What a misleading and click-baity title choice by Ars Technica. This had nothing to do with Okta's platform, as implied. A third-party Vendor Okta used for health insurance information was breached, and personal information on Okta employees was stolen. I'm disappointed in Ars Technica, and Dan Goodin. edit: Updated to be more specific about what part of Okta this had nothing to do with.
https://www.rightwayhealthcare.com is the company mentioned in the article. Okta is shown as a customer on the website, and the company's marketing says "Our members love using Rightway". There is zero mention of security on their website that I see, but the website is entirely marketing and self-congratulatory. I would expect that other Rightway customers were likely also affected, but they had no comment mentioned…
Okta hit by third-party breach, stealing employee data
61–70 of 93 posts
Re: Okta hit by third-party breach, stealing employee data
#62Re: Okta hit by third-party breach, stealing employee data
#63Earlier quoted context omitted.
Those "assessments" amount to sending over a document that says 1. Are you secure? 2. Are you secure? 3. Are you secure? 4. Are you secure? ... 37. Are you secure? and the company sends back 1. Yes. 2. Yes. 3. Yes, definitely. 4. Oh yes. ... 37. Yes. There's a lot more words, but not necessarily a lot more value in those words then what I have here. Some, I admit, but not necessarily a lot. Maybe at the high governme…
Another way of looking at it is that if a company doesn't truth you to answer truthfully, why are they choosing you as a vendor? Presumably you'd be lying about the thing they'd be buying too, or innumerable other things. And 'subsequent lawsuit' is usually a powerful motivator to be honest.
It's literally a deal breaker to send back No, so there's a lot of incentive to do what it takes to send a Yes back.
And "subsequent lawsuit" is a very distant threat in this case.
Less cynically, there are some standards that do have some non-zero teeth in them. Some audits are challenging and at least rate "a good exercise". But that's what I mean by even if the vender truly believes they are compliant with ISO-Thirty-Three-Million-And-Two-Subrevision-A24, they're just one error away from ohnoyourdatabase anyhow.
The net-net of it all is that, as I sort of alluded to, are these assessments worthless? I mean, no, not quite literally zero. If you send one of these documents to a startup of two dudes and a cat and they claim ISO-Thirty-Three-Million-And-Two-Subrevision-A24 compliance, they're lying and the person examining their assessment at least has a chance to be suspicious about it. But in real terms, are they going to be the difference? Unlikely.
Or, let me put this another way. I would bet substantial money Okta has in their possession a response to their questionnaire from Rightway Healthcare in which Rightway Healthcare sings the praises of their immense, extraordinary, back-breaking, industry-leading security efforts, complete with citation of the relevant industry standards they comply with, and that it looks as good as anyone else's answers.
Yet, here we are.
Re: Okta hit by third-party breach, stealing employee data
#64Earlier quoted context omitted.
They have lots of ready to go connectors which makes it easy to integrate lots of apps instead of figuring out all the SAML settings... but any SAML provider will work as long as you can map the right fields. But people like easy things and Okta makes it easy. Many apps who don't have a connector will have docs on how to set things up with Okta, for others you'll have to take the Okta instructions and figure out what…
I'm a bit confused, this seems like a list of pros or at least neutral things?
Re: Okta hit by third-party breach, stealing employee data
#65Re: Okta hit by third-party breach, stealing employee data
#66Not really Okta's fault here, just so happened that Okta was a client of this benefits company. Still, not a good look for Okta.
There are two types of people, people who take responsibility for things that aren’t directly their fault, and people who regularly experience negative outcomes. Okta chose this vendor and they chose to have them store this data. They probably even have security requirements in their contract with them. They could have prevented this. And when you present yourself as a security company, you’re expected to.
Re: Okta hit by third-party breach, stealing employee data
#67A whole lotta nothing. Unless you are an Okta employee.
Which has been a problem, and this enables being more of a problem.
Re: Okta hit by third-party breach, stealing employee data
#68Earlier quoted context omitted.
Most large companies vet their vendors to some extent. It's hard to know if that happened in this case or not, but it's still part of the normal procurement process to perform a security review. These reviews have varying levels of security requirements depending on what type of PII will be stored or processed. Considering this breach included SSN's I'd have expected this to be one of the more thorough reviews.
Those "assessments" amount to sending over a document that says 1. Are you secure? 2. Are you secure? 3. Are you secure? 4. Are you secure? ... 37. Are you secure? and the company sends back 1. Yes. 2. Yes. 3. Yes, definitely. 4. Oh yes. ... 37. Yes. There's a lot more words, but not necessarily a lot more value in those words then what I have here. Some, I admit, but not necessarily a lot. Maybe at the high governme…
Re: Okta hit by third-party breach, stealing employee data
#69Earlier quoted context omitted.
"another" is the weasel word It implies this breach is the same as the previous breach, which it's not. Ars has gone to shit over the last decade.
I don't think I agree that the use of the word "another" implies that the breaches were equal, but I can see why others might interpret it that way. I won't disagree with opinion on the quality of Ars' reporting or this particular article, but I do disagree with the original comment's statement that "this had nothing to do with Okta".
Re: Okta hit by third-party breach, stealing employee data
#70Earlier quoted context omitted.
Ok, but that's not what the article says. It says Okta was breached. Okta was not breached.
It says Okta was "hit by" a breach, which it was. A breach happened, and Okta was impacted. Furthermore, it happened to data which Okta is ultimately responsible for, and Okta should be held responsible for their choices which led to their employees' data being stolen. I'm not sure why you're splitting hairs on this.