Live data from Hacker News

Updated Okta Statement on Lapsus$

okta.com

221–230 of 239 posts

Re: Updated Okta Statement on Lapsus$

#221
post #10
post #4

> Support engineers do have access to limited data - for example, Jira tickets and lists of users - that were seen in the screenshots. Support engineers are also able to facilitate the resetting of passwords and MFA factors for users, but are unable to obtain those passwords. This means they could have reset anybody’s credentials and logged in. There would a record of it if the audit logs are valid, but saying no act…

> This means they could have reset anybody’s credentials and logged in Does it? It specifically says "but are unable to obtain those passwords," which reads to me like they are able to trigger a password reset email to the user, but are not actually able to set the password themselves.

If OKTA gates email like at most organizations, reset email doesn't work. It has to be the ability to set a temp password.

Re: Updated Okta Statement on Lapsus$

#222

> Okta service has not been breached and remains fully operational > highlighted that there was a five-day window of time between January 16-21, 2022, where an attacker had access to a support engineer’s laptop These are some impressive mental gymnastics!

You didn't see graphite. Identity providers cannot be compromised!

Only a support engineer was compromised. Not great, not terrible.

Re: Updated Okta Statement on Lapsus$

#224
post #86

Earlier quoted context omitted.

The LAPSUS$ post suggests that they queried the AWS keys out of Slack. So the support engineers just have access to Slack, and Okta engineers were dumb enough to put those keys in Slack.

I'm incredulous an auth focused company would do this without someone freaking out? Even my much smaller SaaS companies would react quickly to stop and rotate these if this happened.

DPL scanners in Slack, anyone? Figured Okta would definitely have those.

We get alerts when folks are sharing tutorial code with fake keys like DEADBEEF in them. It's nice to know DPL works, if you use it.

Re: Updated Okta Statement on Lapsus$

#225

Earlier quoted context omitted.

Okta is the Oracle of identity management. https://auth0.com is the "still cares about customers" vendor I'm not affiliated with them, just traumatized by working in IT

Auth0 was acquired by Okta ( https://auth0.com/blog/okta-acquisition-announcement/ ), although Okta claims in the post that > There is no impact to Auth0 customers, and there is no impact to HIPAA and FedRAMP customers.

Auth0 is run as an isolated subsidiary in its own infrastructure, with the old CEO still overseeing operations. Due to the massive difference in Okta & Auth0's implementations I don't see that changing anytime soon.

Re: Updated Okta Statement on Lapsus$

#227

Earlier quoted context omitted.

Support tickets, or incidents, or escalations might require creating a new slack channel

It's not a bad idea to create channels for incidents. Ever tried to keep an incident timeline in a Jira ticket? It's absolutely horrendous. We used to automatically create a slack channel whenever a Jira incident ticket was created, and post it into the engineering channel with a message like "SEV1 incident, please join channel #INCIDENT-21". Slack is real nice for posting graphs, links, screenshots, going off on dif…

Ever tried to keep an incident timeline in a Jira ticket?

Once.

Thanks for bringing back the nightmares, friend.

Re: Updated Okta Statement on Lapsus$

#228
post #19
post #8

I don't understand how they can say "unsuccessful attempt to compromise the account of a customer support engineer" . then can say "Following the completion of the service provider’s investigation, we received a report from the forensics firm this week. The report highlighted that there was a five-day window of time between January 16-21, 2022, where an attacker had access to a support engineer’s laptop. This is cons…

I have a bunch of screenshots in my laptop that I take for reasons like attaching to tickets and sharing on Slack. Some are very sensitive if shared outside the company. If the attacker had physical access to the laptop, that explains.

> If the attacker had physical access to the laptop, that explains.

No full disk encryption or alike? Physical access should not be enough to access sensitive data, unless you have data unencrypted.

Re: Updated Okta Statement on Lapsus$

#229

Earlier quoted context omitted.

they edited and added more content https://img.guildedcdn.com/ContentMedia/372280f522049aa0b0eb...

8600 channels? Wouldn't that overwhelm you? I'm trying to think up scenarios where an org would need so many, but I can't. Is this normal?

They have access to that many channels. There's likely many that are public (including history), but the user is not a member.

Re: Updated Okta Statement on Lapsus$

#230

Earlier quoted context omitted.

900 teams? That's a lot, are you sure you don't mean 900 channels (or whatever Teams calls them) instead?

A lot of people want to have full control so rather than create a channel called "Project Phoenix" in a team called "Operations" they'll create a whole new team, and use the general channel. Much like the OP here I'm in hundreds of teams, and almost all of them do all their talking in #general and they wonder why people never respond to notifications. The Teams UX and general paradigm is awful. Right now I'm in 3 gro…

I forgot to mention that the teams interface is truly awful. I do what I should be doing in a “Team” in one of a half dozen pinned group adhoc chats.

The context switch between a mostly useless teams tab and a needlessly full screen IM window is too heavy for me.

Post reply on HN