Live data from Hacker News

Okta’s Investigation of the January 2022 Compromise

okta.com

121–124 of 124 posts

Re: Okta’s Investigation of the January 2022 Compromise

#121

So if I'm reading this right, Okta was aware of a "compromise" of one of their sub-processors that impacted an unknown number of their customers/end users. They then waited more than 2 months before performing their own rudimentary analysis of the audit log to see what actions that sub-processor may have taken during the "compromise". Their CSO writes, "Over the past 24 hours we have analyzed more than 125,000 log en…

The compromised tenant looks like it was specifically _not_ one of the EMEA ones so GDPR wouldn't be relevant here.

I think the issue is that they just wouldn’t know. They didn’t know which customers were impacted. They didn’t know which users personal data might have been compromised. They most likely don’t have the ability to determine whether a user is a EU resident or not as this information would reside with their customers HR systems which all points to having to notify to avoid the legal complications.

Re: Okta’s Investigation of the January 2022 Compromise

#122

I don't understand how the CSO can write this: "In this post, I want to provide a timeline and my perspective on what has transpired, and where we are today with this investigation. I hope that it will illuminate why I am confident in our conclusions that the Okta service has not been breached and there are no corrective actions that need to be taken by our customers." And then go on to write paragraphs of detail and…

I’m finding it hard to figure out what the role of a CSO is after this incident. They seem to be the least knowledgeable about the product they’re creating as to offer the highest degree of plausible deniability possible.

Re: Okta’s Investigation of the January 2022 Compromise

#124

Earlier quoted context omitted.

A person who should not have had access to the system gained near full admin access for five whole days. That is the textbook definition of a breach of security. It doesn't matter if they did it by fooling or paying a low level CS rep to get access to their account vs. using their 'leet hacking skillz' to pwn the electronic defenses. A breach is a breach and the CSO of all people has to own up to that fact.

On the topic of 'leet hacking skillz' I personally find it strange that so many Silicon Valley companies only care abut leetcode for the interview process. You can be a security expert and no tech company will care unless you cram leetcode non-stop. On the plus side the lack of security focus makes for a lot of opportunities for the stock market when betting against overvalued tech companies with this problem!

security design is pretty much the only thing that resembles real engineering in software. other than safety critical systems, it's pretty much the most common thing that can actually go wrong and harm people.

one day there will probably be professional engineering certifications for software engineers, and those certifications will largely center around building secure software and systems. (with maybe some focus on safety critical systems as well)

it's funny when you think about how young the field is.

Post reply on HN