Live data from Hacker News

Updated Okta Statement on Lapsus$

okta.com

151–160 of 239 posts

Re: Updated Okta Statement on Lapsus$

#151

> Okta service has not been breached and remains fully operational > highlighted that there was a five-day window of time between January 16-21, 2022, where an attacker had access to a support engineer’s laptop These are some impressive mental gymnastics!

[deleted]

Re: Updated Okta Statement on Lapsus$

#152
post #100
post #84

Earlier quoted context omitted.

I suspect lots of small channels with only a few people in them. They have 5k employees, it adds up.

#Tom #Dick #Harry

You jest, but the last two companies have been at have had channels named like "Steves" for all the Steves in the company.

Re: Updated Okta Statement on Lapsus$

#153
post #142

Earlier quoted context omitted.

Yep. All these standards are tick boxing for liability. Nothing more. They are not effective security controls and never will be and should never be a measure of that.

I don't know if tick boxing was a spoonerism or intentional or a real thing but I love it and am stealing it. (Upon further review, it appears to be the more UK way of saying it! Ha!)

Yep UK here. Normal here :)

Re: Updated Okta Statement on Lapsus$

#154
post #140

Earlier quoted context omitted.

I don't understand all these crazy assumptions being made. A support engineer being able to set a password on any account is unthinkable, there is zero chance this is actually the case. Especially for a security company. It would be the equivalent of giving the doorman a key that opens everyone's apartment. Obviously support can trigger a reset, that you have to complete from your own e-mail account.

Confusing analogy, doormen frequently do have a key to every apartment in the building. Anyway I agree it would be bad practice but that doesn't mean it's not done.

> doormen frequently do have a key to every apartment in the building

Really? That's insane. I'd like to hear more about that.

Re: Updated Okta Statement on Lapsus$

#155

> Support engineers are also able to facilitate the resetting of passwords and MFA factors for users, but are unable to obtain those passwords. Very ambiguous statement, not really fitting in with the whole "deeply committed to transparency" image they are trying to emit. What does "facilitate" really refer to here? If it was just triggering it, they would have said so, presumably. And why is only passwords mentioned…

There are hundreds of call centers where all the workers do all day is fill out password screens. The exact nature about what they do varies by client and is probably subject to NDA.

Password reset is the soft underbelly of most companies.

Re: Updated Okta Statement on Lapsus$

#156
post #17

Earlier quoted context omitted.

If somebody uses my laptop, my Gmail account is not compromised; I'm being dolphined. Of course 5 days is quite a long time, but this is just to clarify what you didn't understand.

what does dolphined mean. is this a cyber security term?

It might be a new term that denotes someone who thinks a stranger having access to their computer doesn't compromise their accounts.

Re: Updated Okta Statement on Lapsus$

#157

Earlier quoted context omitted.

they edited and added more content https://img.guildedcdn.com/ContentMedia/372280f522049aa0b0eb...

8600 channels? Wouldn't that overwhelm you? I'm trying to think up scenarios where an org would need so many, but I can't. Is this normal?

We have 70k channels in our slack at my current company. A large portion are deserted.

Re: Updated Okta Statement on Lapsus$

#158
post #59

>The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers. despite an overwhelming preponderance of damning evidence from twitter (as well as the hacker themselves) you've somehow managed to find yourselves secure instead? Christs whiskers thats some impressive doublethink. Its also an excellent opportunity to fall on a sword that giv…

LAPSUS is ransomware gang - they are absolutely incentivised to spread FUD to extract money from anyone and attract new leakers.

We should not glorify them.

Re: Updated Okta Statement on Lapsus$

#159

> The Okta service has not been breached and remains fully operational Oh okay then, pack up guys, everything’s fine I really hate this kind of corporate bullshit > There are no corrective actions that need to be taken by our customers. Isn’t this an objectively false statement?

> Isn’t this an objectively false statement?

IMHO it's more of an empty statement. They never pin down what end-state is being discussed. So we can't evaluate if "additional steps are needed" to achieve that (unspecified) state.

It could be that the speaker is intentionally equivocating. I.e., knowing that the audience will assume some particular end-state. But if cornered, the speaker can claim (lie) that he implicitly meant a different end state.

Re: Updated Okta Statement on Lapsus$

#160

Earlier quoted context omitted.

If I use your laptop to get access to your Gmail isn't your Gmail account compromised? I might not have access to your Gmail username and passwords (and MFA), but I can read your email, I can send email as you, etc etc. I feel like I have compromised your gmail account. If I steal your secure token and log into you through a cloned browser session and access your gmail have I compromised your gmail? It feels like it.…

> your Gmail account compromised The access is transient and you remain in ownership over the credentials and account, because the credentials were not compromised (just the programs/browsers with pre-existing auth). Though with physical access it's probably only a mater of time before local admin passwords are brute forced and access to keychain/browser saved logins is inevitable? > If I steal your secure token It's…

> I think we can all agree there's a difference between having access to the laptop and access to the account without the laptop.

There is a difference, but that difference is not the one you seem to be implying. An account can be compromised even it it hasn't been fully and permanently taken over. The temporariness of an account being compromised does not mean the account was not compromised.

You can make a distinction and clarify that the account was compromised but that the account credentials were not. However if you extend that to saying that the account was not compromised when attackers did have temporary access, then you are simply lying.

Post reply on HN