Okta hit by third-party breach, stealing employee data
21–30 of 93 posts
Re: Okta hit by third-party breach, stealing employee data
#22Rough task for people tasked with holding together the “brand”
Re: Okta hit by third-party breach, stealing employee data
#23> We have no evidence to suggest that your personal information has been misused against you. What a fucking horribly disingenuous statement. They are trying to say that nothing bad happened, but their SSN and information was stolen!! The information is going to be sold and at a later date it could be used. But they're not saying that, they're trying to say "Nothing to see here, your information wasn't misused so don…
We, the IT industry, have demonstrated repeatedly that we are not smart enough and/or not diligent enough to consistently protect this information. I think we should admit that and try the reverse approach: make knowledge of our PII worthless for committing fraud and theft. We need to fundamentally shift our methods of proving identity to something that doesn't rely on keeping a 9-digit number a secret.
Re: Okta hit by third-party breach, stealing employee data
#24> We have no evidence to suggest that your personal information has been misused against you. What a fucking horribly disingenuous statement. They are trying to say that nothing bad happened, but their SSN and information was stolen!! The information is going to be sold and at a later date it could be used. But they're not saying that, they're trying to say "Nothing to see here, your information wasn't misused so don…
The bigger question for me is, "why is my SSN still such a valuable bit of information" We, the IT industry, have demonstrated repeatedly that we are not smart enough and/or not diligent enough to consistently protect this information. I think we should admit that and try the reverse approach: make knowledge of our PII worthless for committing fraud and theft. We need to fundamentally shift our methods of proving ide…
It's obvious that having the SSN as a single point of failure is exceedingly stupid, but our government bureaucrats refuse to do anything about it. You can't even request a new SSN, it's practically impossible to get a new one even if your identity is stolen.
The only thing holding us back is red tape, which is the dumbest reason of all.
Re: Okta hit by third-party breach, stealing employee data
#25> We have no evidence to suggest that your personal information has been misused against you. What a fucking horribly disingenuous statement. They are trying to say that nothing bad happened, but their SSN and information was stolen!! The information is going to be sold and at a later date it could be used. But they're not saying that, they're trying to say "Nothing to see here, your information wasn't misused so don…
Not to discount your point- you’re right it’s so disingenuous. BUT we’re quickly approaching a world where every American has been in a leak that affects their data and SSN. Not 100% of course (simply because young people haven’t had a chance to be screwed over) but at some point we should assume that the information is public for a large enough portion of the population and we need to set new expectations.
… that number, presently, has to be a rounding error from being 100%. My SSN was first breached when I was in high school, at least.
But yeah, I agree, we should set new expectations. There could definitely be a better system, and I would like to see companies held to account, but material fines against corps are basically unicorns in America.
Re: Okta hit by third-party breach, stealing employee data
#26> We have no evidence to suggest that your personal information has been misused against you. What a fucking horribly disingenuous statement. They are trying to say that nothing bad happened, but their SSN and information was stolen!! The information is going to be sold and at a later date it could be used. But they're not saying that, they're trying to say "Nothing to see here, your information wasn't misused so don…
But compare how that looks compared against the bigger players which can afford to treat their weekly apocalyptic security incidents like it's just a bad weather phenomenon we just have to accept, apply a patch for and move on.
Re: Okta hit by third-party breach, stealing employee data
#27Earlier quoted context omitted.
What is your preferred alternative?
Out of interest, why would you not just use the directory services that you get bundled with google workspace, azureAD (Now: Entra) or freeipa/keycloak? All of these support oauth2 and SAML, and dynamic groups for less than the cost of each and okta (it seems to be the case everywhere I have seen okta used, another of the above providers is used additionally).
"Okta: comprehensive scim allowing your IT instead of random application admins throughout your company to manage user provisioning / deprovisioning. Start pages that don't require users to remember urls but instead show them a list of applications they can use. Adaptive MFA with IT-administered settings (though Google's super-enterprisey solutions may have sth here.)"
https://news.ycombinator.com/item?id=37995670
Personally, I just go with the Google Workspace and call it a day. Start page is one of those nice to have, but not required features in my book.
Re: Okta hit by third-party breach, stealing employee data
#28That seems like a pretty ridiculous statement. Is it supposed to be reassuring or something? Like, obviously Okta has no way of knowing whether or not their employees PII, having been leaked, will be exploited, and when it does get exploited, it almost certainly will be the employees who find out about it, not Okta.
Re: Okta hit by third-party breach, stealing employee data
#29Not really Okta's fault here, just so happened that Okta was a client of this benefits company. Still, not a good look for Okta.
Does that matter, though? The message I get is that Okta isn't good with security, and they're not good at choosing vendors who are good with security.
Re: Okta hit by third-party breach, stealing employee data
#30Earlier quoted context omitted.
Yes, context matters. If you discount every company that might be impacted by a third-party breach of employee data, you will be left with no vendors. At some point you have to decide what is acceptable, and have insurance/indemnity for the risks. I would not discount Okta because of a decision made by HR.
Most large companies vet their vendors to some extent. It's hard to know if that happened in this case or not, but it's still part of the normal procurement process to perform a security review. These reviews have varying levels of security requirements depending on what type of PII will be stored or processed. Considering this breach included SSN's I'd have expected this to be one of the more thorough reviews.
1. Are you secure?
2. Are you secure?
3. Are you secure?
4. Are you secure?
...
37. Are you secure?
and the company sends back 1. Yes.
2. Yes.
3. Yes, definitely.
4. Oh yes.
...
37. Yes.
There's a lot more words, but not necessarily a lot more value in those words then what I have here. Some, I admit, but not necessarily a lot.Maybe at the high government end a real assessment is done where the experts of the client's choosing go into the provider's actual environment and makes a real assessment. But from what I've seen it's self-reporting the vast majority of the time, and the provider could honestly believe they're running a tight ship and not realize there's one setting in one AWS account that's just a bit too open and oh no my database. (Or perhaps rather "oh no your database".)