, despite the never-ending discussion, there tends to be a firm anchor: build the features that differentiate your product and build everything else."}),"\n",(0,a.jsxs)(t.p,{children:["Jeff Lawson, co-founder and CEO of Twilio captured this well in his book ",(0,a.jsx)(t.em,{children:"Ask Your Developer"}),", writing that \u201CMy rule of thumb is that for anything that gives you differentiation with customers, you should build. Software that faces your customers, you should build.\u201D"]}),"\n",(0,a.jsx)(t.p,{children:"Within this framework, identity almost inevitably appears to be the perfect example of buying instead of building. When has a login screen ever made one product stand out from another? When has a user ever said, \u201CThe product is good but the authentication process brought me joy\u201D?"}),"\n",(0,a.jsx)(t.p,{children:"It\u2019s easy, obvious, and \u2013 from within this framework \u2013 correct to buy your identity feature. Identity isn\u2019t unique here but the strength of the consensus around buying instead of building is striking."}),"\n",(0,a.jsx)(t.p,{children:"Small startups, on one end of the spectrum, tend to strictly follow the rule of thumb above. Along the way to product/market fit, and often well after it, startups find it worthwhile to invest almost everything into the bleeding edge features that will wedge them into the market."}),"\n",(0,a.jsx)(t.p,{children:"Identity is an early requirement they often want to sweep away. Identity becomes a commodity to buy and the defaults \u2013 usually Okta and Auth0 \u2013 feel obvious."}),"\n",(0,a.jsx)(t.p,{children:"Enterprises, on the other end of the spectrum, tend to be swamped with bureaucracy and overwhelmed by internal and external demands. Enterprises tend to need extensive feature coverage, multitudes of integrations, and always-on customer support. From this perspective, defaults appear attractive and Microsoft AD becomes compelling."}),"\n",(0,a.jsxs)(t.blockquote,{children:["\n",(0,a.jsx)(t.p,{children:"Across the spectrum, identity has developed the reputation of being a boring problem with a commodity solution."}),"\n"]}),"\n",(0,a.jsx)(t.p,{children:"If companies were aware of the tradeoffs that come from choosing the default path, we wouldn\u2019t be having this conversation. But for many companies, the default feels like a standard, and all the non-standard paths are obscured."}),"\n",(0,a.jsx)(t.h2,{id:"build-vs-buy-and-its-extremes",children:"Build vs. buy and its extremes"}),"\n",(0,a.jsx)(t.p,{children:"The \u201Cbuild your core; buy everything else\u201D framework feels authoritative because its logic is built on logic we don\u2019t do a good job of questioning."}),"\n",(0,a.jsx)(t.p,{children:"Is there actually always great software to buy? Is build vs. buy a black-and-white decision? Do we actually have a good understanding of differentiation?"}),"\n",(0,a.jsx)(t.p,{children:"No, no, and also no."}),"\n",(0,a.jsx)(t.h3,{id:"third-party-software-is-a-market-for-lemons",children:"Third-party software is a market for lemons"}),"\n",(0,a.jsxs)(t.p,{children:["Lawson\u2019s rule of thumb implicitly relies on an idea in economics called the ",(0,a.jsx)(t.a,{href:"https://en.wikipedia.org/wiki/Efficient-market_hypothesis",children:"efficient-market hypothesis"}
1),". The basic idea is this: assets and asset prices reflect all available information."]}),"\n",(0,a.jsx)(t.p,{children:"There are decades of economists arguing back and forth on the accuracy of this idea, that all data points are brought to the table. But in a cultural and business context, it\u2019s been honed into a simple assumption: the market incentivizes identifying and solving problems and over time, for the most part, the best possible solution is available at any given time."}),"\n",(0,a.jsxs)(t.p,{children:["But there\u2019s a competing theory that explains the software procurement process better: the ",(0,a.jsx)(t.a,{href:"https://en.wikipedia.org/wiki/The_Market_for_Lemons",children:"market for lemons"})," concept. The core argument is that in a market with information asymmetry between buyers and sellers, the quality of the products can degrade and buyers can end up with defective products (lemons)."]}),"\n",(0,a.jsx)(t.p,{children:"Third-party software procurement is often surprisingly inefficient and when you think about your actual experiences purchasing software or using purchased 
