SourceForge Podcast

Authentication & User Management Software: FusionAuth

Slashdot Media Episode 127

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 39:16

FusionAuth is an API-first CIAM platform that gives businesses complete control over authentication, authorization, and identity for users, services, and AI. Deploy it anywhere, scale without unpredictable pricing, and secure complex environments without sacrificing flexibility, performance, or data sovereignty.

In this episode, we explore why identity is no longer “just a login form” but critical infrastructure for security, user experience, and business risk. Dan Moore from FusionAuth breaks down the difference between authentication and authorization, why building your own login system is usually a bad idea for production, and how deploy-anywhere identity gives teams more control over data, upgrades, and reliability. The conversation also looks ahead to AI agents, arguing they need separate identities and deterministic guardrails so systems can safely tell humans and agents apart.


One especially useful takeaway is that the next wave of identity will be shaped by both passkeys and agentic workflows, but passwords aren’t disappearing anytime soon.

Follow SourceForge:

SourceForge.net - https://sourceforge.net
SourceForge LinkedIn
SourceForge X (Twitter)
SourceForge Facebook

Interested in appearing on the SourceForge Podcast? Contact us here.

The SourceForge Podcast is the world's largest B2B software podcast.



SPEAKER_00

Hello everyone and welcome to the SourceForge podcast where we talk to leaders and builders behind today's most interesting B2B software companies. I am your host, Bo Hamilton. Now I've got a quick question for you listeners and viewers. How many times have you logged into something today? Maybe it's your email, bank, maybe it's Slack or Microsoft Teams, probably a dozen times uh before lunch without even really thinking about it. But all of that invisible wiring behind every login screen is an entire industry, and that is identity and access management. And it's quietly become the front line of cybersecurity. Roughly two-thirds of cyber attacks now start with identity, uh stolen passwords, and compromised credentials. Um and one security researcher actually put it um as like attackers aren't breaking in anymore, they're just logging in. So um that's an interesting way to phrase things and a good setup for today's episode. And um, it's gonna get a lot more interesting on that front because it's not just humans logging in, AI agents are on the horizon. They're actually already here in a lot of cases, um, but they're ready to sort of book our flights and manage our accounts. So um the question is how does a website tell the difference between you and your AI? And who makes sure it doesn't go rogue with your credit card, right? That would be a bad scenario. Um, and that's the world where our guest lives in. Dan Moore is the senior director of CIAM, SIAM strategy and identity standards at Fusion Auth. And uh don't worry, we will make him translate that title for us. But SIAM is customer identity and access management, the login technology for your customers, not your employees. Um, Fusion Auth's twist is a deploy anywhere philosophy. You run it in the cloud, on-prem, wherever your data needs to live, so companies keep full ownership of their users' identities. And uh in today's episode, we're gonna get into the difference between authentication and authorization, which is um there's there's a difference, and a shocking number of people get the two confused. And then we're gonna get into why you should think twice before building your own login system and where identity goes in this world full of AI agents. So we've got a lot to discuss. Um, I know that was kind of a wordy introduction. Without further ado, let's go ahead and bring in Dan from FusionNoth. Dan, welcome to the podcast. Glad you could join us. Yeah, thanks for having me. So, um, Dan, let's let's start with your title. Uh, your title is Senior Director of SIAM Strategy and Identity Standards. Uh, I'll say it once in full, and but maybe you can translate it for us. What does your sort of day-to-day actually look like? And how did you find your way into the identity world?

