It feels like a lawyer heavily tweaked this to sound better than it really is.
Updated Okta Statement on Lapsus$
21–30 of 239 posts
Re: Updated Okta Statement on Lapsus$
#22It feels like a lawyer heavily tweaked this to sound better than it really is.
Re: Updated Okta Statement on Lapsus$
#23Re: Updated Okta Statement on Lapsus$
#24Lots more detail: https://blog.cloudflare.com/cloudflare-investigation-of-the-...
Anyway, I likely misinterpreted yesterday’s comment..
Re: Updated Okta Statement on Lapsus$
#25Lots more detail: https://blog.cloudflare.com/cloudflare-investigation-of-the-...
the difference in level of detail and amount of information provided has been out of this world. Thank you!
Okta writes "We are deeply committed to transparency" but shows none in their blogpost in contrast to CloudFlare, that doesn't write anything about transparency but displays a lot of it.
A bit like queuing for your internet providers customer support for 3 hour and hearing "We care about customer satisfaction" every five minutes.
Re: Updated Okta Statement on Lapsus$
#26> Support engineers do have access to limited data - for example, Jira tickets and lists of users - that were seen in the screenshots. Support engineers are also able to facilitate the resetting of passwords and MFA factors for users, but are unable to obtain those passwords. This means they could have reset anybody’s credentials and logged in. There would a record of it if the audit logs are valid, but saying no act…
> This means they could have reset anybody’s credentials and logged in Does it? It specifically says "but are unable to obtain those passwords," which reads to me like they are able to trigger a password reset email to the user, but are not actually able to set the password themselves.
Re: Updated Okta Statement on Lapsus$
#27There were a lot of doomsday predictions in yesterday's thread before any real info had been shared, but it was always the more likely scenario that a support agent contracted through a vendor would have limited read access to their internal systems and wouldn't be able to cause any real damage.
Re: Updated Okta Statement on Lapsus$
#28> Support engineers are also able to facilitate the resetting of passwords and MFA factors for users, but are unable to obtain those passwords. Very ambiguous statement, not really fitting in with the whole "deeply committed to transparency" image they are trying to emit. What does "facilitate" really refer to here? If it was just triggering it, they would have said so, presumably. And why is only passwords mentioned…
Re: Updated Okta Statement on Lapsus$
#29I don't understand how they can say "unsuccessful attempt to compromise the account of a customer support engineer" . then can say "Following the completion of the service provider’s investigation, we received a report from the forensics firm this week. The report highlighted that there was a five-day window of time between January 16-21, 2022, where an attacker had access to a support engineer’s laptop. This is cons…
If somebody uses my laptop, my Gmail account is not compromised; I'm being dolphined. Of course 5 days is quite a long time, but this is just to clarify what you didn't understand.
If I steal your secure token and log into you through a cloned browser session and access your gmail have I compromised your gmail? It feels like it.
Maybe it is just a distinction without a difference.
Re: Updated Okta Statement on Lapsus$
#30Lots more detail: https://blog.cloudflare.com/cloudflare-investigation-of-the-...
I'd love to see more of this in the industry. CF is, IMO, industry leading here.