1software, you\u2019ll likely remember a lot of lemons (even if few software vendors are actually like a used car salesperson)."}),"\n",(0,a.jsxs)(t.p,{children:["Dan Luu has a great article on the topic called ",(0,a.jsx)(t.a,{href:"https://danluu.com/nothing-works/",children:"Why is it so hard to buy things that work well?"})," He writes that companies, in principle, should be able to outsource work outside their core competencies but that those who do, in his experience, \u201Chave been very unhappy with the results compared to what they can get by hiring dedicated engineers.\u201D"]}),"\n",(0,a.jsx)(t.p,{children:"This disappointment applies in absolute terms (meaning the product might not be as good as promised or that support isn\u2019t efficient at making it work for you) and in financial terms (meaning large contracts can often end up costing more than the salaries of the engineers you otherwise would have hired)."}),"\n",(0,a.jsxs)(t.p,{children:["Examples abound, including a product that was supposed to sync data from Postgres to Snowflake that ultimately lost data, duplicated data, and corrupted data. There\u2019s also Cloudflare Access, ",(0,a.jsx)(t.a,{href:"https://twitter.com/benskuhn/status/1382325921311563779?s=20",children:"named by Wave\u2019s then-CTO Ben Kuhn"}),", that came with a product-breaking login problem that the Cloudflare support team misinterpreted before escalating to an engineering team, who \u201Cdeclared it working as intended.\u201D"]}),"\n",(0,a.jsx)(t.p,{children:"The market doesn\u2019t need to exclusively comprise lemons to be a market of lemons; the information asymmetry just needs to be imbalanced enough, consistently enough, that the typical buy vs. build framework doesn\u2019t work."}),"\n",(0,a.jsx)(t.p,{children:"The primary benefit of the API economy, in theory, was the rise of hyper-specialized services built by hyper-specialized engineers."}),"\n",(0,a.jsx)(t.p,{children:"But there\u2019s a downside: If no one knows more about payment processing than Stripe, then how can other engineers adequately evaluate the options? And that doesn\u2019t just apply to sheer functionality. In-house engineers are likely going to struggle to evaluate the quality of the integrations and the amount of support necessary and available too."}),"\n",(0,a.jsx)(t.p,{children:"Consensus provides little relief. As Dan writes, \u201CEven after selecting the consensus best product in the space from the leading (as in largest and most respected) firm, and using the main offering the company has, the product often not only doesn't work but, by design, can't work.\u201D"}),"\n",(0,a.jsx)(t.h2,{id:"buy-vs-build-as-a-false-dichotomy",children:"Buy vs. build as a false dichotomy"}),"\n",(0,a.jsx)(t.p,{children:"The build vs. buy framework often fails because the \u201Cvs.\u201D implies a black-and-white comparison between building software from scratch and buying vendor software that\u2019s effectively a black box."}),"\n",(0,a.jsx)(t.p,{children:"Once you decide you only need a commodity feature, you start to treat the feature as a solved problem that\u2019s solved by an efficient market. And once you assume that, the consensus default becomes the obvious choice."}),"\n",(0,a.jsx)(t.p,{children:"There are two misconceptions buried in the false dichotomy:"}),"\n",(0,a.jsxs)(t.ul,{children:["\n",(0,a.jsxs)(t.li,{children:["To ",(0,a.jsx)(t.em,{children:"build instead of buy"})," is to build from scratch."]}),"\n",(0,a.jsxs)(t.li,{children:["To ",(0,a.jsx)(t.em,{children:"buy instead of build"})," is to get a complete solution in one package."]}),"\n"]}),"\n",(0,a.jsx)(t.p,{children:"In the first misconception, we tend to treat the process of building software as building from the ground up. Building tends to get associated with wastefulness or over-indulgence. This is a shallow way to think about this option, however, considering how many ways you can adopt open source components, buy component parts you can build with and adapt, or build on extensible tools and platforms."}),"\n",(0,a.jsx)(t.p,{children:"And when you purchase component parts from smaller vendors instead of buying \u201Ccomplete\u201D packages from large vendors, you often get to work more closely with the vendor and shape the product in a way that works for you (and for other customers like you). A vendor option can then be customizable out-of-the-box and customizable long-term as you work alongside the vendor."}),"\n",(0,a.jsxs)(t.blockquote,{children:["\n",(0,a.jsxs)(t.p,{children:["Customization of the log in and authentication workflow, using our editable flows, stages, and UI elements, is a core out-of-the-box feature of ",(0,a.jsx)(t.a,{href:"https://goauthentik.io/",children:"authentik"}),"."]}),"\n"]}),"\n",(0,a.jsxs)(t.p,{children:["In the second misconception, we tend to assume that the offered solution is complete and that buying a product merely involves breaking out the company credit card. That might be what the vendors pitch but more often than not, there are significant costs to maintenance and integration. Duncan Greenberg, Vice President at O