SPEAKER_01

Sure. Yeah, this is um, it is a lot to say. And so sometimes I shorten it. But basically the idea is I kind of have like big probably three main responsibilities. Uh, the first is to look out over the wider ecosystem around customer identity and access management and see what our competitors are doing, see what our customers are asking for. And interesting thing about identity as opposed to some of the other areas of uh software development is that standards are a key part of it. So that's the second part of my job, which is to monitor and interact with the standards wherever they're being set. So that could be the Internet Engineering Task Force, the Open ID Foundation, um the Agentic Identity, I believe it's the Identi Agentic Identity Foundation. Um, that's a newer one. And, you know, I'll be honest with you, I don't interact with all these, but I definitely am reading about the uh reading what happens and uh following the mailing lists. And then the third part is to take all that and funnel it into Fusion Auth and determine kind of what makes sense to invest in from a product perspective and what is an important thing for us to weigh in on from a marketing perspective.

SPEAKER_00

Gotcha. Okay, yeah. There's I mean, there's so much to stay on top of, so many acronyms, uh, trends, um, all these different moving pieces in the in the industry right now. Um and you've been at this for you know over 25 years in software, consulting, you know, uh working with startups, engineering. Um so um yeah, thanks for breaking that down with us. I'm really excited to have you here and like pick your brain about uh this industry some more. So you you dropped the um you got the the title, uh Siam. Um before we we go any further, maybe you can help us sort of define some more terms because you've you've told me that a shocking number of people, even in tech, they mix up the two words at the heart of all this authentication and authorization. Um can you just help us explain like what's the difference and why does getting it wrong actually matter?

SPEAKER_01

Yeah, and it's totally understandable, right? I mean, don't ask me to distinguish between you know different types of memory chips, right? Um so I totally understand why a lot of developers, even though they're interacting with this, uh these concepts, they don't really understand the nuances. And I didn't before I started in this area, or I kind of had some you know idea, but I didn't really understand everything. Um not that I understand everything now, but I didn't understand as much as I do now. Um so authentication is who you are, and authorization is what you can do. So the way I like to think about it is that uh an ID card is an example of authentication, right? It shows if I present my driver's license or some other form of government-issued ID, that says uh who I am, but it doesn't necessarily mean that I can get anywhere or I can do anything. Whereas a car key, in my mind, is like the purest example of authorization, where it's just totally distinct from identity, because but just by holding a car key, I can go to the car and turn it on. Um and so those are offline examples in the online world, uh, they're very often paired because most of the time, before you can determine what someone can do, which is authorization, which is a key part of securing your application, you need to know who they are because that has ramifications. Not always, and there's some edge cases, but that's the main flow inside software development, inside online applications. And that is why I think a lot of people conflate the two.

SPEAKER_00

That's a good way to put it. Yeah, I like that metaphor. It's so identity is really, you know, two questions. Who are you and and what can you do? And I feel like um most of us only ever sort of encounter this stuff when we, you know, I don't know, log into like the old school visualization is like using your badge to get into work in the morning or something like that. But uh that's like a whole different, actually, a whole different quarter of the industry where you guys actually play and are focused on, and that's um workforce identity, employees actually logging into company tools, um, sort of the the Okta side of the world. Um, FusionAuth is in customer identity. Um, and correct me if I'm wrong there, um, but uh what makes managing customers' identities a fundamentally different problem?

SPEAKER_01

Yeah, and you got it 100% right. Fusion auth focuses on the customer side of things, and there are other companies like Okta that focus on the workforce side of things. And I think that the if I had to boil the difference down to one thing, it's expectations about a login system are different when someone is paying you than when you were paying them. So with employees, you can enforce things in a way that you can't with customers because customers can go someplace else. Um, there's a lot of follow-on from that uh in terms of the user experience that's expected, uh, the speed, the performance, uh, but there's also some more subtle uh ramifications, one of which is the kind of permission structure and the scaffolding, the and the integrations with tools are much greater than uh for workforce or for employees than they are with customers, right? If you think back to a lot of your interactions with uh not with Slack and all the things that you mentioned when you did your intro, but actually the last time that you interacted with uh an e-commerce site or a restaurant to you know order something online, the interaction was pretty simple, right? You log in, you might have done one or two things, and then you got out, as opposed to Slack when you're you're in it all day. Um so that is those those are kind of the two key things. It's it's what the expectations are, and then it's like the complexity of the authorization model behind the application.

