Earlier quoted context omitted.
They sound like they're running the organisation like a dating site. More reasons to look elsewhere.
Or like Adobe: https://news.ycombinator.com/item?id=30222165
Updated Okta Statement on Lapsus$
211–220 of 239 posts
Re: Updated Okta Statement on Lapsus$
#212The post could use some review/edit. This: "a customer support engineer working for a third-party provider" actually means "one of our customer support engineers, who happens to be an employee of another company, working for us under contract".
Don't believe for a moment that this misdirection is unintentional. It's one big reason you might have contract workers instead of employees in this role, actually.
> Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor’s obligations.
GDPR Art 28(4): https://gdpr-info.eu/art-28-gdpr/
Re: Updated Okta Statement on Lapsus$
#213Earlier quoted context omitted.
If somebody uses my laptop, my Gmail account is not compromised; I'm being dolphined. Of course 5 days is quite a long time, but this is just to clarify what you didn't understand.
"had access to a support engineer’s laptop" is very vague, they could have: 1. some kind of remote access to the support engineer's session on that laptop 2. physical access, no login 3. physical access as a different user 4. physical access, logged in as the support engineer If I have access to your laptop, logged in as you, and you have Gmail open in a browser, then your Gmail account should be considered compromis…
Re: Updated Okta Statement on Lapsus$
#214Re: Updated Okta Statement on Lapsus$
#215Re: Updated Okta Statement on Lapsus$
#216Earlier quoted context omitted.
they edited and added more content https://img.guildedcdn.com/ContentMedia/372280f522049aa0b0eb...
A more poignant elegy to the modern landscape of compliance theater I have never seen: > Security Standards. Okta's ISMP includes adherance to and regular testing of the key controls, systems and procedures of its ISMP to validate that they are properly implemented and effective in addressing the threats and risks identified. Such testing includes: > a) Internal risk assessments; > b) ISO 27001, 27002, 27017 and 2701…
The decision makers have absolutely no idea how any of this stuff works.
Re: Updated Okta Statement on Lapsus$
#217Earlier quoted context omitted.
The LAPSUS$ post suggests that they queried the AWS keys out of Slack. So the support engineers just have access to Slack, and Okta engineers were dumb enough to put those keys in Slack.
I'm incredulous an auth focused company would do this without someone freaking out? Even my much smaller SaaS companies would react quickly to stop and rotate these if this happened.
Re: Updated Okta Statement on Lapsus$
#218Earlier quoted context omitted.
We’ve been monitoring this internally, as customers of an Okta-like service. I’ve also been closely monitoring the responses from our CTO and VP of Security when someone from our DevOps team posted a link to the Verge article in slack this morning. Which brings me to this inquiry: How are your orgs responding to this? We have a dependency on an Okta-like provider and my first thought when reading this news was “you k…
I moved over to Azure AD this morning (we only have a few devs and were already using Azure DevOps so this was doable). I requested that Okta cancel our account and let them know the reason was the potential data breach and their CEO's response on Twitter. Okta's response was that we signed an MSA agreement and that cancelling isn't an option, nor termination of fees.
Interesting. Does this agreement also works the other way as well (Okta can't just decides to terminate your account no matter the reason)?
Re: Updated Okta Statement on Lapsus$
#219Earlier quoted context omitted.
If somebody uses my laptop, my Gmail account is not compromised; I'm being dolphined. Of course 5 days is quite a long time, but this is just to clarify what you didn't understand.
what does dolphined mean. is this a cyber security term?
Re: Updated Okta Statement on Lapsus$
#220Earlier quoted context omitted.
Channel sprawl is very normal. While my day job has a broad scope in the org, I’m a “member” of over 900 MS Teams. I’d guess that 3% are active and i interact with 0.
900 teams? That's a lot, are you sure you don't mean 900 channels (or whatever Teams calls them) instead?
Much like the OP here I'm in hundreds of teams, and almost all of them do all their talking in #general and they wonder why people never respond to notifications.
The Teams UX and general paradigm is awful. Right now I'm in 3 group chats and two channels (in two Teams) discussing the Okta incident. Huge overlap of them, but not 100% so some people aren't getting all the information.