Live data from Hacker News

Okta hit by third-party breach, stealing employee data

arstechnica.com

11–20 of 93 posts

Re: Okta hit by third-party breach, stealing employee data

#11

Okta is so lame no wonder is so popular among corporate mediocrity.

Out of interest - what makes you say this? I'm not disagreeing, just want to understand the general (and seemingly commonly held) belief that they suck.

They have lots of ready to go connectors which makes it easy to integrate lots of apps instead of figuring out all the SAML settings... but any SAML provider will work as long as you can map the right fields. But people like easy things and Okta makes it easy. Many apps who don't have a connector will have docs on how to set things up with Okta, for others you'll have to take the Okta instructions and figure out what that means for an alternate provider. There are other things like counter-signatures which may be easier to do with Okta but also possible with others, if you have the right docs.

Re: Okta hit by third-party breach, stealing employee data

#12
post #9

Not really Okta's fault here, just so happened that Okta was a client of this benefits company. Still, not a good look for Okta.

Does that matter, though? The message I get is that Okta isn't good with security, and they're not good at choosing vendors who are good with security.

Yes, context matters. If you discount every company that might be impacted by a third-party breach of employee data, you will be left with no vendors. At some point you have to decide what is acceptable, and have insurance/indemnity for the risks.

I would not discount Okta because of a decision made by HR.

Re: Okta hit by third-party breach, stealing employee data

#13
post #11

Earlier quoted context omitted.

Out of interest - what makes you say this? I'm not disagreeing, just want to understand the general (and seemingly commonly held) belief that they suck.

They have lots of ready to go connectors which makes it easy to integrate lots of apps instead of figuring out all the SAML settings... but any SAML provider will work as long as you can map the right fields. But people like easy things and Okta makes it easy. Many apps who don't have a connector will have docs on how to set things up with Okta, for others you'll have to take the Okta instructions and figure out what…

Thank you.

Ok another question - where do you see Cerby fitting into that mix?

Re: Okta hit by third-party breach, stealing employee data

#14

Okta is so lame no wonder is so popular among corporate mediocrity.

What is your preferred alternative?

Out of interest, why would you not just use the directory services that you get bundled with google workspace, azureAD (Now: Entra) or freeipa/keycloak?

All of these support oauth2 and SAML, and dynamic groups for less than the cost of each and okta (it seems to be the case everywhere I have seen okta used, another of the above providers is used additionally).

Re: Okta hit by third-party breach, stealing employee data

#15
post #9

Earlier quoted context omitted.

Does that matter, though? The message I get is that Okta isn't good with security, and they're not good at choosing vendors who are good with security.

Yes, context matters. If you discount every company that might be impacted by a third-party breach of employee data, you will be left with no vendors. At some point you have to decide what is acceptable, and have insurance/indemnity for the risks. I would not discount Okta because of a decision made by HR.

Most large companies vet their vendors to some extent. It's hard to know if that happened in this case or not, but it's still part of the normal procurement process to perform a security review. These reviews have varying levels of security requirements depending on what type of PII will be stored or processed. Considering this breach included SSN's I'd have expected this to be one of the more thorough reviews.

Re: Okta hit by third-party breach, stealing employee data

#16
> We have no evidence to suggest that your personal information has been misused against you.

What a fucking horribly disingenuous statement. They are trying to say that nothing bad happened, but their SSN and information was stolen!! The information is going to be sold and at a later date it could be used. But they're not saying that, they're trying to say "Nothing to see here, your information wasn't misused so don't worry!" I would never trust them after giving this statement.

Re: Okta hit by third-party breach, stealing employee data

#17
post #14

Earlier quoted context omitted.

What is your preferred alternative?

Out of interest, why would you not just use the directory services that you get bundled with google workspace, azureAD (Now: Entra) or freeipa/keycloak? All of these support oauth2 and SAML, and dynamic groups for less than the cost of each and okta (it seems to be the case everywhere I have seen okta used, another of the above providers is used additionally).

If you have AzureAD you don’t typically also have Okta. Also the features you listed are like 20% of Okta’s functionality here.

Re: Okta hit by third-party breach, stealing employee data

#18
Did anyone read the article? It's literally not a compromise of Okta. It's a compromise of a healthcare provider that Okta is a customer of. Has absolutely nothing to do with Okta's products, at all, whatsoever.

This is bordering on yellow journalism. I am all for giving shitty companies their due when they fuck up, but that's not what this is at all.

Re: Okta hit by third-party breach, stealing employee data

#19

> We have no evidence to suggest that your personal information has been misused against you. What a fucking horribly disingenuous statement. They are trying to say that nothing bad happened, but their SSN and information was stolen!! The information is going to be sold and at a later date it could be used. But they're not saying that, they're trying to say "Nothing to see here, your information wasn't misused so don…

Not to discount your point- you’re right it’s so disingenuous.

BUT we’re quickly approaching a world where every American has been in a leak that affects their data and SSN. Not 100% of course (simply because young people haven’t had a chance to be screwed over) but at some point we should assume that the information is public for a large enough portion of the population and we need to set new expectations.

Re: Okta hit by third-party breach, stealing employee data

#20
post #11

Earlier quoted context omitted.

Out of interest - what makes you say this? I'm not disagreeing, just want to understand the general (and seemingly commonly held) belief that they suck.

They have lots of ready to go connectors which makes it easy to integrate lots of apps instead of figuring out all the SAML settings... but any SAML provider will work as long as you can map the right fields. But people like easy things and Okta makes it easy. Many apps who don't have a connector will have docs on how to set things up with Okta, for others you'll have to take the Okta instructions and figure out what…

I'm a bit confused, this seems like a list of pros or at least neutral things?
Post reply on HN