Connecting a few dots why, while the headline seems misleading, it might matter. 1. Okta employee PII and foreign key to employee health info (a particularly sensitive class of PII) may be exposed. “On October 12, 2023, Rightway informed Okta that an unauthorized actor gained access to an eligibility census file maintained by Rightway in its provision of services ...” https://www.documentcloud.org/documents/24110001-…
Thanks for this. Posts like this are why I like Hacker News. This is a valid problem for Okta, and I think accurately frames the problem. Real-talk, if you were calling the shots at Okta, what would you do here? Enforce hardware-key MFA everywhere, for every vendor service? Impose a no-professional-social-media policy for all employees? This probably is too late to do any good, but it's pretty clear phishing is a hot…
From their incident report yesterday it looks as though Okta started by blaming the victims, taking half a month to realize Okta itself was the problem. Then they clamped down on Chrome's automatic exfil of company credentials.
That feels narrow.
What seems evident, but not addressed, is their initial reaction of victim customer blaming, the identification of suspicious behavior by multiple different customers before seeing it themselves, and the previous latitude for Chrome, likely trace back to lax culture and behavior, particularly around insider threat: not behaving as if they really believe "the problem is us".
So, address the specific faults as Okta did, but attribute those to a 'root cause' need for a stronger 'security mindset' with active insider threat modeling across all employees and roles, and insider focused detective controls.
Something like, "We spend all our time helping less secure customers level up their security and it's easy to feel good about how much more secure we are than most. But we ourselves don't have to be just better than our customers which probably seems easy. We have to be better than the threats who want to use us against our customers, and that's incredibly hard. Clearly we can do better."
Then double down on security mindset training (for customers to be secure, we have to be secure), and as part of that do comprehensive insider threat modeling and tabletop exercises across roles (even janitors or receptionists), with internal incentives to identify frictionless 'detection and response' controls opportunities across processes and systems.
In parallel I'd pick a new red team pen test firm (more than one, with different strengths and different cultural backgrounds outside US, e.g. Eastern Europe, Israel, Asia), adding a bonus above the standard fixed bid for every avenue identified.
But for the biggest backlog of things to fix, I'd have them do a round inside, with privilege. No room for the idea "if they're inside we already lost" since they will get inside. If I don't know to prevent things like what the insider pentests find, could I at least have seen those types of things?
We need to hear less whack-a-mole prevention in breached firms' writeups, more recognition of insider vantage threat, with visibility and detection.
- - -
TL;DR: Think through: (1) How do we become more worthy of trust. (2) How do we make trust irrelevant?