Live data from Hacker News

Updated Okta Statement on Lapsus$

okta.com

81–90 of 239 posts

Re: Updated Okta Statement on Lapsus$

#81
post #59

>The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers. despite an overwhelming preponderance of damning evidence from twitter (as well as the hacker themselves) you've somehow managed to find yourselves secure instead? Christs whiskers thats some impressive doublethink. Its also an excellent opportunity to fall on a sword that giv…

This is prime bad PR. This is going to be an absolute shit show.

Re: Updated Okta Statement on Lapsus$

#82
post #59

>The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers. despite an overwhelming preponderance of damning evidence from twitter (as well as the hacker themselves) you've somehow managed to find yourselves secure instead? Christs whiskers thats some impressive doublethink. Its also an excellent opportunity to fall on a sword that giv…

If there is one thing you want from a 3rd party auth provider, it's trust - this is not the time to play word games.

I'd have far more faith in them if they were transparent about what had happened, what they're doing about it, and how they will make sure it can't happen again.

Instead, they are being weasels - I for one, will not be using their services again, and this behaviour is the reason why.

Here's another example from a couple of years back where they used some really weasely language to claim they weren't vulnerable to a CVE (spoiler: they were):

https://twitter.com/jonoberheide/status/1506280347306188805?...

Re: Updated Okta Statement on Lapsus$

#83
post #59

>The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers. despite an overwhelming preponderance of damning evidence from twitter (as well as the hacker themselves) you've somehow managed to find yourselves secure instead? Christs whiskers thats some impressive doublethink. Its also an excellent opportunity to fall on a sword that giv…

Maybe I’m just an unimpressed security professional but I’ve still not seen evidence I’d call a breach. At least not a significant one if you want to argue sublantics.

Workers at organizations get compromised all the time. This doesn’t mean their systems/products are compromised.

Re: Updated Okta Statement on Lapsus$

#84

Earlier quoted context omitted.

they edited and added more content https://img.guildedcdn.com/ContentMedia/372280f522049aa0b0eb...

8600 channels? Wouldn't that overwhelm you? I'm trying to think up scenarios where an org would need so many, but I can't. Is this normal?

I suspect lots of small channels with only a few people in them. They have 5k employees, it adds up.

Re: Updated Okta Statement on Lapsus$

#85
post #42
post #2

Lots more detail: https://blog.cloudflare.com/cloudflare-investigation-of-the-...

How is that lots more details ? Your post is only about whether or not CF Okta account has been compromised not about what really happened for all Okta customers

They give more technical details than the Okta post and probably even the Okta customer contact.

Eg.

> Cloudflare reads the system Okta logs every five minutes and stores these in our SIEM so that if we were to experience an incident such as this one, we can look back further than the 90 days provided in the Okta dashboard. Some event types within Okta that we searched for are: user.account.reset_password, user.mfa.factor.update, system.mfa.factor.deactivate, user.mfa.attempt_bypass, and user.session.impersonation.initiate. It’s unclear from communications we’ve received from Okta so far who we would expect the System Log Actor to be from the compromise of an Okta support employee.

Re: Updated Okta Statement on Lapsus$

#86

Earlier quoted context omitted.

To note in some of the earlier screenshots you can see they have the EC2 Instances menu open in their tabs - that's a bit concerning, why does a support engineer need AWS EC2 access?

The LAPSUS$ post suggests that they queried the AWS keys out of Slack. So the support engineers just have access to Slack, and Okta engineers were dumb enough to put those keys in Slack.

I'm incredulous an auth focused company would do this without someone freaking out? Even my much smaller SaaS companies would react quickly to stop and rotate these if this happened.

Re: Updated Okta Statement on Lapsus$

#90
Looks like Lapsus didn't do any damage and thus Okta dismisses the breach as not a breach - just like a proof-of-breach starting notepad.exe on compromised machine was at one of my old jobs dismissed because notepad doesn't do any damage. The security professionals today are the second sellers of snake oil after MBAs. Cue SolarWind with their it is ok for binaries' signatures to differ as they get deformed while being forced through the internet pipes :) Lapsus not being a "state level actor" denied that easy get-out-of-jail-free card to Okta.
Post reply on HN