I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…
Okta’s Investigation of the January 2022 Compromise
111–120 of 124 posts
Re: Okta’s Investigation of the January 2022 Compromise
#112I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…
> an unauthorized user had full super user access to the service From the article: > The majority of support engineering tasks are performed using an internally-built application called SuperUser or SU for short, which is used to perform basic management functions of Okta customer tenants. This does not provide “god-like access” to all its users. This is an application built with least privilege in mind to ensure tha…
Support _Engineer_ that is using a prebuilt application to do stuff like reset MFA. In what world does this have anything to do with engineering?
Re: Okta’s Investigation of the January 2022 Compromise
#113Earlier quoted context omitted.
One company doing a bad job does not mean it's impossible or even uncommon to do a good job. Also, if you wanted to hedge against Okta... feel free. You can U2F 2FA your services behind Okta or in front of it. We use GSuite SSO, but everywhere we can set 2FA outside of it we do so.
> does not mean it's impossible or even uncommon to do a good job. The only way one can reach this conclusion is by ignoring all the breaches / CVEs that happened in large companies during the past few years. Nowadays I just assume every company is crap at security unless proven otherwise.
Yes, most companies are bad at security. Some aren't though. The problem right now is figuring out which ones are - there's very little signal.
Re: Okta’s Investigation of the January 2022 Compromise
#114I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…
Re: Okta’s Investigation of the January 2022 Compromise
#115Earlier quoted context omitted.
At my own workplace (a SaaS service), we cannot change passwords, we can only send reset links (and the reset email goes to the end user). I can't see any place in the screenshots where they are setting a user's password, only sending reset links (which would do nothing if the support user does not have access to system email or end users email). Also at my workplace, 2FA is not enforced by an IdP (like Okta), but by…
How do you send a reset password email with a SSO platform that gates email?
Re: Okta’s Investigation of the January 2022 Compromise
#116Earlier quoted context omitted.
> It seems they care more about their shareholders than their customers. isn't this how publicly-traded companies are supposed to work ? I agree on critizicing that approach and capitalism model, but I don't understand how that isn't common knowledge here.
Of course the sole purpose of a publicly traded company is to maximise the revenue for its shareholders, however, you can take a long term or short term approach on this. Okta appeared to have kept this under wraps to prevent a shareholders backlash (short term approach) However, as a result they achieved the opposite, as the share price is still down this morning. This may of course be a temporarily glitch, however,…
Re: Okta’s Investigation of the January 2022 Compromise
#117Earlier quoted context omitted.
I view this hack as a public service - we're seeing how awfully these big security companies actually handle security in the worst case. Let that be a lesson to everyone who is in favour of mass centralisation. There needs to be a security solution where Okta essentially provides the skeleton of the infrastructure but not the entire solution, such that an Okta compromise does not compromise everyone who uses them.
One company doing a bad job does not mean it's impossible or even uncommon to do a good job. Also, if you wanted to hedge against Okta... feel free. You can U2F 2FA your services behind Okta or in front of it. We use GSuite SSO, but everywhere we can set 2FA outside of it we do so.
We all know it is very uncommon to do a great job. Everyone has been breached sooner or later. Any anyone who has worked in engineering or security in tech companies knows how often security concerns are underprioritized far behind more visible but less important work.
Hedging is a good answer. Relying on a single point of failure that, if it ever fails open, will expose everything at once? Not a smart idea.
Re: Okta’s Investigation of the January 2022 Compromise
#118I don't understand how OKTA is +4.34%/1M and 10.26%/5D. This is bat-shit crazy lol. Anyway I put a 10,000USD 5x sell at 166.19, let's see how it goes from here :D :D :D
hahha. downvote at will. I just made $2k with literally twenty mouse clicks.
I'm excited about this and in the future will be checking stock price first thing when I see these smaller publicly listed tech companies getting hit with big hacks.
For MSFT (and companies of that size) this type of news doesn't move the stock that much but with current volatility there will be plenty of great plays in the future for smaller companies.
Re: Okta’s Investigation of the January 2022 Compromise
#119tl;dr - Companies cheerfully handed over their golden skeleton and city (company) keys over to a third party service provider that offers SSO and now, after they got hacked by some kiddy that writes like a teenager, we found out that they also just cook with water (or less: api keys in slack). Now the public company communication is a reputation crushing web of lies, inaccuracies and whining.
The stock hasn't crashed yet. I see opportunity.
Re: Okta’s Investigation of the January 2022 Compromise
#120Earlier quoted context omitted.
> And then go on to write paragraphs of detail and a timeline that explicitly shows for a five day period an unauthorized user had full super user access to the service. it sounds like they built the support tool (with its unfortunate name) such that it places limited trust in support contractors and the information technology that supports them. because of this they're able to identify potentially affected customers…
A person who should not have had access to the system gained near full admin access for five whole days. That is the textbook definition of a breach of security. It doesn't matter if they did it by fooling or paying a low level CS rep to get access to their account vs. using their 'leet hacking skillz' to pwn the electronic defenses. A breach is a breach and the CSO of all people has to own up to that fact.
You can be a security expert and no tech company will care unless you cram leetcode non-stop.
On the plus side the lack of security focus makes for a lot of opportunities for the stock market when betting against overvalued tech companies with this problem!