SPEAKER_00

Totally. Yeah. And it's like if if it's too complex, it's too burdensome, um, you're gonna put off a lot of um, you know, customers. But at the same time, um, if you're an employee, you you just have to you you have to deal with it. You have to find a way to get through. I mean, that you're being paid to. Um if if so it's kind of interesting. Like the login screen is really both a like a security checkpoint and this sort of sales funnel at the same time, depending on on kind of the how you look at it, the type of user you are, if you're an employee or a customer. Uh, and I think this is where I think every sort of founder and developer listening has had sort of the same like thought. And it's like it's just a login form. How hard can it be? I'll build it myself. Um, but I want to hear from you like, why is that a bad idea? Like, where does rolling out your own um auth go wrong? And then when does a team know it's it's time to bring in a platform like Fusion Auth?

SPEAKER_01

Yeah, and I think that that actually relates to what you were saying before, where there's security and conversion ramifications for a login screen. I call the login screen the front door of your application. And you know you can a hundred percent create or build a front door, but you are often going to be better served by going and buying that front door from a hardware store. Uh, because it will be cheaper, it will be um more secure, it will uh look better, it will you'll have more options and more varieties. But sorry, I like the offline analogies just because the online analogies you know get abstract pretty quick. But for people who definitely, you know, we definitely have uh plenty of customers who come to FusionAuth and say, you know, have built their homegrown system. Sometimes it's it's built from scratch. Oftentimes it's on top of a library or uh something that's part of their uh application framework. But the triggers we see are we can't add features fast enough. And with a tool like Fusionoth, you actually can turn on features without code, right? You just enable um one-time refresh tokens. And I can dig into what that is and why that's valuable, but I can say that uh sometimes people want that, sometimes they don't. But if you're building your own, you have to build that functionality, whereas it's a switch you can flip inside FusionAuth. Uh sometimes it's an availability story. So uh authentication breaks in production and people are running around trying to fix it, and they don't have a battle-tested authentication system in the same way that FusionAuth is, which has been used by thousands of developers uh across the world. Another thing is that they need to add features that are specifically related to federation, so that'd be um in certain use cases, you want to be able to add like login with Google or log in with um Antra or Okta. And uh the last one that is really kind of a driving force is just the risk around holding your own PII and the security that you need to have for taking care of your customers' precious data.

SPEAKER_00

So what I'm hearing is yeah, there's a lot of behind the scenes things to build in and consider when you're going, um, if you're gonna go, you know, go in on your uh build this on your own. And a lot of times it's it's just overwhelming. It's too daunting of a task, which would require you to partner with um like FusionAuth, for example.

SPEAKER_01

I want to push back on that a little bit, right? Because you know, we're developers uh and we understand that like we take on daunting tasks all the time. So I think that it's it's it's deeper than you think it is, but so what? Lots of things are. But the other question that I think you really should ask yourself is what's the opportunity cost? And if you're an engineer or engineering manager, you also need to be thinking, hey, is this adding value to my application that's um useful and distinct? Or is this adding value to my application that is not? And obviously adding authentication to your application is is definitely adding value either way, right? But the question is, is it unique? And there are very few times I've ever heard someone say, oh my God, you gotta check out Application XYZ because their login system is amazing, right? That's a very rare thing. So um, I am not trying to dissuade anybody from building their own login system for a toy application. I did that, and I think you learn a ton. Uh, but I think that if you're talking about a production system, the same way that you wouldn't in 99.99% of situations build your own database, you shouldn't build an authentication system. So Gotcha.

