3 ms·
(Disclaimer: I work at Okta) One thing I've learned at a visceral level is how different threat models are from one organization to the next. And while I agree
by jf 8y ago
(Disclaimer: I work at Okta) One thing I've learned at a visceral level is how different threat models are from one organization to the next.
And while I agree that the things you brought up don't meet my personal standards for security, there are many organizations where those features are acceptable given their use case.
- daveFNbuck 8y agoUnder what threat model do you need 2 factor authentication but it's ok if both factors can be bypassed by SMS? There may be some legitimate use cases, but I don't think companies that need to farm out their security to a third party will usually be in the best position to make this call.
- jf 8y agoAs I recall, for some consumer facing applications, the concern isn't about targeted attacks, but more about automated attacks that try to re-use passwords. In a scenario like that SMS is to slow down automated attacks. Keep in mind that I don't endorse that approach! Just giving an example of a narrow case where that applies. That said, I appreciate your feedback and will personally take your feedback to our product group.
- daveFNbuck 8y agoThat's a good answer, but it doesn't sound like a reasonable threat model for corporate single sign on. Thanks for taking my feedback to your group. I hope it helps.
- jonny_eh 8y agoHow does it feel to have tighter personal security standard than your employer, an employer who specializes in security? Are you trying to improve the situation?
- jf 8y agoI'm sorry. I didn't mean to imply that Okta holds ourselves to a security standard that is lower than my own. What I was trying to say is that the reality is that some organizations do not need (or want!) a high level of security. For some organizations, security questions to reset passwords is an improvement over past process (!) Naturally, as a company that specializes in security, we have a unique threat model and do not allo SMS resets of passwords, security questions, etc for our organization. If you're genuinely interested in learning more, I'd suggest looking at our security certifications: https://www.okta.com/security/ https://www.okta.com/security/ or reading the blog posts by our in-house security team: https://www.okta.com/security-blog/ https://www.okta.com/security-blog/
- jonny_eh 8y agoThanks for the clarification!