Live data from Hacker News

Okta’s Investigation of the January 2022 Compromise

okta.com

111–120 of 124 posts

Re: Okta’s Investigation of the January 2022 Compromise

#111

I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…

I believe part of the job description for CxO jobs is "willing to bend reality as per needs of the company"

Re: Okta’s Investigation of the January 2022 Compromise

#112

I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…

> an unauthorized user had full super user access to the service From the article: > The majority of support engineering tasks are performed using an internally-built application called SuperUser or SU for short, which is used to perform basic management functions of Okta customer tenants. This does not provide “god-like access” to all its users. This is an application built with least privilege in mind to ensure tha…

Kinda unrelated, but how did job title inflation get this bad?

Support _Engineer_ that is using a prebuilt application to do stuff like reset MFA. In what world does this have anything to do with engineering?

Re: Okta’s Investigation of the January 2022 Compromise

#113
post #72

Earlier quoted context omitted.

One company doing a bad job does not mean it's impossible or even uncommon to do a good job. Also, if you wanted to hedge against Okta... feel free. You can U2F 2FA your services behind Okta or in front of it. We use GSuite SSO, but everywhere we can set 2FA outside of it we do so.

> does not mean it's impossible or even uncommon to do a good job. The only way one can reach this conclusion is by ignoring all the breaches / CVEs that happened in large companies during the past few years. Nowadays I just assume every company is crap at security unless proven otherwise.

I'm pretty up on my breaches :)

Yes, most companies are bad at security. Some aren't though. The problem right now is figuring out which ones are - there's very little signal.

Re: Okta’s Investigation of the January 2022 Compromise

#114

I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…

At least he didn't blame the intern...

Re: Okta’s Investigation of the January 2022 Compromise

#115
post #108
post #67

Earlier quoted context omitted.

At my own workplace (a SaaS service), we cannot change passwords, we can only send reset links (and the reset email goes to the end user). I can't see any place in the screenshots where they are setting a user's password, only sending reset links (which would do nothing if the support user does not have access to system email or end users email). Also at my workplace, 2FA is not enforced by an IdP (like Okta), but by…

How do you send a reset password email with a SSO platform that gates email?

If you have 2FA a OTP can be sent to a trusted device or app to allow a password reset without having access to email?

Re: Okta’s Investigation of the January 2022 Compromise

#116

Earlier quoted context omitted.

> It seems they care more about their shareholders than their customers. isn't this how publicly-traded companies are supposed to work ? I agree on critizicing that approach and capitalism model, but I don't understand how that isn't common knowledge here.

Of course the sole purpose of a publicly traded company is to maximise the revenue for its shareholders, however, you can take a long term or short term approach on this. Okta appeared to have kept this under wraps to prevent a shareholders backlash (short term approach) However, as a result they achieved the opposite, as the share price is still down this morning. This may of course be a temporarily glitch, however,…

It doesn't have to be. If the shareholders want the company to otherwise cease operations and throw a big ice cream party for all the shareholders every Friday they can choose to do that. There's nothing that forces a public company to focus only on maximizing shareholder value, they just have to be open and honest about the goals of the company and try and meet the shareholder expectations.

Re: Okta’s Investigation of the January 2022 Compromise

#117

Earlier quoted context omitted.

I view this hack as a public service - we're seeing how awfully these big security companies actually handle security in the worst case. Let that be a lesson to everyone who is in favour of mass centralisation. There needs to be a security solution where Okta essentially provides the skeleton of the infrastructure but not the entire solution, such that an Okta compromise does not compromise everyone who uses them.

One company doing a bad job does not mean it's impossible or even uncommon to do a good job. Also, if you wanted to hedge against Okta... feel free. You can U2F 2FA your services behind Okta or in front of it. We use GSuite SSO, but everywhere we can set 2FA outside of it we do so.

> One company doing a bad job does not mean it's impossible or even uncommon to do a good job.

We all know it is very uncommon to do a great job. Everyone has been breached sooner or later. Any anyone who has worked in engineering or security in tech companies knows how often security concerns are underprioritized far behind more visible but less important work.

Hedging is a good answer. Relying on a single point of failure that, if it ever fails open, will expose everything at once? Not a smart idea.

Re: Okta’s Investigation of the January 2022 Compromise

#118

I don't understand how OKTA is +4.34%/1M and 10.26%/5D. This is bat-shit crazy lol. Anyway I put a 10,000USD 5x sell at 166.19, let's see how it goes from here :D :D :D

hahha. downvote at will. I just made $2k with literally twenty mouse clicks.

Congrats! If you bought PUTS at market open today (or yesterday) you could have made 500% today.

I'm excited about this and in the future will be checking stock price first thing when I see these smaller publicly listed tech companies getting hit with big hacks.

For MSFT (and companies of that size) this type of news doesn't move the stock that much but with current volatility there will be plenty of great plays in the future for smaller companies.

Re: Okta’s Investigation of the January 2022 Compromise

#119

tl;dr - Companies cheerfully handed over their golden skeleton and city (company) keys over to a third party service provider that offers SSO and now, after they got hacked by some kiddy that writes like a teenager, we found out that they also just cook with water (or less: api keys in slack). Now the public company communication is a reputation crushing web of lies, inaccuracies and whining.

The stock hasn't crashed yet. I see opportunity.

Could have made 500% on PUTS today alone though.

Re: Okta’s Investigation of the January 2022 Compromise

#120
post #22

Earlier quoted context omitted.

> And then go on to write paragraphs of detail and a timeline that explicitly shows for a five day period an unauthorized user had full super user access to the service. it sounds like they built the support tool (with its unfortunate name) such that it places limited trust in support contractors and the information technology that supports them. because of this they're able to identify potentially affected customers…

A person who should not have had access to the system gained near full admin access for five whole days. That is the textbook definition of a breach of security. It doesn't matter if they did it by fooling or paying a low level CS rep to get access to their account vs. using their 'leet hacking skillz' to pwn the electronic defenses. A breach is a breach and the CSO of all people has to own up to that fact.

On the topic of 'leet hacking skillz' I personally find it strange that so many Silicon Valley companies only care abut leetcode for the interview process.

You can be a security expert and no tech company will care unless you cram leetcode non-stop.

On the plus side the lack of security focus makes for a lot of opportunities for the stock market when betting against overvalued tech companies with this problem!

Post reply on HN