Live data from Hacker News

Updated Okta Statement on Lapsus$

okta.com

51–60 of 239 posts

Re: Updated Okta Statement on Lapsus$

#51

Lapsus has responded https://img.guildedcdn.com/ContentMedia/e4149dc99f447074cb2c...

they edited and added more content https://img.guildedcdn.com/ContentMedia/372280f522049aa0b0eb...

To note in some of the earlier screenshots you can see they have the EC2 Instances menu open in their tabs - that's a bit concerning, why does a support engineer need AWS EC2 access?

Re: Updated Okta Statement on Lapsus$

#52
post #42
post #2

Lots more detail: https://blog.cloudflare.com/cloudflare-investigation-of-the-...

How is that lots more details ? Your post is only about whether or not CF Okta account has been compromised not about what really happened for all Okta customers

it has more detail on the breach then okta's own statement.

Re: Updated Okta Statement on Lapsus$

#53

Earlier quoted context omitted.

they edited and added more content https://img.guildedcdn.com/ContentMedia/372280f522049aa0b0eb...

To note in some of the earlier screenshots you can see they have the EC2 Instances menu open in their tabs - that's a bit concerning, why does a support engineer need AWS EC2 access?

The LAPSUS$ post suggests that they queried the AWS keys out of Slack. So the support engineers just have access to Slack, and Okta engineers were dumb enough to put those keys in Slack.

Re: Updated Okta Statement on Lapsus$

#54

Earlier quoted context omitted.

they edited and added more content https://img.guildedcdn.com/ContentMedia/372280f522049aa0b0eb...

To note in some of the earlier screenshots you can see they have the EC2 Instances menu open in their tabs - that's a bit concerning, why does a support engineer need AWS EC2 access?

[deleted]

Re: Updated Okta Statement on Lapsus$

#55

Earlier quoted context omitted.

they edited and added more content https://img.guildedcdn.com/ContentMedia/372280f522049aa0b0eb...

To note in some of the earlier screenshots you can see they have the EC2 Instances menu open in their tabs - that's a bit concerning, why does a support engineer need AWS EC2 access?

Can you open the web console with just an access key? My impression was you could only use that to act through a CLI tool, at least officially you need to have powers or act as a user with powers to use the web console directly?

Re: Updated Okta Statement on Lapsus$

#56

Earlier quoted context omitted.

In what way would a Okta user be unable to trigger the reset while a support engineer could? If they are unable to access the Okta website where the password reset gets initiated, they are also unable to access the very same Okta website where the new password would be set. And why use the more general word of "facilitate" when they could have been specific and say "trigger reset password flow" or similar. Hence thei…

User's laptop is lost / stolen. User notifies supervisor. Supervisor (with admin authority on the account) notifies okta support and asks that the password be reset.

[deleted]

Re: Updated Okta Statement on Lapsus$

#57
> The Okta service has not been breached and remains fully operational

Oh okay then, pack up guys, everything’s fine

I really hate this kind of corporate bullshit

> There are no corrective actions that need to be taken by our customers.

Isn’t this an objectively false statement?

Re: Updated Okta Statement on Lapsus$

#58

It feels like a lawyer heavily tweaked this to sound better than it really is.

Source: https://www.google.com/search?q=okta+stock

Besides the opening it doesn't appear to have moved very much. I wonder if LAPSUS$ have short positions open and are frustrated it's not moving which is why they're posting responses to Okta and then updated their response with more information (as linked above).

Re: Updated Okta Statement on Lapsus$

#59
>The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers.

despite an overwhelming preponderance of damning evidence from twitter (as well as the hacker themselves) you've somehow managed to find yourselves secure instead?

Christs whiskers thats some impressive doublethink. Its also an excellent opportunity to fall on a sword that gives future attackers --hat colour dismissed-- an immediate incentive to simply publish regardless as you dont appear to be acting with very much good faith. if this sort of an attack is a carrot, you've clearly shown a predilection for the stick.

Re: Updated Okta Statement on Lapsus$

#60
post #16
post #4

> Support engineers do have access to limited data - for example, Jira tickets and lists of users - that were seen in the screenshots. Support engineers are also able to facilitate the resetting of passwords and MFA factors for users, but are unable to obtain those passwords. This means they could have reset anybody’s credentials and logged in. There would a record of it if the audit logs are valid, but saying no act…

It's been a minute since I was an admin in an Okta directory, but don't all resets use a self-service flow? In order to log in to someone's account, I think you need to compromise their email, too.

They do indeed use a self-service flow.
Post reply on HN