> Okta service has not been breached and remains fully operational > highlighted that there was a five-day window of time between January 16-21, 2022, where an attacker had access to a support engineer’s laptop These are some impressive mental gymnastics!
Updated Okta Statement on Lapsus$
151–160 of 239 posts
Re: Updated Okta Statement on Lapsus$
#152Re: Updated Okta Statement on Lapsus$
#153Earlier quoted context omitted.
Yep. All these standards are tick boxing for liability. Nothing more. They are not effective security controls and never will be and should never be a measure of that.
I don't know if tick boxing was a spoonerism or intentional or a real thing but I love it and am stealing it. (Upon further review, it appears to be the more UK way of saying it! Ha!)
Re: Updated Okta Statement on Lapsus$
#154Earlier quoted context omitted.
I don't understand all these crazy assumptions being made. A support engineer being able to set a password on any account is unthinkable, there is zero chance this is actually the case. Especially for a security company. It would be the equivalent of giving the doorman a key that opens everyone's apartment. Obviously support can trigger a reset, that you have to complete from your own e-mail account.
Confusing analogy, doormen frequently do have a key to every apartment in the building. Anyway I agree it would be bad practice but that doesn't mean it's not done.
Really? That's insane. I'd like to hear more about that.
Re: Updated Okta Statement on Lapsus$
#155> Support engineers are also able to facilitate the resetting of passwords and MFA factors for users, but are unable to obtain those passwords. Very ambiguous statement, not really fitting in with the whole "deeply committed to transparency" image they are trying to emit. What does "facilitate" really refer to here? If it was just triggering it, they would have said so, presumably. And why is only passwords mentioned…
Password reset is the soft underbelly of most companies.
Re: Updated Okta Statement on Lapsus$
#156Earlier quoted context omitted.
If somebody uses my laptop, my Gmail account is not compromised; I'm being dolphined. Of course 5 days is quite a long time, but this is just to clarify what you didn't understand.
what does dolphined mean. is this a cyber security term?
Re: Updated Okta Statement on Lapsus$
#157Earlier quoted context omitted.
they edited and added more content https://img.guildedcdn.com/ContentMedia/372280f522049aa0b0eb...
8600 channels? Wouldn't that overwhelm you? I'm trying to think up scenarios where an org would need so many, but I can't. Is this normal?
Re: Updated Okta Statement on Lapsus$
#158>The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers. despite an overwhelming preponderance of damning evidence from twitter (as well as the hacker themselves) you've somehow managed to find yourselves secure instead? Christs whiskers thats some impressive doublethink. Its also an excellent opportunity to fall on a sword that giv…
We should not glorify them.
Re: Updated Okta Statement on Lapsus$
#159> The Okta service has not been breached and remains fully operational Oh okay then, pack up guys, everything’s fine I really hate this kind of corporate bullshit > There are no corrective actions that need to be taken by our customers. Isn’t this an objectively false statement?
IMHO it's more of an empty statement. They never pin down what end-state is being discussed. So we can't evaluate if "additional steps are needed" to achieve that (unspecified) state.
It could be that the speaker is intentionally equivocating. I.e., knowing that the audience will assume some particular end-state. But if cornered, the speaker can claim (lie) that he implicitly meant a different end state.
Re: Updated Okta Statement on Lapsus$
#160Earlier quoted context omitted.
If I use your laptop to get access to your Gmail isn't your Gmail account compromised? I might not have access to your Gmail username and passwords (and MFA), but I can read your email, I can send email as you, etc etc. I feel like I have compromised your gmail account. If I steal your secure token and log into you through a cloned browser session and access your gmail have I compromised your gmail? It feels like it.…
> your Gmail account compromised The access is transient and you remain in ownership over the credentials and account, because the credentials were not compromised (just the programs/browsers with pre-existing auth). Though with physical access it's probably only a mater of time before local admin passwords are brute forced and access to keychain/browser saved logins is inevitable? > If I steal your secure token It's…
There is a difference, but that difference is not the one you seem to be implying. An account can be compromised even it it hasn't been fully and permanently taken over. The temporariness of an account being compromised does not mean the account was not compromised.
You can make a distinction and clarify that the account was compromised but that the account credentials were not. However if you extend that to saying that the account was not compromised when attackers did have temporary access, then you are simply lying.