>The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers. despite an overwhelming preponderance of damning evidence from twitter (as well as the hacker themselves) you've somehow managed to find yourselves secure instead? Christs whiskers thats some impressive doublethink. Its also an excellent opportunity to fall on a sword that giv…
Maybe I’m just an unimpressed security professional but I’ve still not seen evidence I’d call a breach. At least not a significant one if you want to argue sublantics. Workers at organizations get compromised all the time. This doesn’t mean their systems/products are compromised.
Updated Okta Statement on Lapsus$
91–100 of 239 posts
Re: Updated Okta Statement on Lapsus$
#92Lapsus has responded https://img.guildedcdn.com/ContentMedia/e4149dc99f447074cb2c...
What telegram channel is this?
Re: Updated Okta Statement on Lapsus$
#93Earlier quoted context omitted.
Can you open the web console with just an access key? My impression was you could only use that to act through a CLI tool, at least officially you need to have powers or act as a user with powers to use the web console directly?
Not using access keys- although using the cli you could create a user which does have the ability to login to the portal.
Re: Updated Okta Statement on Lapsus$
#94>The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers. despite an overwhelming preponderance of damning evidence from twitter (as well as the hacker themselves) you've somehow managed to find yourselves secure instead? Christs whiskers thats some impressive doublethink. Its also an excellent opportunity to fall on a sword that giv…
Maybe I’m just an unimpressed security professional but I’ve still not seen evidence I’d call a breach. At least not a significant one if you want to argue sublantics. Workers at organizations get compromised all the time. This doesn’t mean their systems/products are compromised.
Okta is not just a bunch of software, it's also staff and processes, and the result is a trusted service they provide to customers. If that service is compromised, it doesn't really seem to matter how?
Re: Updated Okta Statement on Lapsus$
#95Earlier quoted context omitted.
Password reset requests still go to your registered email.
Do you know if Okta support are/were able to change a user's email?
Re: Updated Okta Statement on Lapsus$
#96Lapsus has responded https://img.guildedcdn.com/ContentMedia/e4149dc99f447074cb2c...
Re: Updated Okta Statement on Lapsus$
#97> Okta service has not been breached and remains fully operational > highlighted that there was a five-day window of time between January 16-21, 2022, where an attacker had access to a support engineer’s laptop These are some impressive mental gymnastics!
> Okta detected an unsuccessful attempt to compromise the account of a customer support engineer working for a third-party provider
> highlighted that there was a five-day window of time between January 16-21, 2022, where an attacker had access to a support engineer’s laptop
Re: Updated Okta Statement on Lapsus$
#98>The Okta service has not been breached and remains fully operational. There are no corrective actions that need to be taken by our customers. despite an overwhelming preponderance of damning evidence from twitter (as well as the hacker themselves) you've somehow managed to find yourselves secure instead? Christs whiskers thats some impressive doublethink. Its also an excellent opportunity to fall on a sword that giv…
If there is one thing you want from a 3rd party auth provider, it's trust - this is not the time to play word games. I'd have far more faith in them if they were transparent about what had happened, what they're doing about it, and how they will make sure it can't happen again. Instead, they are being weasels - I for one, will not be using their services again, and this behaviour is the reason why. Here's another exa…
Re: Updated Okta Statement on Lapsus$
#99Lots more detail: https://blog.cloudflare.com/cloudflare-investigation-of-the-...
> Suspend the one Cloudflare account visible in the screenshots As far as I can see, there's a lot of cloudflare accounts visible in the screenshots shared by the group. Stuff like cloudflaretv1, etc..
Re: Updated Okta Statement on Lapsus$
#100Earlier quoted context omitted.
8600 channels? Wouldn't that overwhelm you? I'm trying to think up scenarios where an org would need so many, but I can't. Is this normal?
I suspect lots of small channels with only a few people in them. They have 5k employees, it adds up.
#Dick
#Harry