New Updated Okta Statement on Lapsus$
21–30 of 38 posts
Re: New Updated Okta Statement on Lapsus$
#22Re: New Updated Okta Statement on Lapsus$
#23Re: New Updated Okta Statement on Lapsus$
#24I can't believe these idiots tried playing chicken with a hacker, heads need to roll over this one. They have completely and needlessly destroyed their credibility by trying and completely failing to control the narrative.
The comedy of this is that one would expect an authentication and identity platform to be in the top percent of good actors in security incident response. Might be time to reinstall Active Directory in your basement.
Re: New Updated Okta Statement on Lapsus$
#25Re: New Updated Okta Statement on Lapsus$
#26Updated Okta Statement on Lapsus$ - https://news.ycombinator.com/item?id=30769537 - March 2022 (220 comments)
Also:
DEV-0537 (LAPSUS$) Criminal actor targeting organizations - https://news.ycombinator.com/item?id=30774406 - March 2022 (0 comments)
Lapsus$ hackers leak 37GB of Microsoft's alleged source code - https://news.ycombinator.com/item?id=30763623 - March 2022 (117 comments)
Re: New Updated Okta Statement on Lapsus$
#27'''
https://www.okta.com/blog/2022/03/updated-okta-statement-on-...
I do enjoy the lies given by Okta.
1. We didn't compromise any laptop? It was a thin client.
2. "Okta detected an unsuccessful attempt to compromise the account of a customer support engineer working for a third-party provider." - I'm STILL unsure how its a unsuccessful attempt? Logged in to superuser portal with the ability to reset the Password and MFA of ~95% of clients isn't successful?
4. For a company that supports Zero-Trust. Support Engineers seem to have excessive access to Slack? 8.6k channels? (You may want to search AKIA* on your Slack, rather a bad security practice to store AWS keys in Slack channels )
5. Support engineers are also able to facilitate the resetting of passwords and MFA factors for users, but are unable to obtain those passwords. - Uhm? I hope no-one can read passwords? not just support engineers, LOL. - are you implying passwords are stored in plaintext?
6. You claim a laptop was compromised? In that case what suspicious IP addresses do you have available to report?
7. The potential impact to Okta customers is NOT limited, I'm pretty certain resetting passwords and MFA would result in complete compromise of many clients systems.
8. If you are committed to transparency how about you hire a firm such as Mandiant and PUBLISH their report? I'm sure it would be very different to your report :)
_________________________________________________________________________________________________________________________________________________________________________________________________________ https://www.okta.com/sites/default/files/2021-12/okta-securi...
21. Security Breach Management. a) Notification: In the event of a Security Breach, Okta notifies impacted customers of such Security Breach. Okta cooperates with an impacted customer’s reasonable request for information regarding such Security Breach, and Okta provides regular updates on any such Security Breach and the investigative action and corrective action(s) taken. -
But customers only found out today? Why wait this long?
9. Access Controls. Okta has in place policies, procedures, and logical controls that are designed:
b. Controls to ensure that all Okta personnel who are granted access to any Customer Data are based on leastprivilege principles;
kkkkkkkkkkkkkkk
1. Security Standards. Okta’s ISMP includes adherence to and regular testing of the key controls, systems and procedures of its ISMP to validate that they are properly implemented and effective in addressing the threats and risks identified. Such testing includes: a) Internal risk assessments; b) ISO 27001, 27002, 27017 and 27018 certifications; c) NIST guidance; and d) SOC2 Type II (or successor standard) audits annually performed by accredited third-party auditors (“Audit Report”).
I don't think storing AWS keys within Slack would comply to any of these standards?
'''
Re: New Updated Okta Statement on Lapsus$
#28The claims that they had AWS keys in Slack are a little unsettling.
Re: New Updated Okta Statement on Lapsus$
#29Earlier quoted context omitted.
The comedy of this is that one would expect an authentication and identity platform to be in the top percent of good actors in security incident response. Might be time to reinstall Active Directory in your basement.
AD controllers are a pain to maintain in the future though. At a BigCo I was SRE at, there were some running on ancient versions of Windows. The funny thing to me is, nobody was quite certain what exactly it gave access to. The support team would need to reset passwords for users on a weekly basis though. It was a huge mess.
I suspect that if your title was SRE, and they still had some on-prem AD controllers, they were probably not maintained as well as a place who still calls their IT folks SysAdmins, if the titles are any hint on the general focus of tech stacks.
Re: New Updated Okta Statement on Lapsus$
#30I think the flip flopping is hurting them and their users more and more. What was initially a flat denial this morning has resulted in taunts from Lapsus$ on Twitter, Okta was out-scooped by Cloudflare's public investigation. Now they admit a breach affecting 2.5% (roughly 250 orgs based on public data). The webinar tomorrow should be fascinating if they allow questions.
“A contractor’s laptop was owned for 5 days who had super user access, but we didn’t get breached” was a strange conclusion in their original state.