News, events & blog

Back

What Happens to Your Digital Service When Authentication Goes Down?

Authentication is usually taken for granted and, in many ways, almost invisible: the user chooses a suitable authentication method, verifies their identity, and continues using the service. But what happens when the authentication service itself stops working?
What Happens to Your Digital Service When Authentication Goes Down?
How can the eeID service help service providers to become more resilient to DDoS attacks? (photo: Canva)

What can we learn from a recent incident?

On 11 September, Estonia’s national authentication service was hit by a distributed denial-of-service (DDoS) attack, causing noticeable disruption for users for around 45 minutes. According to the Estonian Information System Authority (RIA), the service received nearly 86.1 million requests during the attack: more than one hundred times the normal traffic volume of around 765,000 requests per hour. Cloudflare’s protection measures blocked approximately 91% of the requests, but the remaining traffic was still enough to cause temporary overload.

For service providers, this incident is an important reminder: authentication is not just a feature on a login page, but a critical part of digital service infrastructure. Its availability therefore needs to be considered just as carefully as its security. Authentication can become a bottleneck that prevents customers from using a service, reduces revenue opportunities, and creates a negative user experience.

Authentication is a critical part of cybersecurity

When designing authentication, it is therefore important to think not only about how secure it is, but also about what happens if the authentication service becomes temporarily unavailable. Alternative authentication methods or fallback procedures should also be planned in advance.

Imagine a building with an extremely secure electronic door. The lock is difficult to break, and every person entering is reliably identified. But the building has only one entrance. If the door system stops working, it no longer matters how secure the lock is - the entrance itself is unavailable. Authentication can create a similar dependency on a single point of entry.

What makes the recent incident especially illustrative is that the disruption was not caused by a failure in the authentication technology itself, but by a DDoS attack. The purpose of such an attack is to affect service availability by overwhelming it with a very large number of requests. According to RIA, traffic during the attack exceeded normal levels by more than one hundred times. It was most likely not the first such incident, and it will not be the last.

This highlights an aspect of cybersecurity that can sometimes receive less attention than data breaches, passwords, or fraud: availability. If a customer cannot authenticate, they often cannot use the rest of the service either, even if the application itself is otherwise working perfectly.

The solution is redundancy

In the context of business continuity, resilience means having more than one option. In other words, building in redundancy. Using the door analogy, this means adding alternative entrances that can be used if the main entrance becomes unavailable because of a technical failure.

A more resilient architecture combines identity verification and authentication methods that rely on different technical dependencies. This is where the eeID identity verification service can help service providers: one of its key advantages is that it brings multiple authentication solutions together on a single platform.

In addition to national solutions, eeID provides access to several international authentication methods, including solutions based on ID cards, Smart-ID, and eIDAS. Passkeys are also available, offering an additional layer of resilience alongside more traditional authentication methods.

These solutions do not all perform exactly the same function or rely on the same technical route. That is precisely why a diversified selection can make a company’s authentication architecture more resilient. At the same time, it also gives customers a more convenient user experience.

The technical simplicity of eeID

Adding several identity verification and authentication solutions would normally increase technical complexity. eeID makes this significantly simpler. A single integration provides access to dozens of solutions, meaning that much of the technical administration and bureaucracy can be moved away from the company itself.

With eeID, diversifying authentication options also becomes more manageable for smaller development teams. The service is available at an affordable price based only on actual transactions.

Estonia’s national authentication infrastructure is strong. The fact that approximately 91% of the 86.1 million requests during the recent attack were blocked demonstrates the capability of the protection measures in place. At the same time, the incident illustrates a universal technical reality: no digital service or infrastructure dependency can be assumed to have 100% availability.

Resilience is created when the possibility of failure is considered already at the architecture stage. That is why one question should always be included in system design discussions: What happens to our customers if this temporarily stops working?

eeID helps build a more flexible identity architecture by bringing strong electronic identity verification, international identification, and FIDO-based passwordless authentication under one service. A good authentication solution should be both difficult to compromise and difficult to take offline.

Want to assess the resilience of your authentication architecture? Explore the possibilities of eeID and contact us at info@internet.ee to book a demo call.


Email again:

See the latest news and blogs: