Live data from Hacker News

Okta hit by third-party breach, stealing employee data

arstechnica.com

81–90 of 93 posts

Re: Okta hit by third-party breach, stealing employee data

#81

Connecting a few dots why, while the headline seems misleading, it might matter. 1. Okta employee PII and foreign key to employee health info (a particularly sensitive class of PII) may be exposed. “On October 12, 2023, Rightway informed Okta that an unauthorized actor gained access to an eligibility census file maintained by Rightway in its provision of services ...” https://www.documentcloud.org/documents/24110001-…

Thanks for this. Posts like this are why I like Hacker News. This is a valid problem for Okta, and I think accurately frames the problem.

Real-talk, if you were calling the shots at Okta, what would you do here?

Enforce hardware-key MFA everywhere, for every vendor service? Impose a no-professional-social-media policy for all employees? This probably is too late to do any good, but it's pretty clear phishing is a hot vector right now.

Re: Okta hit by third-party breach, stealing employee data

#82

What a misleading and click-baity title choice by Ars Technica. This had nothing to do with Okta's platform, as implied. A third-party Vendor Okta used for health insurance information was breached, and personal information on Okta employees was stolen. I'm disappointed in Ars Technica, and Dan Goodin. edit: Updated to be more specific about what part of Okta this had nothing to do with.

Honestly Ars has really fallen in the past few years.

Re: Okta hit by third-party breach, stealing employee data

#83
post #63
post #59

Earlier quoted context omitted.

Another way of looking at it is that if a company doesn't truth you to answer truthfully, why are they choosing you as a vendor? Presumably you'd be lying about the thing they'd be buying too, or innumerable other things. And 'subsequent lawsuit' is usually a powerful motivator to be honest.

The next layer of cynicism down is more complicated. I'm going to make this up to protect the guiltocent, but I've been on the receiving end of security assessments that ask the moral equivalent of "Do you salt the MD5 hashes you use to store password hashes?" and we end saying Yes in some large number of words because we use bcrypt/scrypt properly, or some industry SSO, or our systems communicate with an internal CA…

Yeah. This is what always trips engineer-types up when dealing with legal. A contract isn’t code. There is usually, on both sides, a certain degree of BSing that goes on. Put another way, both parties are usually knowingly taking on risk associated with non-compliance. “We meet the security requirements in spirit only” is easily one of the more tame instances of this.

Re: Okta hit by third-party breach, stealing employee data

#84
post #44

Earlier quoted context omitted.

Okta (or any company) can't outsource its responsibility when it outsources to a supplier. If Okta printed all that personal data and left it in a box on the street they would be liable.

Ok, but that's not what the article says. It says Okta was breached. Okta was not breached.

It says Onta was hit by a breach, Okta was hit ny a breach, it even says that is was a third party vendor. That's exactly what happened.

Re: Okta hit by third-party breach, stealing employee data

#85

Earlier quoted context omitted.

There are two types of people, people who take responsibility for things that aren’t directly their fault, and people who regularly experience negative outcomes. Okta chose this vendor and they chose to have them store this data. They probably even have security requirements in their contract with them. They could have prevented this. And when you present yourself as a security company, you’re expected to.

There are two types of people, those who express everything in dichotomies, and those who don't, and those who start indexing at zero.

People who start indexing at 0 still say that {0, 1, 2} has 3 elements, not 2. ;)

Re: Okta hit by third-party breach, stealing employee data

#86
post #70

Earlier quoted context omitted.

It says Okta was "hit by" a breach, which it was. A breach happened, and Okta was impacted. Furthermore, it happened to data which Okta is ultimately responsible for, and Okta should be held responsible for their choices which led to their employees' data being stolen. I'm not sure why you're splitting hairs on this.

Because context and sentiment matters. By your logic clickbait is perfectly fine and we should maybe do more because they are (usually) technically correct.

Just continue reading the title all the way to the end? I know it's a long haul but come on, we can't just stop at the first bit of punctuation:

> Okta hit by another breach, this one stealing employee data from 3rd-party vendor

It's clear a breach has affected Okta employees.

