Bold to assume I love Okta.
Okta Personal
21–30 of 53 posts
Re: Okta Personal
#22Perfect. Can't wait to bring it our next family CAB meeting. Ever since going enterprise my families profits are through the roof. ITIL literally has saved my personal relationships and finances. I realized both of my children were net loss figures for the next 18 years so we dropped them off at the fire station and our P&L numbers have never been better. Also turns out being PiMP certified has brought in tons of mon…
What about the front yard basketball hoop. You should be renting that from a local startup, not capitalising all that plastic.
Re: Okta Personal
#23I didn’t set it up yet, so can’t tell. Is this just a personal version of their janky “sso” where they store passwords and their chrome add-in pastes it into the login prompt? IE, not actual Okta-proper that’s IDP doing SAML or OIDC auth?
Re: Okta Personal
#24This is a hard no for me. Not even entirely that they were hacked multiple times, but how they dealt with it each time. https://www.theverge.com/2022/4/20/23034360/okta-lapsus-hack... https://techcrunch.com/2022/12/22/okta-breach-source-code-gi... https://www.malwarebytes.com/blog/news/2023/01/okta-breached...
Re: Okta Personal
#25as suspicious as the domain may look, it does link out to personal.okta.com for account creation. the privacy policy is also a link to okta.com. despite the chatgpt reference, it appears to be a legitimate marketing domain for okta.
Naming conventions like this really trigger my phishy senses.
Re: Okta Personal
#26Re: Okta Personal
#27This is a hard no for me. Not even entirely that they were hacked multiple times, but how they dealt with it each time. https://www.theverge.com/2022/4/20/23034360/okta-lapsus-hack... https://techcrunch.com/2022/12/22/okta-breach-source-code-gi... https://www.malwarebytes.com/blog/news/2023/01/okta-breached...
1. In the first hack, if anything Okta over communicated about the hack: the hack ended up being much less severe than they originally said was possible, and, from a security perspective, the hack didn't really have any negative consequences to customers.
2. Your second 2 links are about the same issue, which was a breach of their GitHub accounts. Again, it's worrisome that someone could find vulnerabilities in their source code, but no customer data was compromised.
You're free to think what you want about the severity of these hacks (I personally think they're low), but I don't see how you could have problems with "how they dealt with it each time". They seemed to have textbook correct incident response communications - what else would you suggest they had done?
Also, given the nature of the breaches, I don't think they point to severe security culture problems at the company (in contrast, for example, to the LastPass and Solarwinds breaches, which showed all the signs of clown show security culture IMO).
Re: Okta Personal
#28This is interesting to me in only one respect. The fact that they think the personal market is lucrative enough to break into while already being successful in the enterprise makes me sad that 1Password couldn’t be content with the personal market and instead decided it was enterprise or bust, much to the chagrin of many of their personal client base.
I believe that 1Password has grown significantly in the professional space, and that Okta likely sees this trend as a competitive threat.
If there's anything that Apple's upending of Blackberry taught us, it's that all you need is a one key decision maker in an entire organization to say "wait, why can't I use {product x}?" for that organization to slowly move away from the entrenched enterprise solution. The fact that Okta is joining the consumer space validates 1Password's decision to creep into the enterprise market.
Re: Okta Personal
#29I don't think I love anything from work, much the same way most McDonalds fry cooks probably aren't particularly smitten with the spatula at their restaurant's grill. But of all the things I regularly interact with at work, Okta is probably the thing I love the least since it signs me out 8+ times a day and bounces me through an unholy amount of redirections every time I click on a "chiclet" all in the name of "security".
If I was still having to track my time, I would genuinely have to log a ticket each day for dealing with Okta with the amount of time it sucks up.
Re: Okta Personal
#30As a security and privacy pro, my own social login footprint is too small to use it, but making products for security people is useless anyway. Someone had to solve this, and a secure portal for app logins also owns the channel. The main risk is that vendors will see their flows being interdicted and sabotage the app, that's how good this is, imo.