Live data from Hacker News

Okta hit by third-party breach, stealing employee data

arstechnica.com

31–40 of 93 posts

Re: Okta hit by third-party breach, stealing employee data

#31

If this is directly related to negligence at Okta or not (which seems like it’s not in this case) doesn’t really matter when “Okta” and “Data Breach” seem to show up close together in headlines a lot. Rough task for people tasked with holding together the “brand”

It'd be more forgivable if they weren't so bad at listening to their customers when they report things, technical or security related.

The best thing Okta has going for them right now is that a lot of these companies are so bloated and slow that changing platforms takes a long time to pull off even the initial agreement that they'll be changing, so they have plenty of time to let things settle even if you're mad at them because switching everything to a new idp is "just not something the business can prioritize right now"

They probably look like hot garbage to customers shopping around but I'd venture with most existing clients over a certain size they'll just ask them for a statement they can email out then the Okta sales guys will treat a few directors to happy hour and a ball game, delaying the long process of being dumped from even starting.

Re: Okta hit by third-party breach, stealing employee data

#32

Did anyone read the article? It's literally not a compromise of Okta. It's a compromise of a healthcare provider that Okta is a customer of. Has absolutely nothing to do with Okta's products, at all, whatsoever. This is bordering on yellow journalism. I am all for giving shitty companies their due when they fuck up, but that's not what this is at all.

[deleted]

Re: Okta hit by third-party breach, stealing employee data

#33
post #9

Earlier quoted context omitted.

Does that matter, though? The message I get is that Okta isn't good with security, and they're not good at choosing vendors who are good with security.

Yes, context matters. If you discount every company that might be impacted by a third-party breach of employee data, you will be left with no vendors. At some point you have to decide what is acceptable, and have insurance/indemnity for the risks. I would not discount Okta because of a decision made by HR.

I'm discounting a security company with several recent high-profile security incidents. As somebody that implemented Okta for a bank, for both customers and internal personnel, I am very concerned.

EDIT: Before you defend Okta, tell me why it took three weeks for them to disclose this breach to their own employees? If they're dragging their feet for their own employees, and given Cloudflare's recent experience, why should I trust Okta at all?

> Okta learned of the compromise and data theft on October 12 and didn’t disclose it until Thursday, exactly three weeks later.

Re: Okta hit by third-party breach, stealing employee data

#34

> “The types of personal information contained in the impacted eligibility census file included your Name, Social Security Number, and health or medical insurance plan number,” a letter sent to affected Okta employees stated. “We have no evidence to suggest that your personal information has been misused against you.” That seems like a pretty ridiculous statement. Is it supposed to be reassuring or something? Like, o…

Sounds like the statement is referencing the past not the future. I think it’s a reasonable thing for them to say: this was stolen, and that sucks, but perhaps a little reassuringly we haven’t detected this being misused. idk.

Re: Okta hit by third-party breach, stealing employee data

#35
post #9

Earlier quoted context omitted.

Does that matter, though? The message I get is that Okta isn't good with security, and they're not good at choosing vendors who are good with security.

Yes, context matters. If you discount every company that might be impacted by a third-party breach of employee data, you will be left with no vendors. At some point you have to decide what is acceptable, and have insurance/indemnity for the risks. I would not discount Okta because of a decision made by HR.

I would.

A critical part of having a robust security program is having an effective third party risk management program which evaluates all third parties that you do business with and holds them to high security standards. Okta is the ultimate party that is responsible for protecting this data, and that still remains true even if they subcontract out the protection of that data. If you aren't doing third party risk management, then it calls into question what other critical parts of security you're failing at.

For a company like Okta, which supposedly is a "security" company, to have _repeated_ security failings like this should make everyone question them.

Re: Okta hit by third-party breach, stealing employee data

#36

> “The types of personal information contained in the impacted eligibility census file included your Name, Social Security Number, and health or medical insurance plan number,” a letter sent to affected Okta employees stated. “We have no evidence to suggest that your personal information has been misused against you.” That seems like a pretty ridiculous statement. Is it supposed to be reassuring or something? Like, o…

Sounds like the statement is referencing the past not the future. I think it’s a reasonable thing for them to say: this was stolen, and that sucks, but perhaps a little reassuringly we haven’t detected this being misused. idk.

To the extent that it is reassuring, it is misleading, right? Unless they have some way of being reasonably sure that the fact that they haven’t detected misuse implies that it hasn’t happened.

Re: Okta hit by third-party breach, stealing employee data

#37
What a misleading and click-baity title choice by Ars Technica.

This had nothing to do with Okta's platform, as implied. A third-party Vendor Okta used for health insurance information was breached, and personal information on Okta employees was stolen.

I'm disappointed in Ars Technica, and Dan Goodin.

edit: Updated to be more specific about what part of Okta this had nothing to do with.

Re: Okta hit by third-party breach, stealing employee data

#38

Not really Okta's fault here, just so happened that Okta was a client of this benefits company. Still, not a good look for Okta.

There are two types of people, people who take responsibility for things that aren’t directly their fault, and people who regularly experience negative outcomes.

Okta chose this vendor and they chose to have them store this data. They probably even have security requirements in their contract with them. They could have prevented this. And when you present yourself as a security company, you’re expected to.

Re: Okta hit by third-party breach, stealing employee data

#39
post #14

Earlier quoted context omitted.

Out of interest, why would you not just use the directory services that you get bundled with google workspace, azureAD (Now: Entra) or freeipa/keycloak? All of these support oauth2 and SAML, and dynamic groups for less than the cost of each and okta (it seems to be the case everywhere I have seen okta used, another of the above providers is used additionally).

If you have AzureAD you don’t typically also have Okta. Also the features you listed are like 20% of Okta’s functionality here.

If you have office licenses you have AzureAD. Lots of places have office licenses for all of or most of their employees and still have Okta.

Re: Okta hit by third-party breach, stealing employee data

#40

> We have no evidence to suggest that your personal information has been misused against you. What a fucking horribly disingenuous statement. They are trying to say that nothing bad happened, but their SSN and information was stolen!! The information is going to be sold and at a later date it could be used. But they're not saying that, they're trying to say "Nothing to see here, your information wasn't misused so don…

The bigger question for me is, "why is my SSN still such a valuable bit of information" We, the IT industry, have demonstrated repeatedly that we are not smart enough and/or not diligent enough to consistently protect this information. I think we should admit that and try the reverse approach: make knowledge of our PII worthless for committing fraud and theft. We need to fundamentally shift our methods of proving ide…

That’s a bigger questions, and it is a good one, but practically it is not really relevant (other than, I guess, Okta’s vendor has made a small contribution to making it obvious how ill suited these numbers are for authentication).
Post reply on HN