SPEAKER_00

Yeah, no, that's a that's a good um good distinction there. And it's I I guess the way I'm I'm just thinking of like the login form, it's it's like the form itself is the easy sort of 5% of the equation. The the hard part is the 95% you don't see, the password hashing, uh, multiple factor authentication, account recovery, all accession management, like you mentioned token security, all these things. But but yeah, it's just um uh and then you can you gotta think of the stakes, right? The stakes are wild. I was I was actually reading uh in prep for this interview, is um that the average identity breach costs about $1.64 million to recover from. And that seems kind of low. Um, I mean, it just depends on the on the business and in and industry, but that's just the average. So um, you know, the quick sort of login form from from three years ago could really end up being the most expensive code your team has ever ever wrote, really. And yeah, you can't just recover from that overnight. No, that's that will that will haunt you for years. So say I'm convinced that I'm I'm buying and not building. Um now I'm staring at a crowded shelf of of different sort of vendors. Um what jumped out to me with you guys is most vendors uh say, like, you know, give us give us your users, we'll host them in the cloud. Fusion auth sort of went uh a different direction with this deploy anywhere model. Um you run it on your own infrastructure, own your own, like own your data outright. Um why why build a company around that? And like who does that really relate to and matter?

SPEAKER_01

I mean, I think that the reason that we built this is because our founders were developers and they understood that this was such an important architectural component. There's the data sovereignty side that you kind of mentioned, right, where you want to own your data. There's also just the performance side, too, right? Sometimes you may want to have availability and operations be in your purview as a developer or DevOps team, but yet still benefit from the features getting delivered uh on a regular cadence. So I think that is one of the ways that we stand out. Uh, and that's and I will say that a lot of our customers are happy to have us host for them. And so we operate for them in our uh hosted cloud. Uh, but what they buy with the self-hosting model is optionality. So we never hold on to your data, and we I've seen this happen. We have customers who leave for a variety of reasons, right? They might be trying to minimize costs and so they're going to self-host, or they might be shutting down, and so they want to, you know, take their user data and make sure that it's taken care of. And in all those cases, we are happy to give you all of your data because it's yours. You own it, and you can continue to run the exact same version of Fusionoth and exact same software in your own on-prem environment if that suits your needs. So I think that answers your question. Um, yeah. And I will say, like, you know, uh, that is always uh an issue with any kind of major architectural component in software, and there's a spectrum because on the far side is like the pure place, where you have little responsibility, but like, you know, Stripe, for example. Like you have little responsibility, but you have little control. And then there's, I'm gonna host everything in my own environment and I'm gonna like run it on bare metal. And Fusion Off exists on that spectrum, you know, in a couple of places. Um, even in the cloud, for example, we actually let you control the version upgrade. So you aren't forced to upgrade to a new version. You can actually put it into your quarterly planning and you know, do your testing and uh make sure that, again, this crucial application component doesn't fall over because of you know some edge case that you've uncovered that um you know doesn't exist uh in our custom.

SPEAKER_00

Yeah, I I like that. I like that approach. And it just it it's it's sort of an inversion from what you typically see. It's like most most software companies sort of brag about all the the data they have on their customers, and your pitch is really just uh basically like we we don't know nothing about your users by design. That's that's a a specific like design choice. Um and I think that's a it's a good um selling point. You know, I think it resonates with developers and being developer focused um kind of speaks uh it shines through that decision. So okay, so we've talked, we've kind of talked about you know um who you are, but earlier that mention uh you mentioned that second question of like what are you allowed to do? And that's where FusionAuth has has been making some big moves lately, um, bringing in fine-grained authorization into the same platform as authentication. Um historically speaking, developers sort of combined the two um uh separate. They had like, or they they bolted together separate systems for each, let's say. Um, why should they be sort of unified um in 2026? And and why why is now the time to do it?

