Live data from Hacker News

Okta hit by third-party breach, stealing employee data

arstechnica.com

61–70 of 93 posts

Re: Okta hit by third-party breach, stealing employee data

#61

What a misleading and click-baity title choice by Ars Technica. This had nothing to do with Okta's platform, as implied. A third-party Vendor Okta used for health insurance information was breached, and personal information on Okta employees was stolen. I'm disappointed in Ars Technica, and Dan Goodin. edit: Updated to be more specific about what part of Okta this had nothing to do with.

https://www.rightwayhealthcare.com is the company mentioned in the article. Okta is shown as a customer on the website, and the company's marketing says "Our members love using Rightway". There is zero mention of security on their website that I see, but the website is entirely marketing and self-congratulatory. I would expect that other Rightway customers were likely also affected, but they had no comment mentioned…

Okta is promoting Rightway as a benefit of Okta: https://rewards.okta.com/us/healthcare/medical/rightway-heal...

Re: Okta hit by third-party breach, stealing employee data

#63
post #59
post #30

Earlier quoted context omitted.

Those "assessments" amount to sending over a document that says 1. Are you secure? 2. Are you secure? 3. Are you secure? 4. Are you secure? ... 37. Are you secure? and the company sends back 1. Yes. 2. Yes. 3. Yes, definitely. 4. Oh yes. ... 37. Yes. There's a lot more words, but not necessarily a lot more value in those words then what I have here. Some, I admit, but not necessarily a lot. Maybe at the high governme…

Another way of looking at it is that if a company doesn't truth you to answer truthfully, why are they choosing you as a vendor? Presumably you'd be lying about the thing they'd be buying too, or innumerable other things. And 'subsequent lawsuit' is usually a powerful motivator to be honest.

The next layer of cynicism down is more complicated. I'm going to make this up to protect the guiltocent, but I've been on the receiving end of security assessments that ask the moral equivalent of "Do you salt the MD5 hashes you use to store password hashes?" and we end saying Yes in some large number of words because we use bcrypt/scrypt properly, or some industry SSO, or our systems communicate with an internal CA TLS authority where "passwords" aren't even in sight, or whatever other solution leaves salted MD5 in the dust.

It's literally a deal breaker to send back No, so there's a lot of incentive to do what it takes to send a Yes back.

And "subsequent lawsuit" is a very distant threat in this case.

Less cynically, there are some standards that do have some non-zero teeth in them. Some audits are challenging and at least rate "a good exercise". But that's what I mean by even if the vender truly believes they are compliant with ISO-Thirty-Three-Million-And-Two-Subrevision-A24, they're just one error away from ohnoyourdatabase anyhow.

The net-net of it all is that, as I sort of alluded to, are these assessments worthless? I mean, no, not quite literally zero. If you send one of these documents to a startup of two dudes and a cat and they claim ISO-Thirty-Three-Million-And-Two-Subrevision-A24 compliance, they're lying and the person examining their assessment at least has a chance to be suspicious about it. But in real terms, are they going to be the difference? Unlikely.

Or, let me put this another way. I would bet substantial money Okta has in their possession a response to their questionnaire from Rightway Healthcare in which Rightway Healthcare sings the praises of their immense, extraordinary, back-breaking, industry-leading security efforts, complete with citation of the relevant industry standards they comply with, and that it looks as good as anyone else's answers.

Yet, here we are.

Re: Okta hit by third-party breach, stealing employee data

#64
post #11

Earlier quoted context omitted.

They have lots of ready to go connectors which makes it easy to integrate lots of apps instead of figuring out all the SAML settings... but any SAML provider will work as long as you can map the right fields. But people like easy things and Okta makes it easy. Many apps who don't have a connector will have docs on how to set things up with Okta, for others you'll have to take the Okta instructions and figure out what…

I'm a bit confused, this seems like a list of pros or at least neutral things?

People use them because they are easy to use, on the other hand their security issues over the past few years could make clients consider alternatives.

Re: Okta hit by third-party breach, stealing employee data

#66

Not really Okta's fault here, just so happened that Okta was a client of this benefits company. Still, not a good look for Okta.

There are two types of people, people who take responsibility for things that aren’t directly their fault, and people who regularly experience negative outcomes. Okta chose this vendor and they chose to have them store this data. They probably even have security requirements in their contract with them. They could have prevented this. And when you present yourself as a security company, you’re expected to.

There are two types of people, those who express everything in dichotomies, and those who don't, and those who start indexing at zero.

Re: Okta hit by third-party breach, stealing employee data

#68
post #30
post #15

Earlier quoted context omitted.

Most large companies vet their vendors to some extent. It's hard to know if that happened in this case or not, but it's still part of the normal procurement process to perform a security review. These reviews have varying levels of security requirements depending on what type of PII will be stored or processed. Considering this breach included SSN's I'd have expected this to be one of the more thorough reviews.

Those "assessments" amount to sending over a document that says 1. Are you secure? 2. Are you secure? 3. Are you secure? 4. Are you secure? ... 37. Are you secure? and the company sends back 1. Yes. 2. Yes. 3. Yes, definitely. 4. Oh yes. ... 37. Yes. There's a lot more words, but not necessarily a lot more value in those words then what I have here. Some, I admit, but not necessarily a lot. Maybe at the high governme…

Self-assessments are definitely an option some companies use, but there is a middle ground between a full assessment conducted by the customer and a self-assessment. ISO, SOC2, etc. all provide what I would consider to be better than a simple self-assessment as they require a third-party audit. They aren't anywhere close to perfect but they are significantly better than a self-assessment IMHO. There are no guarantees, of course.

Re: Okta hit by third-party breach, stealing employee data

#69
post #53

Earlier quoted context omitted.

"another" is the weasel word It implies this breach is the same as the previous breach, which it's not. Ars has gone to shit over the last decade.

I don't think I agree that the use of the word "another" implies that the breaches were equal, but I can see why others might interpret it that way. I won't disagree with opinion on the quality of Ars' reporting or this particular article, but I do disagree with the original comment's statement that "this had nothing to do with Okta".

Without knowing the context, I doubt anyone reading the title is thinking "maybe they mean another breach where Okta is impacted but Okta is not the culprit, despite recent events". No, the title is simply misleading. They could have swapped Okta for another company's name or something like "Personal information stolen in healthcare company breach", and the news likely wouldn't get much attention, which is as much as what the article is actually worth. Singling out Okta among many of that company's clients is simply meaningless and wrong and does nothing other than attention grabbing.

Re: Okta hit by third-party breach, stealing employee data

#70

Earlier quoted context omitted.

Ok, but that's not what the article says. It says Okta was breached. Okta was not breached.

It says Okta was "hit by" a breach, which it was. A breach happened, and Okta was impacted. Furthermore, it happened to data which Okta is ultimately responsible for, and Okta should be held responsible for their choices which led to their employees' data being stolen. I'm not sure why you're splitting hairs on this.

Because context and sentiment matters. By your logic clickbait is perfectly fine and we should maybe do more because they are (usually) technically correct.
Post reply on HN