Live data from Hacker News

Okta’s Investigation of the January 2022 Compromise

okta.com

1–10 of 124 posts

Re: Okta’s Investigation of the January 2022 Compromise

#3
"Although that individual attempt was unsuccessful, out of an abundance of caution, we reset the account and notified Sitel who engaged a leading forensic firm to perform an investigation."

Really don't like that they're still unwilling to actually say the name of the 'leading forensic firm'.

Re: Okta’s Investigation of the January 2022 Compromise

#4
> This is an application built with least privilege in mind

Uh huh, makes sense

> Named SuperUser

Uhh...

It lists all the operations that it can't do, but not what it can do. Can they download a private SAML certificate? Can they impersonate a user? Can they configure SSO and MFA settings? Can they download audit logs?

Re: Okta’s Investigation of the January 2022 Compromise

#5
> The majority of support engineering tasks are performed using an internally-built application called SuperUser or SU for short, which is used to perform basic management functions of Okta customer tenants.

Pretty ominous name. I wouldn’t hand out “super user” accounts to support engineers from contracting firms for “basic duties in handling inbound support queries”.

Re: Okta’s Investigation of the January 2022 Compromise

#8
I don't understand how the CSO can write this:

"In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers."

And then go on to write paragraphs of detail and a timeline that explicitly shows for a five day period an unauthorized user had full super user access to the service.

He explicitly says, "The report from the forensic firm highlighted that there was a five-day window of time between January 16-21, 2022 when the threat actor had access to the Sitel environment, which we validated with our own analysis."

This is some unbelievable double speak to try to claim that Okta was not breached. Any trust I had in this company is completely in the toilet, just based on this response. How is the CEO not responding to this too? The hole just keeps getting dug deeper the more they say.

Re: Okta’s Investigation of the January 2022 Compromise

#9
What a weird and potentially misleading statement.

* They stress that the compromised account wasn't able to "create/delete users or download customer databases", but not what it could do. Could it change passwords of accounts and add 2fa methods, allowing them to take over rarely/never accessed users? Disable 2fa? Change account permissions? List user accounts and metadata to build a user account DB for further attacks? The application is named "SuperUser" ...

* It took public posting of a screenshot to trigger an audit of access logs, two months after the compromise was detected!

* "Only" 2.5% of customers were accessed. That's supposed to be a good thing? Those were certainly the most valuable targets.

* Concludes everything is just fine and no corrective actions need to be taken, but affected customers might want to do their own analysis... Huh?

Sounds a lot like damage control.

Re: Okta’s Investigation of the January 2022 Compromise

#10

I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…

Sounds like the main point of disagreement is the definition of a single word, "breached". Otherwise, everyone is in agreement about what happened, right? I agree with your definition of the word for whatever it's worth.

At this point, it would be helpful for Okta to stop using the term "breached", because apparently they aren't using the word in the same way everyone else is, and it's a point of contention.

Post reply on HN