I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…
Okta’s Investigation of the January 2022 Compromise
11–20 of 124 posts
Re: Okta’s Investigation of the January 2022 Compromise
#12david bradbury will probably fail upwards, must be nice
Re: Okta’s Investigation of the January 2022 Compromise
#13I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…
I view this hack as a public service - we're seeing how awfully these big security companies actually handle security in the worst case. Let that be a lesson to everyone who is in favour of mass centralisation. There needs to be a security solution where Okta essentially provides the skeleton of the infrastructure but not the entire solution, such that an Okta compromise does not compromise everyone who uses them.
Re: Okta’s Investigation of the January 2022 Compromise
#14> The majority of support engineering tasks are performed using an internally-built application called SuperUser or SU for short, which is used to perform basic management functions of Okta customer tenants. Pretty ominous name. I wouldn’t hand out “super user” accounts to support engineers from contracting firms for “basic duties in handling inbound support queries”.
Re: Okta’s Investigation of the January 2022 Compromise
#15Re: Okta’s Investigation of the January 2022 Compromise
#16I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…
Re: Okta’s Investigation of the January 2022 Compromise
#17I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…
I view this hack as a public service - we're seeing how awfully these big security companies actually handle security in the worst case. Let that be a lesson to everyone who is in favour of mass centralisation. There needs to be a security solution where Okta essentially provides the skeleton of the infrastructure but not the entire solution, such that an Okta compromise does not compromise everyone who uses them.
Re: Okta’s Investigation of the January 2022 Compromise
#18Earlier quoted context omitted.
I view this hack as a public service - we're seeing how awfully these big security companies actually handle security in the worst case. Let that be a lesson to everyone who is in favour of mass centralisation. There needs to be a security solution where Okta essentially provides the skeleton of the infrastructure but not the entire solution, such that an Okta compromise does not compromise everyone who uses them.
It's wild that apparently near full admin access to the service was handed out to subcontractors of subcontractors. There was so little oversight and so many levels of indirection that it took months to figure out the full impact of the breach and incident. This does not seem like a healthy or responsible security policy for a company whose primary business is... authentication security.
Re: Okta’s Investigation of the January 2022 Compromise
#19I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…
Re: Okta’s Investigation of the January 2022 Compromise
#20They are unable to create or delete users. They cannot download customer databases. They cannot access our source code repositories.
So they can likely arbitrarily access/impersonate or at least password reset existing users, and probably reconfigure the accounts in creative ways.
For transparency, these customers will receive a report that shows the actions performed on their Okta tenant by Sitel during that period of time. We think this is the best way to let customers assess the situation for themselves.
So they have no idea which of the actions were or weren't legitimate and make it their customers' problem.