SPEAKER_01

Yeah, and so Fusionauth has always supported role-based access control um as kind of a unified feature, but the world is growing more complex and applications growing more complex. And we definitely heard from our customers that they had authorization models that they um wanted Fusionoth to help with that were our back role-based access control just broke down for. And over the last, I'd say, four or five years, ever since the really the Google Zanzibar paper was the big thing that that caused authorization as a service to really explode, um, although there are some other standards in the space too, um, there's been the existence of kind of standalone authorization servers. And the same way the Fusion Auth is a standalone authentication server that's separate from your application, these authorization servers are as well. And, you know, 15 years ago, authorization, if it was either kind of embedded in if-then statements in your code or you know, maybe used a framework or some library to kind of abstract that out. Well, this is that next step. And so by making this available uh paired with FusionAuth, you get the ability to kind of build these more complex authorization models while still uh getting the performance and the feature richness that you need. Uh, one thing that is worth noting is that self-deployability is even more important for authorization servers because you can imagine that an authentication event happens and then you have a session for a certain period of time. And so, you know, God forbid that authentication server goes down because new people can't authenticate, but like the existing people can still interact with your application. But an authorization server, you should be checking that every time anybody interacts with you at all. And so lots of times we see people maybe using FusionAuth hosts in the cloud and then using FusionAuth FGA inside their uh, you know, right parked right next to their application because they want to have operational control of that because it's even more tightly coupled to their application.

SPEAKER_00

So yeah, it makes sense why you'd you'd want one system sort of answering both of those questions and having this sort of paper trail with uh who's who's being authorized and what's happening. You mentioned the people being authorized, but but uh increasingly uh nowadays it's it's not so much people, right? That's it's it's AI agents. Um hope you like that segue. I want to get into that topic because that's it's it's super exciting. It's everyone's talking about right now. It's it's AI agents. They've I mean for a last couple of years or so, it's it was on the horizon. Now they're they're here and it's they're really only gonna grow in prevalence, um, I would say. But um, you know, we we are really heading towards that world where, you know, an agent, uh my agent, everyone's gonna have their own agent, books, you know, my flights and buys my train tickets. Um in that world, what what happens to identity? How does a website, you know, tell my agent apart from me and and how do you stop it from doing things that I never authorized?

SPEAKER_01

So there's a lot to dig into there, right? Certainly a lot longer than we have to talk about now because I talked at the beginning about how I'm you know watching the standards, and I will say that there is some work. Uh there, well, first of all, there's this explosion of people thinking about this, and then there's some work to like bring standardization to this space. But um, you know, at the end of the day, our opinion is that you need to have a separate identity for your agent, and that is based on the the ability for other systems to like differentiate, right? Because if that agent has your ID card and is running around as you, then there's no way for a system to to differentiate. So that's where an agent, say, driving a browser, really worries me because there's no, I mean, there's heuristics you can do, right? Like how many requests is it making a second? Um, is it operating 24 hours a day that you could use to distinguish those, but it's not for real, or you can't do that um in a way that is 100% accurate. Um so we think that agents should have separate identities. We also think, and this follows on from that, is that there should be deterministic guardrails around agents. And this is still definitely in development, but we think that there's a space for you to deterministically delegate your things that you want to do to agents. So in your example of, or an example of like buying train tickets, you may put guardrails around that. You won't just say, buy me any train tickets because you have desire to go to um, you know, city A, not city B. So that's one guardrail. You'll probably have a max price. You'll definitely have like timing. Um, don't send me a two in the morning, don't buy tickets for then. And so um there's a lot of scope for creating those guardrails. Um, and I think that is going to be a partnership between the people that are building the agents, but also all of the systems that are gonna be interacting with those agents. And we've seen an explosion in protocols like MCP or even just plain old APIs uh that, you know, I don't know if applications that were aiming purely at consumers, you know, had the same incentive to expose that machine readable uh functionality that they do now.

SPEAKER_00

All right, Dan. Now there's always this uh sort of tension between security and convenience. How do you help companies make login safer without making it all the more frustrating for users?

