Lapsus has responded https://img.guildedcdn.com/ContentMedia/e4149dc99f447074cb2c...
they edited and added more content https://img.guildedcdn.com/ContentMedia/372280f522049aa0b0eb...
Updated Okta Statement on Lapsus$
51–60 of 239 posts
Re: Updated Okta Statement on Lapsus$
#52Lots more detail: https://blog.cloudflare.com/cloudflare-investigation-of-the-...
How is that lots more details ? Your post is only about whether or not CF Okta account has been compromised not about what really happened for all Okta customers
Re: Updated Okta Statement on Lapsus$
#53Earlier quoted context omitted.
they edited and added more content https://img.guildedcdn.com/ContentMedia/372280f522049aa0b0eb...
To note in some of the earlier screenshots you can see they have the EC2 Instances menu open in their tabs - that's a bit concerning, why does a support engineer need AWS EC2 access?
Re: Updated Okta Statement on Lapsus$
#54Earlier quoted context omitted.
they edited and added more content https://img.guildedcdn.com/ContentMedia/372280f522049aa0b0eb...
To note in some of the earlier screenshots you can see they have the EC2 Instances menu open in their tabs - that's a bit concerning, why does a support engineer need AWS EC2 access?
Re: Updated Okta Statement on Lapsus$
#55Earlier quoted context omitted.
they edited and added more content https://img.guildedcdn.com/ContentMedia/372280f522049aa0b0eb...
To note in some of the earlier screenshots you can see they have the EC2 Instances menu open in their tabs - that's a bit concerning, why does a support engineer need AWS EC2 access?
Re: Updated Okta Statement on Lapsus$
#56Earlier quoted context omitted.
In what way would a Okta user be unable to trigger the reset while a support engineer could? If they are unable to access the Okta website where the password reset gets initiated, they are also unable to access the very same Okta website where the new password would be set. And why use the more general word of "facilitate" when they could have been specific and say "trigger reset password flow" or similar. Hence thei…
User's laptop is lost / stolen. User notifies supervisor. Supervisor (with admin authority on the account) notifies okta support and asks that the password be reset.
Re: Updated Okta Statement on Lapsus$
#57Oh okay then, pack up guys, everything’s fine
I really hate this kind of corporate bullshit
> There are no corrective actions that need to be taken by our customers.
Isn’t this an objectively false statement?
Re: Updated Okta Statement on Lapsus$
#58It feels like a lawyer heavily tweaked this to sound better than it really is.
Source: https://www.google.com/search?q=okta+stock
Re: Updated Okta Statement on Lapsus$
#59despite an overwhelming preponderance of damning evidence from twitter (as well as the hacker themselves) you've somehow managed to find yourselves secure instead?
Christs whiskers thats some impressive doublethink. Its also an excellent opportunity to fall on a sword that gives future attackers --hat colour dismissed-- an immediate incentive to simply publish regardless as you dont appear to be acting with very much good faith. if this sort of an attack is a carrot, you've clearly shown a predilection for the stick.
Re: Updated Okta Statement on Lapsus$
#60> Support engineers do have access to limited data - for example, Jira tickets and lists of users - that were seen in the screenshots. Support engineers are also able to facilitate the resetting of passwords and MFA factors for users, but are unable to obtain those passwords. This means they could have reset anybody’s credentials and logged in. There would a record of it if the audit logs are valid, but saying no act…
It's been a minute since I was an admin in an Okta directory, but don't all resets use a self-service flow? In order to log in to someone's account, I think you need to compromise their email, too.