Live data from Hacker News

New Updated Okta Statement on Lapsus$

news.ycombinator.com

11–20 of 38 posts

Re: New Updated Okta Statement on Lapsus$

#11

I can't believe these idiots tried playing chicken with a hacker, heads need to roll over this one. They have completely and needlessly destroyed their credibility by trying and completely failing to control the narrative.

You know the hackers are going to keep giving them more rope to hang themselves with, should that be the path they want to keep going down.

Re: New Updated Okta Statement on Lapsus$

#13
post #6
post #2

I think the flip flopping is hurting them and their users more and more. What was initially a flat denial this morning has resulted in taunts from Lapsus$ on Twitter, Okta was out-scooped by Cloudflare's public investigation. Now they admit a breach affecting 2.5% (roughly 250 orgs based on public data). The webinar tomorrow should be fascinating if they allow questions.

“A contractor’s laptop was owned for 5 days who had super user access, but we didn’t get breached” was a strange conclusion in their original state.

I think they were gamble my that it couldn't be proven

Re: New Updated Okta Statement on Lapsus$

#14
post #2

I think the flip flopping is hurting them and their users more and more. What was initially a flat denial this morning has resulted in taunts from Lapsus$ on Twitter, Okta was out-scooped by Cloudflare's public investigation. Now they admit a breach affecting 2.5% (roughly 250 orgs based on public data). The webinar tomorrow should be fascinating if they allow questions.

[deleted]

Re: New Updated Okta Statement on Lapsus$

#15

Surprised they’re still being this transparent at this stage. I expected the lawyers to have shut it down by now.

There are thousands of organizations spending a lot of money on okta that are demanding answers. If they didn't respond, their business wouldn't survive.

Re: New Updated Okta Statement on Lapsus$

#17

Surprised they’re still being this transparent at this stage. I expected the lawyers to have shut it down by now.

There are thousands of organizations spending a lot of money on okta that are demanding answers. If they didn't respond, their business wouldn't survive.

I hope their business does not survive; it’s a terrible company with bad products. But I don’t see them going anywhere. They’ve won over IT administrators, many of whom are all in with Okta (and the no code movement). Hard to see them giving up all that investment.

Re: New Updated Okta Statement on Lapsus$

#18

Earlier quoted context omitted.

They lost all credibility when they failed to do the one single thing companies trust them to do, on a massive and severe scale, with long-lasting financial repercussions for AT LEAST 250 of the worlds biggest companies (I believe it's more than they're letting on).

It is a shame that the new DHS 72 hour reporting requirement was not in effect when this breach occurred, but it is extremely evident why it is required. Regarding business classification, I don't think it's too difficult to argue that commercial identity providers are critical infra. https://news.ycombinator.com/item?id=30699024 https://www.congress.gov/bill/117th-congress/house-bill/2471...

That law is modelled on laws in the EU, Australia and other countries. I know if my employer is one of the affected companies they are in breach of our notification laws.

Re: New Updated Okta Statement on Lapsus$

#19

I can't believe these idiots tried playing chicken with a hacker, heads need to roll over this one. They have completely and needlessly destroyed their credibility by trying and completely failing to control the narrative.

The comedy of this is that one would expect an authentication and identity platform to be in the top percent of good actors in security incident response.

Might be time to reinstall Active Directory in your basement.

Post reply on HN