Summary
In this episode of the SourceForge Podcast, Dan Moore, Senior Director of CIAM Strategy and Identity Standards at FusionAuth, joins host Beau Hamilton to explain why the login screen is the front door of your application, and why most teams underestimate what sits behind it.
With more than 25 years in software, Dan breaks down the difference between authentication and authorization, makes the case against rolling your own auth in production, and looks ahead to a world where AI agents need identities of their own.
In this episode:
- Authentication vs. Authorization: Why an ID card and a car key are two different things, and why conflating the two creates real security gaps.
- Customer vs. Workforce Identity: Expectations change when the user is paying you instead of the other way around, which is why CIAM demands different UX, performance, and permission models than employee IAM.
- The Build-vs-Buy Reality: The login form is the easy 5%. Password hashing, MFA, account recovery, session and token security, and compliance are the other 95%, and the opportunity cost is rarely worth it.
- Deploy Anywhere, Own Your Data: How FusionAuth's self-hosting model gives teams data sovereignty, control over upgrade timing, and the optionality to take their user data with them at any point.
- Fine-Grained Authorization: Why RBAC breaks down as applications grow more complex, and why an authorization server, consulted on every single request, needs even tighter operational control than authentication.
- Identity for AI Agents: Why agents need separate identities from the humans they represent, and why deterministic guardrails matter when agents are non-deterministic and fast.
- Passwords Aren't Dead: Passkeys and biometrics are gaining ground, but passwords have attributes and a life cycle that will keep them around for years.
- Intelligent MFA: A new FusionAuth capability that scores authentication events across 10+ risk signals and issues MFA challenges accordingly.
Dan's one takeaway: most engineering teams treat identity like a utility, picking a vendor and forgetting about it until renewal or an outage. Identity is critical infrastructure, just like your database. That means owning where you deploy, when you upgrade, and where your data lives.







