Live data from Hacker News

Updated Okta Statement on Lapsus$

okta.com

191–200 of 239 posts

Re: Updated Okta Statement on Lapsus$

#191
post #7

> In January 2022, Okta detected an unsuccessful attempt to compromise the account of a customer support engineer working for a third-party provider It looked kinda successful though...

I think they're meaning it like a login attempt here. If you submit a login form 5 times, that's 5 login attempts. Another similar example is free throw attempts . https://www.statmuse.com/nba/ask/most-free-throw-attempts-pe... I wouldn't have realized that unless I'd read far enough to see that Entity A did compromise Account B. Since the author didn't define what an attempt in this context means, I think it would b…

Ahhh you reckon they are being sneaky with language? So something like:

- unsuccessful login occurs

- successful login + screenshot + various nefarious actions

- (some time later)

- attacker's access locked down

Implying that they detected an unsuccessful login, but doesn't mean that they didn't prevent unauthorized access, which would make what they said technically correct but kinda useless for us users. That is something I did not originally consider, but wow ... maybe. I hope not. I mainly want answers about what is affected, and whether Auth0 was compromised.

Re: Updated Okta Statement on Lapsus$

#192

Earlier quoted context omitted.

Channel sprawl is very normal. While my day job has a broad scope in the org, I’m a “member” of over 900 MS Teams. I’d guess that 3% are active and i interact with 0.

900 teams? That's a lot, are you sure you don't mean 900 channels (or whatever Teams calls them) instead?

Nope. 900 teams.

Somewhere, there’s some project manager that says “Wow, I bet spooky23 would love to know about my spreadsheet sorting project”.

Re: Updated Okta Statement on Lapsus$

#194
post #17

Earlier quoted context omitted.

If somebody uses my laptop, my Gmail account is not compromised; I'm being dolphined. Of course 5 days is quite a long time, but this is just to clarify what you didn't understand.

If someone has access to your laptop with a logged-in Gmail account, they could change your password and log you out of your other devices, effectively gaining total control of your account and locking you out.

Typically services will have you confirm your current password before allowing you to change it (for exactly this reason).

Re: Updated Okta Statement on Lapsus$

#196
post #182

Earlier quoted context omitted.

> If that service is compromised, it doesn't really seem to matter how? I hear what you're saying, but the how does really matter, and will change how customers perceive the issue and make decisions about how to react. e.g. "databases were open to the Internet and all data has been siphoned" lands quite differently than "a staff member abused their privileges but the scope of abuse was limited to xyz". If I'm a custo…

How it happened doesn't change the fact that they have been breached. If I was a bank and claimed that I haven't been robbed, an insider just transferred billions of pounds out of the bank and then fled, I think everyone would rightly say "What are you talking about, you have been robbed!" It doesn't matter if it was done by a guy in a black and white stripey t-shirt, or if it was done by a rogue internal employee, a…

I don't think anyone would call the second case a robbery, they'd call it embezzlement or fraud.

Re: Updated Okta Statement on Lapsus$

#197
post #172

Earlier quoted context omitted.

I moved over to Azure AD this morning (we only have a few devs and were already using Azure DevOps so this was doable). I requested that Okta cancel our account and let them know the reason was the potential data breach and their CEO's response on Twitter. Okta's response was that we signed an MSA agreement and that cancelling isn't an option, nor termination of fees.

They sound like they're running the organisation like a dating site. More reasons to look elsewhere.

Or like Adobe: https://news.ycombinator.com/item?id=30222165

Re: Updated Okta Statement on Lapsus$

#198
post #165

Earlier quoted context omitted.

We’ve been monitoring this internally, as customers of an Okta-like service. I’ve also been closely monitoring the responses from our CTO and VP of Security when someone from our DevOps team posted a link to the Verge article in slack this morning. Which brings me to this inquiry: How are your orgs responding to this? We have a dependency on an Okta-like provider and my first thought when reading this news was “you k…

I moved over to Azure AD this morning (we only have a few devs and were already using Azure DevOps so this was doable). I requested that Okta cancel our account and let them know the reason was the potential data breach and their CEO's response on Twitter. Okta's response was that we signed an MSA agreement and that cancelling isn't an option, nor termination of fees.

Okta is the Oracle of identity management.

https://auth0.com is the "still cares about customers" vendor

I'm not affiliated with them, just traumatized by working in IT

Re: Updated Okta Statement on Lapsus$

#199
post #8

I don't understand how they can say "unsuccessful attempt to compromise the account of a customer support engineer" . then can say "Following the completion of the service provider’s investigation, we received a report from the forensics firm this week. The report highlighted that there was a five-day window of time between January 16-21, 2022, where an attacker had access to a support engineer’s laptop. This is cons…

It is really clever wording, but it is possible for the statements to be true, while being deliberately misleading. What they initially detected, and what the 3rd-party investigation found, were two different things. Okta initially "detected an unsuccessful attempt" - the successful attempts were not detected initially but the detected event did lead to an investigation. Now, JUST this week (presumably, in the last 7…

I didn't find this misleading at all. Just a chronology of their evolving understanding.

Re: Updated Okta Statement on Lapsus$

#200
post #129

Given the nature of what Okta does, is this going to kill them? It's like the business version of a headshot.

Probably not. It's really inconvenient for a large organisation to drop them given how embedded identity gets into everything. It's reputational damage but something worse [0] happened to OneLogin a few years back and they're still around. [0] https://www.csoonline.com/article/3389138/how-onelogin-respo... (unsurprisingly the canonical article from their weblog is missing now)

https://news.ycombinator.com/item?id=14458105 | https://web.archive.org/web/20170621202358/https://www.onelo...
Post reply on HN