Okta’s Investigation of the January 2022 Compromise
1–10 of 124 posts
Re: Okta’s Investigation of the January 2022 Compromise
#2Re: Okta’s Investigation of the January 2022 Compromise
#3Really don't like that they're still unwilling to actually say the name of the 'leading forensic firm'.
Re: Okta’s Investigation of the January 2022 Compromise
#4Uh huh, makes sense
> Named SuperUser
Uhh...
It lists all the operations that it can't do, but not what it can do. Can they download a private SAML certificate? Can they impersonate a user? Can they configure SSO and MFA settings? Can they download audit logs?
Re: Okta’s Investigation of the January 2022 Compromise
#5Pretty ominous name. I wouldn’t hand out “super user” accounts to support engineers from contracting firms for “basic duties in handling inbound support queries”.
Re: Okta’s Investigation of the January 2022 Compromise
#6Re: Okta’s Investigation of the January 2022 Compromise
#7Re: Okta’s Investigation of the January 2022 Compromise
#8"In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers."
And then go on to write paragraphs of detail and a timeline that explicitly shows for a five day period an unauthorized user had full super user access to the service.
He explicitly says, "The report from the forensic firm highlighted that there was a five-day window of time between January 16-21, 2022 when the threat actor had access to the Sitel environment, which we validated with our own analysis."
This is some unbelievable double speak to try to claim that Okta was not breached. Any trust I had in this company is completely in the toilet, just based on this response. How is the CEO not responding to this too? The hole just keeps getting dug deeper the more they say.
Re: Okta’s Investigation of the January 2022 Compromise
#9* They stress that the compromised account wasn't able to "create/delete users or download customer databases", but not what it could do. Could it change passwords of accounts and add 2fa methods, allowing them to take over rarely/never accessed users? Disable 2fa? Change account permissions? List user accounts and metadata to build a user account DB for further attacks? The application is named "SuperUser" ...
* It took public posting of a screenshot to trigger an audit of access logs, two months after the compromise was detected!
* "Only" 2.5% of customers were accessed. That's supposed to be a good thing? Those were certainly the most valuable targets.
* Concludes everything is just fine and no corrective actions need to be taken, but affected customers might want to do their own analysis... Huh?
Sounds a lot like damage control.
Re: Okta’s Investigation of the January 2022 Compromise
#10I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…
At this point, it would be helpful for Okta to stop using the term "breached", because apparently they aren't using the word in the same way everyone else is, and it's a point of contention.