Live data from Hacker News

Okta Personal

oktapersonal.com

21–30 of 53 posts

Re: Okta Personal

#21
post #3

Bold to assume I love Okta.

I mean, it's certainly strange to "love" an IDP. Though I will say, going from a more corporate controlled Azure AD + ping + on prem legacy crap, working somewhere that gets everything funneling through okta has been SO much better

Re: Okta Personal

#22

Perfect. Can't wait to bring it our next family CAB meeting. Ever since going enterprise my families profits are through the roof. ITIL literally has saved my personal relationships and finances. I realized both of my children were net loss figures for the next 18 years so we dropped them off at the fire station and our P&L numbers have never been better. Also turns out being PiMP certified has brought in tons of mon…

I would be looking for round 2 investors in your AI synthesised book "how to sell your kids pre- IPO" and also discussing ISO27001 certification on those dance poles. Are they conformant? Are they made onshore or are you ignoring supply chain risk here?

What about the front yard basketball hoop. You should be renting that from a local startup, not capitalising all that plastic.

Re: Okta Personal

#23
post #12

I didn’t set it up yet, so can’t tell. Is this just a personal version of their janky “sso” where they store passwords and their chrome add-in pastes it into the login prompt? IE, not actual Okta-proper that’s IDP doing SAML or OIDC auth?

I can't think of a single application I use that supports SAML for non-business/enterprise accounts.

Re: Okta Personal

#24
post #4

This is a hard no for me. Not even entirely that they were hacked multiple times, but how they dealt with it each time. https://www.theverge.com/2022/4/20/23034360/okta-lapsus-hack... https://techcrunch.com/2022/12/22/okta-breach-source-code-gi... https://www.malwarebytes.com/blog/news/2023/01/okta-breached...

Absolutely this, plus the fact that this smells like a pet project that'll get shut down next time there's a reshuffle. Keep it.

Re: Okta Personal

#25

as suspicious as the domain may look, it does link out to personal.okta.com for account creation. the privacy policy is also a link to okta.com. despite the chatgpt reference, it appears to be a legitimate marketing domain for okta.

Why even have oktapersonal.com? personal.okta.com is almost the same number of characters - just an extra period. Is it purely for SEO purposes? Is it because a company can be named “personal”, and so personal.okta.com would be taken by an enterprise customer?

Naming conventions like this really trigger my phishy senses.

Re: Okta Personal

#26
I want all my apps in one place, right where they are, on my desktop computer. I don't have an i9 with 64gb of ram, 2 2gb ssds, and a 16gb graphics card so I can cloud compute.

Re: Okta Personal

#27
post #4

This is a hard no for me. Not even entirely that they were hacked multiple times, but how they dealt with it each time. https://www.theverge.com/2022/4/20/23034360/okta-lapsus-hack... https://techcrunch.com/2022/12/22/okta-breach-source-code-gi... https://www.malwarebytes.com/blog/news/2023/01/okta-breached...

I don't understand your position:

1. In the first hack, if anything Okta over communicated about the hack: the hack ended up being much less severe than they originally said was possible, and, from a security perspective, the hack didn't really have any negative consequences to customers.

2. Your second 2 links are about the same issue, which was a breach of their GitHub accounts. Again, it's worrisome that someone could find vulnerabilities in their source code, but no customer data was compromised.

You're free to think what you want about the severity of these hacks (I personally think they're low), but I don't see how you could have problems with "how they dealt with it each time". They seemed to have textbook correct incident response communications - what else would you suggest they had done?

Also, given the nature of the breaches, I don't think they point to severe security culture problems at the company (in contrast, for example, to the LastPass and Solarwinds breaches, which showed all the signs of clown show security culture IMO).

Re: Okta Personal

#28

This is interesting to me in only one respect. The fact that they think the personal market is lucrative enough to break into while already being successful in the enterprise makes me sad that 1Password couldn’t be content with the personal market and instead decided it was enterprise or bust, much to the chagrin of many of their personal client base.

My interpretation is actually the opposite.

I believe that 1Password has grown significantly in the professional space, and that Okta likely sees this trend as a competitive threat.

If there's anything that Apple's upending of Blackberry taught us, it's that all you need is a one key decision maker in an entire organization to say "wait, why can't I use {product x}?" for that organization to slowly move away from the entrenched enterprise solution. The fact that Okta is joining the consumer space validates 1Password's decision to creep into the enterprise market.

Re: Okta Personal

#29
> The Okta you know and love for work...

I don't think I love anything from work, much the same way most McDonalds fry cooks probably aren't particularly smitten with the spatula at their restaurant's grill. But of all the things I regularly interact with at work, Okta is probably the thing I love the least since it signs me out 8+ times a day and bounces me through an unholy amount of redirections every time I click on a "chiclet" all in the name of "security".

If I was still having to track my time, I would genuinely have to log a ticket each day for dealing with Okta with the amount of time it sucks up.

Re: Okta Personal

#30
I love the idea, and will recommend it to people.

As a security and privacy pro, my own social login footprint is too small to use it, but making products for security people is useless anyway. Someone had to solve this, and a secure portal for app logins also owns the channel. The main risk is that vendors will see their flows being interdicted and sabotage the app, that's how good this is, imo.

Post reply on HN