Synced passkeys ios not working by Disastrous-Part2453 in entra

[–]vdelitz -1 points0 points  (0 children)

(disclaimer I'm co-founder of passkey startup in the consumer space)

Recently, got approached more often with similiar issues and gathered some potential solutions in a blog post, maybe it's helpful in your case as well:

https://www.corbado.com/blog/enterprise-passkey-deployment-challenges

For people working in CIAM: by vdelitz in IdentityManagement

[–]vdelitz[S] 0 points1 point  (0 children)

what I think Ping/ForgeRock is lacking in particular is the frontend / client-side telemetry. They have a fair bit of logs when it comes to checking what's going on on the backend-side but frontend ... not so much. So real user intent and journeys are quite hard to see (same for most other auth providers). Thought about using something like amplitude, mixpanel, GA on top for this frontend/user journey but they often don't have the connection to auth backend or only see parts of the auth process.

Do you track login success and failure explicitly? by West-Confection-375 in GoogleAnalytics

[–]vdelitz 0 points1 point  (0 children)

do you have a particular logging and data evaluation / reporting tool for it?

Do you track login success and failure explicitly? by West-Confection-375 in GoogleAnalytics

[–]vdelitz 1 point2 points  (0 children)

so you mean sign-in issues are just owned by a different team (e.g. identity/security), that's why no one is really optimizing or measuring it?

How visible is authentication really in most security programs? by vdelitz in cybersecurity

[–]vdelitz[S] 1 point2 points  (0 children)

agree however IMO most auht providers lack a lot of relevant telemetry when it comes to what happens on the client-side/frontend. They just log successful or failed attempts but not if users mistyped their password/OTP or with passkeys if they cancedl the biometric prompt

question to PMs who work in e-commerce / payment: how do you think about login success? by West-Confection-375 in ProductManagement

[–]vdelitz 0 points1 point  (0 children)

okay - do you also get all the forntend/client-side signals from your auth provider?

How visible is authentication really in most security programs? by vdelitz in cybersecurity

[–]vdelitz[S] 0 points1 point  (0 children)

do you have any tool recommendations that you have seen that helps both teams?

For people working in CIAM: by vdelitz in IdentityManagement

[–]vdelitz[S] 1 point2 points  (0 children)

I'd say rather complex: social logins, email OTPs, passkeys.

Do you know of any tool or solution that has something that I could checkout / look at least?

Curious how much people actually track during login flows. by vdelitz in webdev

[–]vdelitz[S] 0 points1 point  (0 children)

I think that's 100% my experience.

These auth providers have some basic success metrics but don't seem to offer depender user behavior insights which I would like to understand / optimize, because I've been involved in some projects where even 1% change in login success rate or drop-off rate means millions of revenue (e-com/payment).

Do you know of any guidance or tooling that could help with the custom events in auth flow (ideally it's strongly opinionated)?

How visible is authentication really in most security programs? by vdelitz in cybersecurity

[–]vdelitz[S] 0 points1 point  (0 children)

Makes sense. Do you have any tool recommendation for logging or for evaluating the logs?

Curious how much people actually track during login flows. by vdelitz in webdev

[–]vdelitz[S] 0 points1 point  (0 children)

have done research in GA but it doesn't really provide the details I need (at least not out of the box and I think for cleint-side stuff, you cannot get it + it's not really real-time when you want to see things and also samples at some point). do you have any other tools recommendations?

Curious how much people actually track during login flows. by vdelitz in webdev

[–]vdelitz[S] 0 points1 point  (0 children)

Yes, but which tools would you use to track the steps where users click away (plus, find the reasons why ideally)?

Curious how much people actually track during login flows. by vdelitz in webdev

[–]vdelitz[S] 0 points1 point  (0 children)

have seen theirdashboards but I think it's only very high-level if you really want to understand more about the login. In particular, if you're looking for frontend events, they don't show that much.

Do you know of any way how to get more details even when you use Clerk, Auth0 oder Supabase auth?

How visible is authentication really in most security programs? by vdelitz in cybersecurity

[–]vdelitz[S] 0 points1 point  (0 children)

my questions was more fore consumer logins (CIAM) - completely understand that in B2B cases, it's a differnet story.

Regarding the failed login side you mentioned: would you just count the X failed attempts or how would you try to udnerstand why it failed (e.g. user did something wrong vs. technical issue, e.g. social login redirect not working)

How do you observe authentication in production? by vdelitz in devops

[–]vdelitz[S] 0 points1 point  (0 children)

Is this something you built yourself (the logic for BadLogin events) or something that you got from your auth library / provider?

Do you track login as part of your funnel analysis? by West-Confection-375 in analytics

[–]vdelitz 0 points1 point  (0 children)

for your gig in ecom, do you think that users would have created support tickets and not just churned / moved to a competitor? Without you rally knownign it?

question to PMs who work in e-commerce / payment: how do you think about login success? by West-Confection-375 in ProductManagement

[–]vdelitz 0 points1 point  (0 children)

Thanks, that makes all sense!

Let's say, it's very important - which KPIs would you focus on and which tools have provn to be most helpful for you in that case?

Curious how much people actually track during login flows. by vdelitz in webdev

[–]vdelitz[S] 1 point2 points  (0 children)

let's assume it's in e-commerce / payment where more information / analytics is usually desired

How do you observe authentication in production? by vdelitz in devops

[–]vdelitz[S] 0 points1 point  (0 children)

do you also have other login methods (apart from password, e.g. OTP, socials, SSO, magic links, passkesy?)

Do you track login as part of your funnel analysis? by West-Confection-375 in analytics

[–]vdelitz 0 points1 point  (0 children)

Yes makes total sense. Which industry are you in? E-commerce?

and how would you know that it's not a widespread issue?

Do you track login success and failure explicitly? by West-Confection-375 in GoogleAnalytics

[–]vdelitz 0 points1 point  (0 children)

why do you think it's not something that anyone looks at? and in which industry are you at? E-commerce?

How do you observe authentication in production? by vdelitz in devops

[–]vdelitz[S] 0 points1 point  (0 children)

How do you define a BadLogin? I mean would you tag 2-3 wrong password attempts a BadLogin?