1scar Health, has ",(0,a.jsx)(t.a,{href:"https://medium.com/oscar-tech/the-many-pitfalls-of-build-vs-buy-5364f49a4fed",children:"argued"})," that \u201CThe choice is also often better seen as buy and maintain or buy and integrate\u201D because, he writes, \u201CSome amount of building is always required.\u201D"]}),"\n",(0,a.jsxs)(t.p,{children:["And while some of these costs can be written off as short-term, others linger. Will Larson, CTO at Carta, ",(0,a.jsx)(t.a,{href:"https://lethain.com/build-vs-buy/",children:"writes that risks include"})," \u201Cthe vendor going out of business, shifting their pricing in a way that\u2019s incompatible with your usage, suffering a severe security breach that makes you decide to stop working with them, or canceling the business line.\u201D"]}),"\n",(0,a.jsxs)(t.p,{children:["Even open-source and open-core components can pose this danger. Consider HashiCorp\u2019s recent ",(0,a.jsx)(t.a,{href:"https://twitter.com/HashiCorp/status/1689733106813562880?s=20",children:"controversial licensing change"}),"."]}),"\n",(0,a.jsx)(t.h3,{id:"differentiation-is-not-always-obvious",children:"Differentiation is not always obvious"}),"\n",(0,a.jsx)(t.p,{children:"Finally, one of the most misleading aspects of the typical buy vs. build framework is how it leans on an idea that\u2019s hard to define: differentiation."}),"\n",(0,a.jsx)(t.p,{children:"In the original framework, startups are supposed to build only the features that differentiate their products from other products or that otherwise make them stand out and feel valuable to their target customers."}),"\n",(0,a.jsxs)(t.p,{children:["There\u2019s a compelling logic to this because it often makes sense to devote most of your resources to a single opportunity instead of spreading yourself thin. When you start to achieve product/market fit, the market \u201C",(0,a.jsx)(t.a,{href:"https://a16z.com/2017/02/18/12-things-about-product-market-fit-2/#:~:text=The%20question%20then%20is%3A%20who,organically%20(i.e.%2C%20without%20any%20advertising)",children:"pulls product out of the startup"}),".\u201D And when that happens, it makes sense to work in that direction rather than distracting yourself with other tasks."]}),"\n",(0,a.jsx)(t.p,{children:"The trouble is that the directive to build customer-facing features isn\u2019t always a good framework. Netflix, for example, built the whole idea of chaos engineering because they couldn\u2019t buy the kind of resilience they needed. Customers would benefit but most wouldn\u2019t even notice; still, they built."}),"\n",(0,a.jsx)(t.p,{children:"This is another way the efficient market hypothesis can lead us astray."}),"\n",(0,a.jsx)(t.p,{children:"Sometimes, even industry-leading vendors aren\u2019t a good fit. They might be missing features you need; they might charge exorbitant prices for your usage levels or for essential features like SSO; and they might not be iterating fast enough to keep up with changing demands."}),"\n",(0,a.jsxs)(t.p,{children:["The more carefully you think not only about ",(0,a.jsx)(t.em,{children:"what"})," differentiates you but ",(0,a.jsx)(t.em,{children:"how"})," you can make [X feature] into something that differentiates you, the more you\u2019ll find reasons to build."]}),"\n",(0,a.jsx)(t.h2,{id:"security-is-90-execution-and-10-innovation",children:"Security is 90% execution and 10% innovation"}),"\n",(0,a.jsx)(t.p,{children:"One of the best reasons to buy software is because a vendor is naturally incentivized to iterate, innovate, and keep up with a changing market (a market that likely isn\u2019t yours but may feed into yours)."}),"\n",(0,a.jsx)(t.p,{children:"It would be obviously foolish, for example, to try building your own LLM instead of working with OpenAI. They\u2019re already far ahead and they\u2019ve built a machine for staying ahead and going faster."}),"\n",(0,a.jsx)(t.p,{children:"This dynamic, however, isn\u2019t true across many markets. Unlike AI, where most of the market feels like whitespace, modern security concerns are fairly well mapped out. There are many issues, of course, and many gaps in the market remain, but there aren\u2019t many paradigm shifts on the horizon nor problem areas that still require pioneers."}),"\n",(0,a.jsxs)(t.blockquote,{children:["\n",(0,a.jsx)(t.p,{children:"We\u2019re not doing brain surgery, in other words; we\u2019re matching prescriptions to known diagnoses."}),"\n"]}),"\n",(0,a.jsxs)(t.p,{children:["In security, where the typical build vs. buy framework perhaps works the least well, security team
