Live data from Hacker News

New Updated Okta Statement on Lapsus$

news.ycombinator.com

1–10 of 38 posts

Re: New Updated Okta Statement on Lapsus$

#2
I think the flip flopping is hurting them and their users more and more. What was initially a flat denial this morning has resulted in taunts from Lapsus$ on Twitter, Okta was out-scooped by Cloudflare's public investigation. Now they admit a breach affecting 2.5% (roughly 250 orgs based on public data).

The webinar tomorrow should be fascinating if they allow questions.

Re: New Updated Okta Statement on Lapsus$

#3
Do I believe the revision? Well, I believe it more than the flat denial, but I doubt the scale. I expect another revision because Okta showed they revise in the light of emerging evidence and experience.

Re: New Updated Okta Statement on Lapsus$

#4
post #2

I think the flip flopping is hurting them and their users more and more. What was initially a flat denial this morning has resulted in taunts from Lapsus$ on Twitter, Okta was out-scooped by Cloudflare's public investigation. Now they admit a breach affecting 2.5% (roughly 250 orgs based on public data). The webinar tomorrow should be fascinating if they allow questions.

They've lost all credibility at this point. You can't say "we didn't get breached, nobody got owned" and then turn around and say "actually a lot of our customers did get owned" after you get called out on it.

Re: New Updated Okta Statement on Lapsus$

#5
post #2

I think the flip flopping is hurting them and their users more and more. What was initially a flat denial this morning has resulted in taunts from Lapsus$ on Twitter, Okta was out-scooped by Cloudflare's public investigation. Now they admit a breach affecting 2.5% (roughly 250 orgs based on public data). The webinar tomorrow should be fascinating if they allow questions.

They've lost all credibility at this point. You can't say "we didn't get breached, nobody got owned" and then turn around and say "actually a lot of our customers did get owned" after you get called out on it.

They lost all credibility when they failed to do the one single thing companies trust them to do, on a massive and severe scale, with long-lasting financial repercussions for AT LEAST 250 of the worlds biggest companies (I believe it's more than they're letting on).

Re: New Updated Okta Statement on Lapsus$

#6
post #2

I think the flip flopping is hurting them and their users more and more. What was initially a flat denial this morning has resulted in taunts from Lapsus$ on Twitter, Okta was out-scooped by Cloudflare's public investigation. Now they admit a breach affecting 2.5% (roughly 250 orgs based on public data). The webinar tomorrow should be fascinating if they allow questions.

“A contractor’s laptop was owned for 5 days who had super user access, but we didn’t get breached” was a strange conclusion in their original state.

Re: New Updated Okta Statement on Lapsus$

#7

Earlier quoted context omitted.

They've lost all credibility at this point. You can't say "we didn't get breached, nobody got owned" and then turn around and say "actually a lot of our customers did get owned" after you get called out on it.

They lost all credibility when they failed to do the one single thing companies trust them to do, on a massive and severe scale, with long-lasting financial repercussions for AT LEAST 250 of the worlds biggest companies (I believe it's more than they're letting on).

It is a shame that the new DHS 72 hour reporting requirement was not in effect when this breach occurred, but it is extremely evident why it is required. Regarding business classification, I don't think it's too difficult to argue that commercial identity providers are critical infra.

https://news.ycombinator.com/item?id=30699024

https://www.congress.gov/bill/117th-congress/house-bill/2471...

Post reply on HN