Live data from Hacker News

Okta’s Investigation of the January 2022 Compromise

okta.com

11–20 of 124 posts

Re: Okta’s Investigation of the January 2022 Compromise

#11

I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…

I view this hack as a public service - we're seeing how awfully these big security companies actually handle security in the worst case. Let that be a lesson to everyone who is in favour of mass centralisation. There needs to be a security solution where Okta essentially provides the skeleton of the infrastructure but not the entire solution, such that an Okta compromise does not compromise everyone who uses them.

Re: Okta’s Investigation of the January 2022 Compromise

#13

I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…

I view this hack as a public service - we're seeing how awfully these big security companies actually handle security in the worst case. Let that be a lesson to everyone who is in favour of mass centralisation. There needs to be a security solution where Okta essentially provides the skeleton of the infrastructure but not the entire solution, such that an Okta compromise does not compromise everyone who uses them.

It's wild that apparently near full admin access to the service was handed out to subcontractors of subcontractors. There was so little oversight and so many levels of indirection that it took months to figure out the full impact of the breach and incident. This does not seem like a healthy or responsible security policy for a company whose primary business is... authentication security.

Re: Okta’s Investigation of the January 2022 Compromise

#14
post #5

> The majority of support engineering tasks are performed using an internally-built application called SuperUser or SU for short, which is used to perform basic management functions of Okta customer tenants. Pretty ominous name. I wouldn’t hand out “super user” accounts to support engineers from contracting firms for “basic duties in handling inbound support queries”.

Unless there's some amount of "lying-by-omission" going on here (or some amount of me not understanding what was said), it doesn't sound like support staff get actual super user access to me. It just sounds like a poorly named internal app.

Re: Okta’s Investigation of the January 2022 Compromise

#16

I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…

[deleted]

Re: Okta’s Investigation of the January 2022 Compromise

#17

I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…

I view this hack as a public service - we're seeing how awfully these big security companies actually handle security in the worst case. Let that be a lesson to everyone who is in favour of mass centralisation. There needs to be a security solution where Okta essentially provides the skeleton of the infrastructure but not the entire solution, such that an Okta compromise does not compromise everyone who uses them.

One company doing a bad job does not mean it's impossible or even uncommon to do a good job. Also, if you wanted to hedge against Okta... feel free. You can U2F 2FA your services behind Okta or in front of it. We use GSuite SSO, but everywhere we can set 2FA outside of it we do so.

Re: Okta’s Investigation of the January 2022 Compromise

#18

Earlier quoted context omitted.

I view this hack as a public service - we're seeing how awfully these big security companies actually handle security in the worst case. Let that be a lesson to everyone who is in favour of mass centralisation. There needs to be a security solution where Okta essentially provides the skeleton of the infrastructure but not the entire solution, such that an Okta compromise does not compromise everyone who uses them.

It's wild that apparently near full admin access to the service was handed out to subcontractors of subcontractors. There was so little oversight and so many levels of indirection that it took months to figure out the full impact of the breach and incident. This does not seem like a healthy or responsible security policy for a company whose primary business is... authentication security.

But it was cheap!

Re: Okta’s Investigation of the January 2022 Compromise

#19

I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…

[deleted]

Re: Okta’s Investigation of the January 2022 Compromise

#20
It's interesting how you need to read what they don't write to actually figure out what they're saying:

They are unable to create or delete users. They cannot download customer databases. They cannot access our source code repositories.

So they can likely arbitrarily access/impersonate or at least password reset existing users, and probably reconfigure the accounts in creative ways.

For transparency, these customers will receive a report that shows the actions performed on their Okta tenant by Sitel during that period of time. We think this is the best way to let customers assess the situation for themselves.

So they have no idea which of the actions were or weren't legitimate and make it their customers' problem.

Post reply on HN