Live data from Hacker News

Okta hit by third-party breach, stealing employee data

arstechnica.com

41–50 of 93 posts

Re: Okta hit by third-party breach, stealing employee data

#41

Earlier quoted context omitted.

The bigger question for me is, "why is my SSN still such a valuable bit of information" We, the IT industry, have demonstrated repeatedly that we are not smart enough and/or not diligent enough to consistently protect this information. I think we should admit that and try the reverse approach: make knowledge of our PII worthless for committing fraud and theft. We need to fundamentally shift our methods of proving ide…

This is the dangers of a too-powerful bureaucracy. It's obvious that having the SSN as a single point of failure is exceedingly stupid, but our government bureaucrats refuse to do anything about it. You can't even request a new SSN, it's practically impossible to get a new one even if your identity is stolen. The only thing holding us back is red tape, which is the dumbest reason of all.

It's the danger of using something as a universal password (terrible practice #1) that's often stored in plain text (terrible practice #2).

I don't regularly deal much with federal government agencies beyond the IRS. Which ones let you do nefarious things if you only know a person's name, address, and SSN? The IRS doesn't, because they require you to know info from what you filed last year.

Re: Okta hit by third-party breach, stealing employee data

#42

Earlier quoted context omitted.

If you have AzureAD you don’t typically also have Okta. Also the features you listed are like 20% of Okta’s functionality here.

If you have office licenses you have AzureAD. Lots of places have office licenses for all of or most of their employees and still have Okta.

AzureAD licenses near the feature equivalent of Okta are much more expensive than base office licenses that only give you access to the office apps and cloud storage.

Re: Okta hit by third-party breach, stealing employee data

#43

> We have no evidence to suggest that your personal information has been misused against you. What a fucking horribly disingenuous statement. They are trying to say that nothing bad happened, but their SSN and information was stolen!! The information is going to be sold and at a later date it could be used. But they're not saying that, they're trying to say "Nothing to see here, your information wasn't misused so don…

The bigger question for me is, "why is my SSN still such a valuable bit of information" We, the IT industry, have demonstrated repeatedly that we are not smart enough and/or not diligent enough to consistently protect this information. I think we should admit that and try the reverse approach: make knowledge of our PII worthless for committing fraud and theft. We need to fundamentally shift our methods of proving ide…

Because the US has a political aversion to centralized IDs at the federal level, but an identity provider of some sort is necessary for lots of business interactions.

Re: Okta hit by third-party breach, stealing employee data

#44

What a misleading and click-baity title choice by Ars Technica. This had nothing to do with Okta's platform, as implied. A third-party Vendor Okta used for health insurance information was breached, and personal information on Okta employees was stolen. I'm disappointed in Ars Technica, and Dan Goodin. edit: Updated to be more specific about what part of Okta this had nothing to do with.

Okta (or any company) can't outsource its responsibility when it outsources to a supplier.

If Okta printed all that personal data and left it in a box on the street they would be liable.

Re: Okta hit by third-party breach, stealing employee data

#46

What a misleading and click-baity title choice by Ars Technica. This had nothing to do with Okta's platform, as implied. A third-party Vendor Okta used for health insurance information was breached, and personal information on Okta employees was stolen. I'm disappointed in Ars Technica, and Dan Goodin. edit: Updated to be more specific about what part of Okta this had nothing to do with.

Maybe someone is short selling.

Re: Okta hit by third-party breach, stealing employee data

#47
post #44

What a misleading and click-baity title choice by Ars Technica. This had nothing to do with Okta's platform, as implied. A third-party Vendor Okta used for health insurance information was breached, and personal information on Okta employees was stolen. I'm disappointed in Ars Technica, and Dan Goodin. edit: Updated to be more specific about what part of Okta this had nothing to do with.

Okta (or any company) can't outsource its responsibility when it outsources to a supplier. If Okta printed all that personal data and left it in a box on the street they would be liable.

Ok, but that's not what the article says. It says Okta was breached. Okta was not breached.

Re: Okta hit by third-party breach, stealing employee data

#48

I don’t know why people are all pretending like this is irrelevant to Okta's security. An employee list like that is a goldmine for all sorts of social engineering and phishing attacks.

It’s not that it isn’t relevant, it’s the clickbait-y headline and insinuation that Okta itself was compromised again. Any major company using third-party vendors would be in the same position (and for all we know, this healthcare company provided services to multiple other companies). Fault Okta for not doing enough vendor due diligence, sure, but don’t use clickbait to imply Okta itself was breached.

Re: Okta hit by third-party breach, stealing employee data

#49

Earlier quoted context omitted.

The bigger question for me is, "why is my SSN still such a valuable bit of information" We, the IT industry, have demonstrated repeatedly that we are not smart enough and/or not diligent enough to consistently protect this information. I think we should admit that and try the reverse approach: make knowledge of our PII worthless for committing fraud and theft. We need to fundamentally shift our methods of proving ide…

This is the dangers of a too-powerful bureaucracy. It's obvious that having the SSN as a single point of failure is exceedingly stupid, but our government bureaucrats refuse to do anything about it. You can't even request a new SSN, it's practically impossible to get a new one even if your identity is stolen. The only thing holding us back is red tape, which is the dumbest reason of all.

It probably seemed a lot more reasonable back when most people’s exposure to “password” was “the thing you needed to get into the speakeasy.”

Re: Okta hit by third-party breach, stealing employee data

#50
post #44

Earlier quoted context omitted.

Okta (or any company) can't outsource its responsibility when it outsources to a supplier. If Okta printed all that personal data and left it in a box on the street they would be liable.

Ok, but that's not what the article says. It says Okta was breached. Okta was not breached.

It says Okta was "hit by" a breach, which it was. A breach happened, and Okta was impacted. Furthermore, it happened to data which Okta is ultimately responsible for, and Okta should be held responsible for their choices which led to their employees' data being stolen.

I'm not sure why you're splitting hairs on this.

Post reply on HN