1s can turn into pilots and drivers of tools instead of engineers. Adrian Sanabria, Director of Product Marketing at Valence Security, ",(0,a.jsx)(t.a,{href:"https://medium.com/@sawaba/when-to-purchase-a-solution-to-your-cybersecurity-problem-86de1fa203ba",children:"explains that many security teams"})," have \u201Cmistaken a bill of goods for a security program.\u201D In the process, he writes, there become \u201Centire security \u2018teams\u2019 that are little more than babysitters for a particular product the company owns.\u201D"]}),"\n",(0,a.jsx)(t.p,{children:"And this is where the opportunity to build (or customize) instead of buy exists. In a mature industry, where standards are stable and most problems have at least broad solutions, it often makes more sense to build a feature in-house so that you can execute it as well as possible."}),"\n",(0,a.jsx)(t.p,{children:"There comes a point where the creation and implementation remaining to be done is best done by the people closest to the precise problem in its exact context. In the security industry, success depends more on a granular understanding of the problem than sheer innovation."}),"\n",(0,a.jsx)(t.h2,{id:"lets-make-identity-fun-again",children:"Let\u2019s make identity fun again"}),"\n",(0,a.jsx)(t.p,{children:"We can make identity \u2013 as well as many similar problems \u2013 fun again. We can resist defaulting to industry leaders and insist on building custom solutions or building on top of products that will grow with us."}),"\n",(0,a.jsx)(t.p,{children:"The goal isn\u2019t to flip our defaults and start building everything from scratch. The goal is to reexamine our building and buying criteria and recontextualize them in our industries, use cases, and particular needs. The more we do so, the more we\u2019ll find that building is a better path than we might have guessed."}),"\n",(0,a.jsx)(t.p,{children:"And even if building isn\u2019t the right option, reconsidering our choices and our decision criteria will help us figure out how to search for better vendors and how to fully evaluate them."}),"\n",(0,a.jsx)(t.p,{children:"For years, we\u2019ve tried to avoid building as much as possible and it\u2019s an extreme that is worth resisting or at least questioning. But as someone who\u2019s building around identity every day, I can assure you it\u2019s more fun than you\u2019d guess and more rewarding \u2013 both for you and your users."})]})}function u(e={}){let{wrapper:t}={...(0,o.R)(),...e.components};return t?(0,a.jsx)(t,{...e,children:(0,a.jsx)(d,{...e})}):d(e)}},23735(e,t,n){n.d(t,{A:()=>i});let i=n.p+"assets/images/image1-629e61d243a0c88d54ab0fda2a16af41.jpg"},64701(e,t,n){n.d(t,{A:()=>i});let i=n.p+"assets/images/image1-629e61d243a0c88d54ab0fda2a16af41.jpg"},23191(e,t,n){n.d(t,{R:()=>s,x:()=>r});var i=n(92990);let a={},o=i.createContext(a);function s(e){let t=i.useContext(o);return i.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function r(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(a):e.components||a:s(e.components),i.createElement(o.Provider,{value:t},e.children)}},31761(e){e.exports=JSON.parse('{"permalink":"/blog/2023-08-16-lets-make-identity-fun-again","source":"@site/blog/2023-08-16-lets-make-identity-fun-again/item.md","title":"Let\u2019s make identity fun again (whether we build it or buy it)","description":"Identity \u2013 whether we\u2019re talking about internal authentication (think Auth0) or external authentication (think Okta) \u2013 has become boring.","date":"2023-08-16T00:00:00.000Z","tags":[{"inline":true,"label":"build-vs-buy","permalink":"/blog/tags/build-vs-buy"},{"inline":true,"label":"SSO","permalink":"/blog/tags/sso"},{"inline":true,"label":"third-party software","permalink":"/blog/tags/third-party-software"},{"inline":true,"label":"identity provider","permalink":"/blog/tags/identity-provider"},{"inline":true,"label":"vendors","permalink":"/blog/tags/vendors"},{"inline":true,"label":"security","permalink":"/blog/tags/security"},{"inline":true,"label":"authentication","permalink":"/blog/tags/authentication"}],"readingTime":11.89,"hasTruncateMarker":true,"authors":[{"name":"Jens Langhammer","title":"CTO at Authentik Security Inc","url":"https://github.com/BeryJu","page":{"permalink":"/blog/authors/jens"},"imageURL":"/img/people/jens.jpeg","key":"jens"}],"frontMatter":{"title":"Let\u2019s make identity fun again (whether we build it or buy it)","
1slug":"2023-08-16-lets-make-identity-fun-again","authors":["jens"],"tags":["build-vs-buy","SSO","third-party software","identity provider","vendors","security","authentication"],"hide_table_of_contents":false,"image":"./image1.jpg"},"unlisted":false,"prevItem":{"title":"My hobby became my job, 50% extra pay, just needed to let go of GPLv3","permalink":"/blog/2023-08-23-my-hobby-became-my-job"},"nextItem":{"title":"The tightrope walk of authentication: a balance of convenience and security","permalink":"/blog/2023-08-09-the-tightrope-walk-of-authentication"}}')}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.