SPEAKER_01

Yeah, this is really important, especially in the SIAM context. So I one thing you can do is you can layer on risk signals to an authentication event and then take steps like challenging for MFA if someone logs in from a new IP address or a um at a time that isn't usually um that they don't usually log in at. Um and we actually just released a new feature called Intelligent MFA, which does exactly this. It takes 10 risk signals and uses them to determine whether an authentication is low, high, or medium risk and issues MFA challenges in a configurable way. You do that. Another thing you need to do is meet your user population where they are in terms of authentication methods. Some folks want passwords, some want passkeys, some want email links, um, some business owners want integration with tools like Entra or Okta. And the last thing I think is important is FusionA thinks of itself as a set of best practices building blocks for authentication. And for many of our customers, what is out of the box works great, but other times you need to extend it. And so we offer integration points like webhooks and API calls and the ability to run JavaScript snippets during the authentication workflow. And so having that lets you, again, tune your authentication um experience to what your users want.

SPEAKER_00

Gotcha. Okay. Intelligent MFA sounds like a powerful new capability that uh prospective clients should be interested in looking at looking into and checking out. Okay, so would you would you uh I mean there's some protocols that are starting to sort of um stand out um and become universally adopted. Is are you kind of waiting for um some sort of like uh government framework intervention to kind of help standardize things or just kind of waiting for the private market to kind of figure out the best approach?

SPEAKER_01

Yeah, I mean, I would say the private market is definitely there. And then, you know, to be honest with you, this feels a ton like a bigger version of some of the explosion of APIs that that happened in the early 2010s when mobile apps got big. And so I see some of the same mistakes and some of the same excitement that's coming on. But um, yeah, I I don't think that the government um has a huge role in that. And even in the normal identity standards for customers, um, you know, certainly for the military and critical infrastructure, the government has a role 100%. But like, you know, even looking at some of the places I mentioned earlier, the IETF and the Open ID Foundation, those are all private bodies coming together and building interoperable standards. Um, sometimes NIST gets involved and kind of like, we'll do best practices. But even with NIST, the authors tend to be from private companies who are just kind of gathering under the um the imprimatur of NIST to like do some um standards work to like make everybody's lives easier.

SPEAKER_00

So it's like they the the government probably have more you know interest in like setting the requirements for you know robust privacy and security standpoints, but as far as the actual like specific wiring of the framework and the protocols, let's leave that to the industry.

SPEAKER_01

That's a great, that's a great point. Yeah, I kind of ignored the privacy aspects and the compliance aspects. I guess I nodded to it with the military stuff, but yeah, definitely around the rights of of human beings and especially more vulnerable human beings like miners, the government 100% has a role and has played a role. Um I think that the AI agent stuff is new enough that right now, you know, I'm not aware of any legislation around gentic AI. There's definitely legislation around like what you know, I think New York has a law about like if AI reviews your job application, you need to know about it or it needs to be kind of uh laid out, you know, the principles then. I'm all on board with that. I think that setting that boundary around like who can own my data is a really important thing for the government to weigh in on. But as far as kind of the nuts and bolts of like how AI agents are connecting to this travel agent site or that travel agent site or that travel site, you know, that to me is a little in the in the in the weeds for the government to get into.

SPEAKER_00

Yeah, kind of early, early stages at least, too. Yeah, it's you kind of just have to wait and see and see where it goes. And um uh yeah, I mean, there uh this this topic, we uh we could, like you're saying, like lead a whole episode, a multi-part episode on on this topic alone, but it's it's just fascinating to think about. Um and I wanted to get your your you know take on it. Um uh because like I know the most of the internet now is like or at least more than 50% is is driven by bots, I believe, is officially as of like earlier this year. Um and some parts are are more overwhelmed than others. Um and then I saw a stat that machine identities can already outnumber humans um by human ones by as much as uh 100 to 1. And so, you know, weak management of those non-human identities is becoming like this a huge share of breaches. Um so you know, these bots are they're they're they're already logging in and they're already, you know, and we're just now sort of figuring out the rules, so to speak.

