Live data from Hacker News

Okta hit by third-party breach, stealing employee data

arstechnica.com

71–80 of 93 posts

Re: Okta hit by third-party breach, stealing employee data

#71
Connecting a few dots why, while the headline seems misleading, it might matter.

1. Okta employee PII and foreign key to employee health info (a particularly sensitive class of PII) may be exposed.

“On October 12, 2023, Rightway informed Okta that an unauthorized actor gained access to an eligibility census file maintained by Rightway in its provision of services ...”

https://www.documentcloud.org/documents/24110001-okta-indivi...

The file contained the following information on current and former Okta employees and their dependents:

- Full names

- Social Security Numbers (SSNs)

- Health or Medical Insurance plan number

2. Okta and its customer pool are known to be under an aggressive series of phishing and social engineering attacks.

3. This type of information makes those attacks more effective.

So while this particular breach starts as a Rightway problem, the nature of what was taken puts Okta itself at additional risk, as attackers build their social engineering / phishing dossier while looking for ways to get into Okta and/or get to Okta's customers in bulk.

Re: Okta hit by third-party breach, stealing employee data

#72
post #57

Earlier quoted context omitted.

To the extent that it is reassuring, it is misleading, right? Unless they have some way of being reasonably sure that the fact that they haven’t detected misuse implies that it hasn’t happened.

I think there's probably a legal reason that's included, as it's in all info leak announcements I've seen.

It seems like the most reassuring/misleading thing that can be said without technically lying.

Re: Okta hit by third-party breach, stealing employee data

#73
post #46

What a misleading and click-baity title choice by Ars Technica. This had nothing to do with Okta's platform, as implied. A third-party Vendor Okta used for health insurance information was breached, and personal information on Okta employees was stolen. I'm disappointed in Ars Technica, and Dan Goodin. edit: Updated to be more specific about what part of Okta this had nothing to do with.

Maybe someone is short selling.

The truth is usually less exciting.

Re: Okta hit by third-party breach, stealing employee data

#74
post #46

What a misleading and click-baity title choice by Ars Technica. This had nothing to do with Okta's platform, as implied. A third-party Vendor Okta used for health insurance information was breached, and personal information on Okta employees was stolen. I'm disappointed in Ars Technica, and Dan Goodin. edit: Updated to be more specific about what part of Okta this had nothing to do with.

Maybe someone is short selling.

Someone(s) almost certainly (are), not necessarily relatedly (to the article, to the breaches, yeah absolutely), what a pointlessly vague thing to say.

Re: Okta hit by third-party breach, stealing employee data

#75
post #9

Earlier quoted context omitted.

Does that matter, though? The message I get is that Okta isn't good with security, and they're not good at choosing vendors who are good with security.

Yes, context matters. If you discount every company that might be impacted by a third-party breach of employee data, you will be left with no vendors. At some point you have to decide what is acceptable, and have insurance/indemnity for the risks. I would not discount Okta because of a decision made by HR.

Okta isn't just any random company though. Employee data can be used for targeted attacks, and Okta is a significantly more interesting target than most other companies.

As such I would expect a company like Okta to take much more care about which 3rd party solutions they use.

Re: Okta hit by third-party breach, stealing employee data

#76
post #57

Earlier quoted context omitted.

I think there's probably a legal reason that's included, as it's in all info leak announcements I've seen.

It seems like the most reassuring/misleading thing that can be said without technically lying.

Or there's a legal responsibility to disclose if you know anything? So everyone has to explicitly say they don't?

IANAL, so not sure.

That it's always included and worded exactly the same makes me suspect legal instead of PR.

Re: Okta hit by third-party breach, stealing employee data

#77
post #30
post #15

Earlier quoted context omitted.

Most large companies vet their vendors to some extent. It's hard to know if that happened in this case or not, but it's still part of the normal procurement process to perform a security review. These reviews have varying levels of security requirements depending on what type of PII will be stored or processed. Considering this breach included SSN's I'd have expected this to be one of the more thorough reviews.

