Okta concludes its investigation into the January 2022 compromise
1–6 of 6 posts
Re: Okta concludes its investigation into the January 2022 compromise
#2Re: Okta concludes its investigation into the January 2022 compromise
#3Re: Okta concludes its investigation into the January 2022 compromise
#4Is there any reason they do not mention who is the "globally recognized cybersecurity firm"? Also I did not find them mentioning anything about honesty :).
If you are still on Okta in a month, you should be held criminally liable when the next hack happens.
Re: Okta concludes its investigation into the January 2022 compromise
#5Re: Okta concludes its investigation into the January 2022 compromise
#6Is there any reason they do not mention who is the "globally recognized cybersecurity firm"? Also I did not find them mentioning anything about honesty :).
Yes, that the cybersecurity firm found a big enough trashfire that they don't want their name associated. If there were a competent security firm, there would be a detailed timeline (perhaps not in this post, but linked from it) of "Hacker got access, did X, Y, Z. Last access using compromised token was at A and token expired automatically at B". The other alternative is they hired Kaspersky and don't want to mention…
Now, that said, Okta should be more open in order to engender trust. I think this is where you are going with the comment and in this I agree.