SPEAKER_01

And I will say that actually ties back to the previous thing we talked about with fine-grained authorization, because human beings you can think of as um non-deterministic but slow, and traditional software interacting with systems is deterministic but fast, but agents are kind of non-deterministic and fast. And so they will find, they will poke holes in your authorization framework in ways that you don't expect. And so you really need that to be deterministic. Um, you already should have been you know thinking about that from a human perspective, but it just uh becomes even more important in an agentic world.

SPEAKER_00

Yeah, yeah, good point. Yeah, it's and it's it's one of those things too, where as these these capabilities, these like really capable LLMs and agentic systems are are being kind of deployed, there's gonna be this big spike of of like everyone freaking out and and rushing to adopt protocols and like remedy various issues. Um and in theory, hopefully it'll kind of level out a little bit and things will kind of settle, settle down, hopefully.

SPEAKER_01

But we we've seen this story before, right? I mean, you know, um it it by the way, it's super exciting, and I'm really uh glad to be part of it. But yeah, it does feel like there's a little bit of like churn and you aren't sure which you know um frameworks and protocols and decisions you know um need to be, you know, are worth your attention and which aren't. And that's part of my job is to like monitor that and kind of see what's getting adoption, what is getting uh people excited about our conferences, what are you know implementation patterns. And I think that's where Fusional can actually provide a lot of value to our customers is to say, actually, hey, you know, at least when it comes to identity, you know, we've got this, we have an opinion on this, we can help you build the right safe systems. Um and you basically, you know, you don't no one should outsource everything around their technology decisions, but we can be a partner to you in in making the right choice.

SPEAKER_00

Yeah. So so let's say, you know, five, 10 years out, maybe, maybe like three, four or five years out. What does what is logging in even look like? You know, because passwords have been sort of um like dying for a decade now, and and yet they're they're still here. I know like over on Slashdot will like frequently run stories about you know the passwordless future future. And uh that always gets a ton of engagement. People are like, oh no, they've been saying this for years. Um and passkeys are obviously gaining ground, agents are coming. So what actually changes for for regular people and like what sort of stubbornly stays the same?

SPEAKER_01

I mean, I will say that like telegrams were you could send a telegram until about like five years ago. So technology has a long, long life cycle, and and passwords. I said this uh recently to a friend. I was like, passwords are gonna be around for a long time because they have certain attributes that make a lot of sense and they're relatively easy to implement. And the people who are kind of building their own systems are probably gonna still be using passwords. Um, but I think that you will get more and more adoption of technologies like pass keys, which are just inherently more secure and have some ease of use benefits. Um and I think that also uh, you know, we're talking about agentics stuff. Like, I think that there will be agents built into your operating system and or your browser that will leverage an authentication event that you do with, and this is from the consumer perspective. I think the enterprise perspective is totally different. But like I think customers are or consumers are used to those two entry points, right? It's either your face ID on your iPhone or it's um, you know, conceivably logging into your Chrome browser. And from there, you can kind of build in that delegation piece. But I think that uh that for consumer-facing agents is just where the UX is gonna overwhelm any kind of other options.

SPEAKER_00

What does the enterprise side of things look like?

SPEAKER_01

I mean, there the customer is different, right? Like again, back to the employees uh get paid, consumers pay you. So I think it'll be more dictated top-down, the same way that um a lot of enterprises don't let you install any software you want on your laptop. They will dictate, you know, what uh APIs you can connect to, uh what protocols work, uh, which services you can connect to. And I don't think that that same kind of like level of constraint will be uh in the consumer world. Um there was a new, um, I think it's called XAA. There was a new enterprise manage OAuth protocol that just kind of got integrated into Cloud. And I think it's amazing for, and it basically lets you as an admin say, okay, I want to let you know, people in the engineering department connect to these A, B, and C services via uh model context protocol, and then I want to let the finance people connect to these services, and you can manage it all from within the central choke point, which is great for the enterprise. And we'll, I predict see zero adoption from consumers because consumers are totally disparate and they're not gonna, you know, maybe there's a small use case for like a family where like parents might like have some control over the um, you know, what a what a child has access to. But um it's just they're two, you know, really different worlds.

