Live data from Hacker News

Updated Okta Statement on Lapsus$

okta.com

91–100 of 239 posts

Re: Updated Okta Statement on Lapsus$

#91
post #59

>The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers. despite an overwhelming preponderance of damning evidence from twitter (as well as the hacker themselves) you've somehow managed to find yourselves secure instead? Christs whiskers thats some impressive doublethink. Its also an excellent opportunity to fall on a sword that giv…

Maybe I’m just an unimpressed security professional but I’ve still not seen evidence I’d call a breach. At least not a significant one if you want to argue sublantics. Workers at organizations get compromised all the time. This doesn’t mean their systems/products are compromised.

Without proper separation of duties to limit blast radius, it's just as damaging as a software vulnerability. It sounds like that's the real issue here: Compromise of a support engineer lead to far more access than should have been permissible.

Re: Updated Okta Statement on Lapsus$

#93
post #68

Earlier quoted context omitted.

Can you open the web console with just an access key? My impression was you could only use that to act through a CLI tool, at least officially you need to have powers or act as a user with powers to use the web console directly?

Not using access keys- although using the cli you could create a user which does have the ability to login to the portal.

Untrue, any valid access key pair set can call “GetSignInToken” and access the aws console.

Re: Updated Okta Statement on Lapsus$

#94
post #59

>The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers. despite an overwhelming preponderance of damning evidence from twitter (as well as the hacker themselves) you've somehow managed to find yourselves secure instead? Christs whiskers thats some impressive doublethink. Its also an excellent opportunity to fall on a sword that giv…

Maybe I’m just an unimpressed security professional but I’ve still not seen evidence I’d call a breach. At least not a significant one if you want to argue sublantics. Workers at organizations get compromised all the time. This doesn’t mean their systems/products are compromised.

If through compromising those workers outside parties gain access to sensitive systems, and that situation is not promptly detected and corrected, then the system _is_ compromised.

Okta is not just a bunch of software, it's also staff and processes, and the result is a trusted service they provide to customers. If that service is compromised, it doesn't really seem to matter how?

Re: Updated Okta Statement on Lapsus$

#95
post #15

Earlier quoted context omitted.

Password reset requests still go to your registered email.

Do you know if Okta support are/were able to change a user's email?

You can indeed change the email / login on a user's profile an an org admin, but we probably won't know if Okta support agents themselves can also do that.

Re: Updated Okta Statement on Lapsus$

#97

> Okta service has not been breached and remains fully operational > highlighted that there was a five-day window of time between January 16-21, 2022, where an attacker had access to a support engineer’s laptop These are some impressive mental gymnastics!

What got me was this:

> Okta detected an unsuccessful attempt to compromise the account of a customer support engineer working for a third-party provider

> highlighted that there was a five-day window of time between January 16-21, 2022, where an attacker had access to a support engineer’s laptop

Re: Updated Okta Statement on Lapsus$

#98
post #82
post #59

>The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers. despite an overwhelming preponderance of damning evidence from twitter (as well as the hacker themselves) you've somehow managed to find yourselves secure instead? Christs whiskers thats some impressive doublethink. Its also an excellent opportunity to fall on a sword that giv…

If there is one thing you want from a 3rd party auth provider, it's trust - this is not the time to play word games. I'd have far more faith in them if they were transparent about what had happened, what they're doing about it, and how they will make sure it can't happen again. Instead, they are being weasels - I for one, will not be using their services again, and this behaviour is the reason why. Here's another exa…

[deleted]

Re: Updated Okta Statement on Lapsus$

#99
post #2

Lots more detail: https://blog.cloudflare.com/cloudflare-investigation-of-the-...

> Suspend the one Cloudflare account visible in the screenshots As far as I can see, there's a lot of cloudflare accounts visible in the screenshots shared by the group. Stuff like cloudflaretv1, etc..

Sorry. Should have been clearer. There’s a screenshot showing a password reset about to happen for a specific person. We suspended that account. In parallel, we were using our own logging to look for any password reset/MFA change over the last four months and just went ahead and forced a reset for all those users.

Re: Updated Okta Statement on Lapsus$

#100
post #84

Earlier quoted context omitted.

8600 channels? Wouldn't that overwhelm you? I'm trying to think up scenarios where an org would need so many, but I can't. Is this normal?

I suspect lots of small channels with only a few people in them. They have 5k employees, it adds up.

#Tom

#Dick

#Harry

Post reply on HN