>The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers. despite an overwhelming preponderance of damning evidence from twitter (as well as the hacker themselves) you've somehow managed to find yourselves secure instead? Christs whiskers thats some impressive doublethink. Its also an excellent opportunity to fall on a sword that giv…
Updated Okta Statement on Lapsus$
81–90 of 239 posts
Re: Updated Okta Statement on Lapsus$
#82>The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers. despite an overwhelming preponderance of damning evidence from twitter (as well as the hacker themselves) you've somehow managed to find yourselves secure instead? Christs whiskers thats some impressive doublethink. Its also an excellent opportunity to fall on a sword that giv…
I'd have far more faith in them if they were transparent about what had happened, what they're doing about it, and how they will make sure it can't happen again.
Instead, they are being weasels - I for one, will not be using their services again, and this behaviour is the reason why.
Here's another example from a couple of years back where they used some really weasely language to claim they weren't vulnerable to a CVE (spoiler: they were):
https://twitter.com/jonoberheide/status/1506280347306188805?...
Re: Updated Okta Statement on Lapsus$
#83>The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers. despite an overwhelming preponderance of damning evidence from twitter (as well as the hacker themselves) you've somehow managed to find yourselves secure instead? Christs whiskers thats some impressive doublethink. Its also an excellent opportunity to fall on a sword that giv…
Workers at organizations get compromised all the time. This doesn’t mean their systems/products are compromised.
Re: Updated Okta Statement on Lapsus$
#84Earlier quoted context omitted.
they edited and added more content https://img.guildedcdn.com/ContentMedia/372280f522049aa0b0eb...
8600 channels? Wouldn't that overwhelm you? I'm trying to think up scenarios where an org would need so many, but I can't. Is this normal?
Re: Updated Okta Statement on Lapsus$
#85Lots more detail: https://blog.cloudflare.com/cloudflare-investigation-of-the-...
How is that lots more details ? Your post is only about whether or not CF Okta account has been compromised not about what really happened for all Okta customers
Eg.
> Cloudflare reads the system Okta logs every five minutes and stores these in our SIEM so that if we were to experience an incident such as this one, we can look back further than the 90 days provided in the Okta dashboard. Some event types within Okta that we searched for are: user.account.reset_password, user.mfa.factor.update, system.mfa.factor.deactivate, user.mfa.attempt_bypass, and user.session.impersonation.initiate. It’s unclear from communications we’ve received from Okta so far who we would expect the System Log Actor to be from the compromise of an Okta support employee.
Re: Updated Okta Statement on Lapsus$
#86Earlier quoted context omitted.
To note in some of the earlier screenshots you can see they have the EC2 Instances menu open in their tabs - that's a bit concerning, why does a support engineer need AWS EC2 access?
The LAPSUS$ post suggests that they queried the AWS keys out of Slack. So the support engineers just have access to Slack, and Okta engineers were dumb enough to put those keys in Slack.
Re: Updated Okta Statement on Lapsus$
#87Re: Updated Okta Statement on Lapsus$
#88Re: Updated Okta Statement on Lapsus$
#89Lapsus has responded https://img.guildedcdn.com/ContentMedia/e4149dc99f447074cb2c...