Re: Okta hit by third-party breach, stealing employee data

#87
post #48

I don’t know why people are all pretending like this is irrelevant to Okta's security. An employee list like that is a goldmine for all sorts of social engineering and phishing attacks.

It’s not that it isn’t relevant, it’s the clickbait-y headline and insinuation that Okta itself was compromised again. Any major company using third-party vendors would be in the same position (and for all we know, this healthcare company provided services to multiple other companies). Fault Okta for not doing enough vendor due diligence, sure, but don’t use clickbait to imply Okta itself was breached.

Firstly, the title literally does what you're asking:

> Okta hit by another breach, this one stealing employee data from 3rd-party vendor

You have to read the whole thing.

Secondly, let's assume you were right and the title was simple "Okta hit by another breach" and there were no other words.

Do you not view it as problematic that the company has in two months had a major compromise of its own services via phishing, as well as that of a company supplying health-related services to its own employees? Do you not view that as potentially hazardous and concerning?

They chose this company. Effectively, they vetted this company and believed them to be doing things in a way that was secure for their employees. If that vetting process is terrible, then it speaks to how organization-wide the issues there are.

Re: Okta hit by third-party breach, stealing employee data

#88
post #63

Earlier quoted context omitted.

The next layer of cynicism down is more complicated. I'm going to make this up to protect the guiltocent, but I've been on the receiving end of security assessments that ask the moral equivalent of "Do you salt the MD5 hashes you use to store password hashes?" and we end saying Yes in some large number of words because we use bcrypt/scrypt properly, or some industry SSO, or our systems communicate with an internal CA…

Yeah. This is what always trips engineer-types up when dealing with legal. A contract isn’t code. There is usually, on both sides, a certain degree of BSing that goes on. Put another way, both parties are usually knowingly taking on risk associated with non-compliance. “We meet the security requirements in spirit only” is easily one of the more tame instances of this.

It's not that clear cut.

A contract is a probabilistic promise.

According to the writer's understanding of the law (and the risk tolerance they have for being caught) these are the terms they're putting to paper.

Generally, that means the writer's legal team feels confident that if everything goes sideways and they're standing in a courtroom, they have the best possible chance at winning the case with the language they used.

Now everyone around legal (e.g. sales, marketing, product, etc.) likely has different incentives. But the entire reason legal is somewhat firewalled is because they're the ones thinking about that future courtroom.

So it's less "there's a certain degree of BSing" and more that sometimes sales gets their preferred language and sometimes legal wins.

And of course, sometimes neither of them know relevant technical details and both their proposals are jibberish.

Re: Okta hit by third-party breach, stealing employee data

#89

What a misleading and click-baity title choice by Ars Technica. This had nothing to do with Okta's platform, as implied. A third-party Vendor Okta used for health insurance information was breached, and personal information on Okta employees was stolen. I'm disappointed in Ars Technica, and Dan Goodin. edit: Updated to be more specific about what part of Okta this had nothing to do with.

ARS commenters seem to have created a very specific kind of echo chamber and they guard it passionately, fiercely rebuking any and all dissenting opinions into oblivion. Sadly, ARS writers seem motivated to cater these folks' predilections. Sometimes it seems like they write articles with little purpose other than to provide grist for their beloved mob's mill. Perhaps these journalists are rewarded for 'high audience engagement.'

So glad HN hasn't devolved into that. Gratitude to the mods here.

Re: Okta hit by third-party breach, stealing employee data

#90
post #84

Earlier quoted context omitted.

Ok, but that's not what the article says. It says Okta was breached. Okta was not breached.

It says Onta was hit by a breach, Okta was hit ny a breach, it even says that is was a third party vendor. That's exactly what happened.

The problem is the article is farming clicks by piggie backing off of the very recent and public breach Okta had. I don't know if there's a term for this, but it's clear to me they're abusing oktas name.
Post reply on HN