> Support engineers do have access to limited data - for example, Jira tickets and lists of users - that were seen in the screenshots. Support engineers are also able to facilitate the resetting of passwords and MFA factors for users, but are unable to obtain those passwords. This means they could have reset anybody’s credentials and logged in. There would a record of it if the audit logs are valid, but saying no act…
> This means they could have reset anybody’s credentials and logged in Does it? It specifically says "but are unable to obtain those passwords," which reads to me like they are able to trigger a password reset email to the user, but are not actually able to set the password themselves.
Updated Okta Statement on Lapsus$
221–230 of 239 posts
Re: Updated Okta Statement on Lapsus$
#222> Okta service has not been breached and remains fully operational > highlighted that there was a five-day window of time between January 16-21, 2022, where an attacker had access to a support engineer’s laptop These are some impressive mental gymnastics!
You didn't see graphite. Identity providers cannot be compromised!
Re: Updated Okta Statement on Lapsus$
#223Re: Updated Okta Statement on Lapsus$
#224Earlier quoted context omitted.
The LAPSUS$ post suggests that they queried the AWS keys out of Slack. So the support engineers just have access to Slack, and Okta engineers were dumb enough to put those keys in Slack.
I'm incredulous an auth focused company would do this without someone freaking out? Even my much smaller SaaS companies would react quickly to stop and rotate these if this happened.
We get alerts when folks are sharing tutorial code with fake keys like DEADBEEF in them. It's nice to know DPL works, if you use it.
Re: Updated Okta Statement on Lapsus$
#225Earlier quoted context omitted.
Okta is the Oracle of identity management. https://auth0.com is the "still cares about customers" vendor I'm not affiliated with them, just traumatized by working in IT
Auth0 was acquired by Okta ( https://auth0.com/blog/okta-acquisition-announcement/ ), although Okta claims in the post that > There is no impact to Auth0 customers, and there is no impact to HIPAA and FedRAMP customers.
Re: Updated Okta Statement on Lapsus$
#226Re: Updated Okta Statement on Lapsus$
#227Earlier quoted context omitted.
Support tickets, or incidents, or escalations might require creating a new slack channel
It's not a bad idea to create channels for incidents. Ever tried to keep an incident timeline in a Jira ticket? It's absolutely horrendous. We used to automatically create a slack channel whenever a Jira incident ticket was created, and post it into the engineering channel with a message like "SEV1 incident, please join channel #INCIDENT-21". Slack is real nice for posting graphs, links, screenshots, going off on dif…
Once.
Thanks for bringing back the nightmares, friend.
Re: Updated Okta Statement on Lapsus$
#228I don't understand how they can say "unsuccessful attempt to compromise the account of a customer support engineer" . then can say "Following the completion of the service provider’s investigation, we received a report from the forensics firm this week. The report highlighted that there was a five-day window of time between January 16-21, 2022, where an attacker had access to a support engineer’s laptop. This is cons…
I have a bunch of screenshots in my laptop that I take for reasons like attaching to tickets and sharing on Slack. Some are very sensitive if shared outside the company. If the attacker had physical access to the laptop, that explains.
No full disk encryption or alike? Physical access should not be enough to access sensitive data, unless you have data unencrypted.
Re: Updated Okta Statement on Lapsus$
#229Earlier quoted context omitted.
they edited and added more content https://img.guildedcdn.com/ContentMedia/372280f522049aa0b0eb...
8600 channels? Wouldn't that overwhelm you? I'm trying to think up scenarios where an org would need so many, but I can't. Is this normal?
Re: Updated Okta Statement on Lapsus$
#230Earlier quoted context omitted.
900 teams? That's a lot, are you sure you don't mean 900 channels (or whatever Teams calls them) instead?
A lot of people want to have full control so rather than create a channel called "Project Phoenix" in a team called "Operations" they'll create a whole new team, and use the general channel. Much like the OP here I'm in hundreds of teams, and almost all of them do all their talking in #general and they wonder why people never respond to notifications. The Teams UX and general paradigm is awful. Right now I'm in 3 gro…
The context switch between a mostly useless teams tab and a needlessly full screen IM window is too heavy for me.