Live data from Hacker News

Okta hit by third-party breach, stealing employee data

arstechnica.com

51–60 of 93 posts

Re: Okta hit by third-party breach, stealing employee data

#51
post #48

I don’t know why people are all pretending like this is irrelevant to Okta's security. An employee list like that is a goldmine for all sorts of social engineering and phishing attacks.

It’s not that it isn’t relevant, it’s the clickbait-y headline and insinuation that Okta itself was compromised again. Any major company using third-party vendors would be in the same position (and for all we know, this healthcare company provided services to multiple other companies). Fault Okta for not doing enough vendor due diligence, sure, but don’t use clickbait to imply Okta itself was breached.

The real takeaway for Okta in 2023, if they didn't know it already, is they are dealing with nation state threat actors, and if they think they are over-investing in security, they probably aren't.

Re: Okta hit by third-party breach, stealing employee data

#52

Earlier quoted context omitted.

Not to discount your point- you’re right it’s so disingenuous. BUT we’re quickly approaching a world where every American has been in a leak that affects their data and SSN. Not 100% of course (simply because young people haven’t had a chance to be screwed over) but at some point we should assume that the information is public for a large enough portion of the population and we need to set new expectations.

> we’re quickly approaching a world where every American has been in a leak that affects their data and SSN. Not 100% of course (simply because young people haven’t had a chance to be screwed over) … that number, presently, has to be a rounding error from being 100%. My SSN was first breached when I was in high school, at least . But yeah, I agree, we should set new expectations. There could definitely be a better sy…

We need a bunch of case law indicating that banks and credit card companies that don’t authenticate past this widely leaked PII are on the hook for the loss of money (rather than the uninvolved third parties who are being impersonated).

Re: Okta hit by third-party breach, stealing employee data

#53

Earlier quoted context omitted.

Ok, but that's not what the article says. It says Okta was breached. Okta was not breached.

It says Okta was "hit by" a breach, which it was. A breach happened, and Okta was impacted. Furthermore, it happened to data which Okta is ultimately responsible for, and Okta should be held responsible for their choices which led to their employees' data being stolen. I'm not sure why you're splitting hairs on this.

"another" is the weasel word

It implies this breach is the same as the previous breach, which it's not.

Ars has gone to shit over the last decade.

Re: Okta hit by third-party breach, stealing employee data

#54
post #48

I don’t know why people are all pretending like this is irrelevant to Okta's security. An employee list like that is a goldmine for all sorts of social engineering and phishing attacks.

It’s not that it isn’t relevant, it’s the clickbait-y headline and insinuation that Okta itself was compromised again. Any major company using third-party vendors would be in the same position (and for all we know, this healthcare company provided services to multiple other companies). Fault Okta for not doing enough vendor due diligence, sure, but don’t use clickbait to imply Okta itself was breached.

Be it as it may, it does not really matter, whether it came from a Okta database or of any other company. It further compromises Okta's security which is pretty bad because being secure is basically their primary service proposition.

Re: Okta hit by third-party breach, stealing employee data

#55

What a misleading and click-baity title choice by Ars Technica. This had nothing to do with Okta's platform, as implied. A third-party Vendor Okta used for health insurance information was breached, and personal information on Okta employees was stolen. I'm disappointed in Ars Technica, and Dan Goodin. edit: Updated to be more specific about what part of Okta this had nothing to do with.

https://www.rightwayhealthcare.com is the company mentioned in the article. Okta is shown as a customer on the website, and the company's marketing says "Our members love using Rightway". There is zero mention of security on their website that I see, but the website is entirely marketing and self-congratulatory. I would expect that other Rightway customers were likely also affected, but they had no comment mentioned in this article so how wide the breach was is unknown. Okta is a well-known company so that's why this article focused on them, which is not the real story, but I guess like you said clickbait.

Re: Okta hit by third-party breach, stealing employee data

#57

Earlier quoted context omitted.

Sounds like the statement is referencing the past not the future. I think it’s a reasonable thing for them to say: this was stolen, and that sucks, but perhaps a little reassuringly we haven’t detected this being misused. idk.

To the extent that it is reassuring, it is misleading, right? Unless they have some way of being reasonably sure that the fact that they haven’t detected misuse implies that it hasn’t happened.

I think there's probably a legal reason that's included, as it's in all info leak announcements I've seen.

Re: Okta hit by third-party breach, stealing employee data

#58
post #53

Earlier quoted context omitted.

It says Okta was "hit by" a breach, which it was. A breach happened, and Okta was impacted. Furthermore, it happened to data which Okta is ultimately responsible for, and Okta should be held responsible for their choices which led to their employees' data being stolen. I'm not sure why you're splitting hairs on this.

"another" is the weasel word It implies this breach is the same as the previous breach, which it's not. Ars has gone to shit over the last decade.

I don't think I agree that the use of the word "another" implies that the breaches were equal, but I can see why others might interpret it that way.

I won't disagree with opinion on the quality of Ars' reporting or this particular article, but I do disagree with the original comment's statement that "this had nothing to do with Okta".

Re: Okta hit by third-party breach, stealing employee data

#59
post #30
post #15

Earlier quoted context omitted.

Most large companies vet their vendors to some extent. It's hard to know if that happened in this case or not, but it's still part of the normal procurement process to perform a security review. These reviews have varying levels of security requirements depending on what type of PII will be stored or processed. Considering this breach included SSN's I'd have expected this to be one of the more thorough reviews.

Those "assessments" amount to sending over a document that says 1. Are you secure? 2. Are you secure? 3. Are you secure? 4. Are you secure? ... 37. Are you secure? and the company sends back 1. Yes. 2. Yes. 3. Yes, definitely. 4. Oh yes. ... 37. Yes. There's a lot more words, but not necessarily a lot more value in those words then what I have here. Some, I admit, but not necessarily a lot. Maybe at the high governme…

Another way of looking at it is that if a company doesn't truth you to answer truthfully, why are they choosing you as a vendor?

Presumably you'd be lying about the thing they'd be buying too, or innumerable other things.

And 'subsequent lawsuit' is usually a powerful motivator to be honest.

Re: Okta hit by third-party breach, stealing employee data

#60
post #53

Earlier quoted context omitted.

It says Okta was "hit by" a breach, which it was. A breach happened, and Okta was impacted. Furthermore, it happened to data which Okta is ultimately responsible for, and Okta should be held responsible for their choices which led to their employees' data being stolen. I'm not sure why you're splitting hairs on this.

"another" is the weasel word It implies this breach is the same as the previous breach, which it's not. Ars has gone to shit over the last decade.

> but I do disagree with the original comment's statement that "this had nothing to do with Okta".

I could have probably phrased this as "this had nothing to do with Okta's technology."

Post reply on HN