SPEAKER_00

Well, um uh Dan, this has been great. Thank you, thank you for um answering a lot of my like technical questions about fusion fusion auth and you know authentication. Um what's a what's a book, what's a podcast or some kind of resource that's really shaped how you think about your work or your leadership style?

SPEAKER_01

There's a ton uh that impact have impacted me, but the one that I would pick out that I would love for your listeners to check out is called Crossing the Unknown Sea, uh Work is a Pilgrimage of Identity, and it's by a British poet, and it really talks about living an authentic life and how work can be part of that. And that just made me understand that like being authentic, having difficult conversations, and asking for what you want and what you need, uh, as well as treating people how they want to be treated as opposed to how you want to be treated is a key part of leadership.

SPEAKER_00

I love that. That's awesome. Okay, so crossing the unknown sea, um, I'm gonna add that to my list. Um and authenticity is is really the the is so important right now. I mean, with from the you look at from um kind of more my background of like the content creator space and influencing space, it's like we're all looking for authenticity. Um and and we can see, you know, like when you AI, a lot of people don't like AI because it's not authentic, it's not created by a human, and like um there's that kind of uh divide there.

SPEAKER_01

Don't be afraid. And it is not easy to not be afraid, you know, because you have to be authentic, you have the flip side of authenticity is vulnerability. And if you aren't, you know, really displaying who you are, or when you do really display who you are, you are being vulnerable. So um I don't want to downplay how hard it is. It's it's not easy.

SPEAKER_00

So no, very very, very true. It's it's tough, especially when you you know you're putting it out there for you got commenters and um people, everyone has an opinion. Um, and so it can be tough. I know like this is hopefully relevant, but um also I I want to plug um you you literally wrote a book of your own, right? Letters to a new developer.

SPEAKER_01

I I'll give the the 30-second thing, which is basically I wanted to write a book that encapsulated kind of everything I'd learned over 20 years of being a software developer, apart from technology. So you're not gonna read letters to a new developer and learn about the latest React or AI framework or anything like that. It's gonna it uh I tried to make it um cover topics like community, um, how to learn, um, you know, first steps to take on a new job that will hopefully be timeless.

SPEAKER_00

Awesome. Okay, awesome. Yeah, we got two, two for the price of one here. We got two great resources um for listeners to to add to their list. So um that's great. And then the other question I have, um kind of getting back on track um with Fusionoth is if if listeners only remember one thing about Fusionoth from this conversation, uh, what would that one thing be? What would that one thing be like shouting from the rooftops?

SPEAKER_01

I guess I would say that I think most people and engineering teams treat identity like a utility. You pick a vendor and you forget about it until the renewable pops up or it goes down or the API changes and you're frustrated. But identity is critical infrastructure. It's just like a database. And that means that control isn't optional anymore. It means owning where you deploy, when you upgrade, and where your data lives is critical. Um, as application developers, as I'm sure a lot of your audiences is, uh, these are questions that you need to be asking when you're thinking about how to add that simple login form to your application.

SPEAKER_00

Well said. Own your identity infrastructure. I think that really, that really ran through this entire conversation. So um, Dan, this thank you so much for coming on and making identity genuinely just fun to talk about and insightful. So appreciate everything you shared with us.

SPEAKER_01

Yeah, thank you for having me. And I'd love to connect to any of your listeners that uh want to connect and chat more about identity or AI agents or uh you know work life balance authenticity.

SPEAKER_00

Perfect. Yes, absolutely. And uh they can find you over on LinkedIn and you can learn more about Fusion Auth over at FusionAuth.io. Um links will be down below in the description. Thank you all for listening to the Source Forge podcast. I'm your host, Bo Hamilton. Don't forget to subscribe, like, comment, all those fun things. Um, and look forward to the next B2B software related podcast. I will talk to you in the next one.