I don’t know why people are all pretending like this is irrelevant to Okta's security. An employee list like that is a goldmine for all sorts of social engineering and phishing attacks.
It’s not that it isn’t relevant, it’s the clickbait-y headline and insinuation that Okta itself was compromised again. Any major company using third-party vendors would be in the same position (and for all we know, this healthcare company provided services to multiple other companies). Fault Okta for not doing enough vendor due diligence, sure, but don’t use clickbait to imply Okta itself was breached.
Okta hit by third-party breach, stealing employee data
51–60 of 93 posts
Re: Okta hit by third-party breach, stealing employee data
#52Earlier quoted context omitted.
Not to discount your point- you’re right it’s so disingenuous. BUT we’re quickly approaching a world where every American has been in a leak that affects their data and SSN. Not 100% of course (simply because young people haven’t had a chance to be screwed over) but at some point we should assume that the information is public for a large enough portion of the population and we need to set new expectations.
> we’re quickly approaching a world where every American has been in a leak that affects their data and SSN. Not 100% of course (simply because young people haven’t had a chance to be screwed over) … that number, presently, has to be a rounding error from being 100%. My SSN was first breached when I was in high school, at least . But yeah, I agree, we should set new expectations. There could definitely be a better sy…
Re: Okta hit by third-party breach, stealing employee data
#53Earlier quoted context omitted.
Ok, but that's not what the article says. It says Okta was breached. Okta was not breached.
It says Okta was "hit by" a breach, which it was. A breach happened, and Okta was impacted. Furthermore, it happened to data which Okta is ultimately responsible for, and Okta should be held responsible for their choices which led to their employees' data being stolen. I'm not sure why you're splitting hairs on this.
It implies this breach is the same as the previous breach, which it's not.
Ars has gone to shit over the last decade.
Re: Okta hit by third-party breach, stealing employee data
#54I don’t know why people are all pretending like this is irrelevant to Okta's security. An employee list like that is a goldmine for all sorts of social engineering and phishing attacks.
It’s not that it isn’t relevant, it’s the clickbait-y headline and insinuation that Okta itself was compromised again. Any major company using third-party vendors would be in the same position (and for all we know, this healthcare company provided services to multiple other companies). Fault Okta for not doing enough vendor due diligence, sure, but don’t use clickbait to imply Okta itself was breached.
Re: Okta hit by third-party breach, stealing employee data
#55What a misleading and click-baity title choice by Ars Technica. This had nothing to do with Okta's platform, as implied. A third-party Vendor Okta used for health insurance information was breached, and personal information on Okta employees was stolen. I'm disappointed in Ars Technica, and Dan Goodin. edit: Updated to be more specific about what part of Okta this had nothing to do with.
Re: Okta hit by third-party breach, stealing employee data
#56Re: Okta hit by third-party breach, stealing employee data
#57Earlier quoted context omitted.
Sounds like the statement is referencing the past not the future. I think it’s a reasonable thing for them to say: this was stolen, and that sucks, but perhaps a little reassuringly we haven’t detected this being misused. idk.
To the extent that it is reassuring, it is misleading, right? Unless they have some way of being reasonably sure that the fact that they haven’t detected misuse implies that it hasn’t happened.
Re: Okta hit by third-party breach, stealing employee data
#58Earlier quoted context omitted.
It says Okta was "hit by" a breach, which it was. A breach happened, and Okta was impacted. Furthermore, it happened to data which Okta is ultimately responsible for, and Okta should be held responsible for their choices which led to their employees' data being stolen. I'm not sure why you're splitting hairs on this.
"another" is the weasel word It implies this breach is the same as the previous breach, which it's not. Ars has gone to shit over the last decade.
I won't disagree with opinion on the quality of Ars' reporting or this particular article, but I do disagree with the original comment's statement that "this had nothing to do with Okta".
Re: Okta hit by third-party breach, stealing employee data
#59Earlier quoted context omitted.
Most large companies vet their vendors to some extent. It's hard to know if that happened in this case or not, but it's still part of the normal procurement process to perform a security review. These reviews have varying levels of security requirements depending on what type of PII will be stored or processed. Considering this breach included SSN's I'd have expected this to be one of the more thorough reviews.
Those "assessments" amount to sending over a document that says 1. Are you secure? 2. Are you secure? 3. Are you secure? 4. Are you secure? ... 37. Are you secure? and the company sends back 1. Yes. 2. Yes. 3. Yes, definitely. 4. Oh yes. ... 37. Yes. There's a lot more words, but not necessarily a lot more value in those words then what I have here. Some, I admit, but not necessarily a lot. Maybe at the high governme…
Presumably you'd be lying about the thing they'd be buying too, or innumerable other things.
And 'subsequent lawsuit' is usually a powerful motivator to be honest.
Re: Okta hit by third-party breach, stealing employee data
#60Earlier quoted context omitted.
It says Okta was "hit by" a breach, which it was. A breach happened, and Okta was impacted. Furthermore, it happened to data which Okta is ultimately responsible for, and Okta should be held responsible for their choices which led to their employees' data being stolen. I'm not sure why you're splitting hairs on this.
"another" is the weasel word It implies this breach is the same as the previous breach, which it's not. Ars has gone to shit over the last decade.
I could have probably phrased this as "this had nothing to do with Okta's technology."