So if I'm reading this right, Okta was aware of a "compromise" of one of their sub-processors that impacted an unknown number of their customers/end users. They then waited more than 2 months before performing their own rudimentary analysis of the audit log to see what actions that sub-processor may have taken during the "compromise". Their CSO writes, "Over the past 24 hours we have analyzed more than 125,000 log en…
The compromised tenant looks like it was specifically _not_ one of the EMEA ones so GDPR wouldn't be relevant here.
Okta’s Investigation of the January 2022 Compromise
121–124 of 124 posts
Re: Okta’s Investigation of the January 2022 Compromise
#122I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…
Re: Okta’s Investigation of the January 2022 Compromise
#123Re: Okta’s Investigation of the January 2022 Compromise
#124Earlier quoted context omitted.
A person who should not have had access to the system gained near full admin access for five whole days. That is the textbook definition of a breach of security. It doesn't matter if they did it by fooling or paying a low level CS rep to get access to their account vs. using their 'leet hacking skillz' to pwn the electronic defenses. A breach is a breach and the CSO of all people has to own up to that fact.
On the topic of 'leet hacking skillz' I personally find it strange that so many Silicon Valley companies only care abut leetcode for the interview process. You can be a security expert and no tech company will care unless you cram leetcode non-stop. On the plus side the lack of security focus makes for a lot of opportunities for the stock market when betting against overvalued tech companies with this problem!
one day there will probably be professional engineering certifications for software engineers, and those certifications will largely center around building secure software and systems. (with maybe some focus on safety critical systems as well)
it's funny when you think about how young the field is.