Those "assessments" amount to sending over a document that says 1. Are you secure? 2. Are you secure? 3. Are you secure? 4. Are you secure? ... 37. Are you secure? and the company sends back 1. Yes. 2. Yes. 3. Yes, definitely. 4. Oh yes. ... 37. Yes. There's a lot more words, but not necessarily a lot more value in those words then what I have here. Some, I admit, but not necessarily a lot. Maybe at the high governme…

I think you haven't seen enough. Self assessment is a great start. I've seen companies demanding their vendors to go through pentesting from several different pentesting companies, and then addressing all high-severity issues to the satisfaction of the pentesting company before officially allowed as a vendor.

Naturally you still have to trust the pentesting company to do a good job but it's better than just a self assessment.

Re: Okta hit by third-party breach, stealing employee data

#78

Earlier quoted context omitted.

> we’re quickly approaching a world where every American has been in a leak that affects their data and SSN. Not 100% of course (simply because young people haven’t had a chance to be screwed over) … that number, presently, has to be a rounding error from being 100%. My SSN was first breached when I was in high school, at least . But yeah, I agree, we should set new expectations. There could definitely be a better sy…

We need a bunch of case law indicating that banks and credit card companies that don’t authenticate past this widely leaked PII are on the hook for the loss of money (rather than the uninvolved third parties who are being impersonated).

This is already the case. You have to prove you weren’t involved (a quick police report will do), but you’re expected to be made right already. Banks have just deemed this current level of fraud acceptable.

Currently, if Mallory finds Alice’s SSN and opens a credit line at Lazy Bank Corp, and then runs up a bill in Alice’s name, Alice will be assumed responsible. It’ll affect Alice’s credit score, etc when the banks report these balances.

If Alice notices these changes, they can submit a letter to the bank, demanding that the bank remove these reports and close the account (Fair Credit Reporting Act?). The bank can say “but we have the SSN of Alice, so it’s Alice’s” but if Alice can prove they’re not responsible -through lawyers or strongly worded letters or otherwise- (“I don’t and have never lived at the address on file, that IP address originated from Belarus, etc”) then the bank is legally required to remove the association between Alice and that debt. Note that filing a police report is like “auto winning” because it’s a crime to lie to the police.

I think the real question is what’s the actual harm on a society level in not validating further? We already have a process to undo the harm on an individual level, but do we need more onerous procedures?

Re: Okta hit by third-party breach, stealing employee data

#79
post #46

What a misleading and click-baity title choice by Ars Technica. This had nothing to do with Okta's platform, as implied. A third-party Vendor Okta used for health insurance information was breached, and personal information on Okta employees was stolen. I'm disappointed in Ars Technica, and Dan Goodin. edit: Updated to be more specific about what part of Okta this had nothing to do with.

Maybe someone is short selling.

The concept of journalists trading on the news they break is coincidentally making waves right now with this new startup called Hunterbrook[^1]. I assume that outright misleading headlines won't be something they'd risk, but it's an interesting concept, since, yeah normally this is something you'd accuse someone of, and not expect that to be the whole point.

[^1]: https://www.ft.com/content/3c861c6c-87be-459d-b62f-b44bf2d75...

Re: Okta hit by third-party breach, stealing employee data

#80
post #69

Earlier quoted context omitted.

I don't think I agree that the use of the word "another" implies that the breaches were equal, but I can see why others might interpret it that way. I won't disagree with opinion on the quality of Ars' reporting or this particular article, but I do disagree with the original comment's statement that "this had nothing to do with Okta".

Without knowing the context, I doubt anyone reading the title is thinking "maybe they mean another breach where Okta is impacted but Okta is not the culprit, despite recent events". No, the title is simply misleading. They could have swapped Okta for another company's name or something like "Personal information stolen in healthcare company breach", and the news likely wouldn't get much attention, which is as much as…

Immediately what I thought when I read it.

The person you’re responding to is being obtuse to the point where it feels like trolling or contrarianism for the sake of contrarianism. Certainly a bad-faith argument.

Post reply on HN