4 ms·
I'm sorry. I didn't mean to imply that Okta holds ourselves to a security standard that is lower than my own. What I was trying to say is that the reality is th
by jf 8y ago
I'm sorry. I didn't mean to imply that Okta holds ourselves to a security standard that is lower than my own. What I was trying to say is that the reality is that some organizations do not need (or want!) a high level of security. For some organizations, security questions to reset passwords is an improvement over past process (!)
Naturally, as a company that specializes in security, we have a unique threat model and do not allo SMS resets of passwords, security questions, etc for our organization.
If you're genuinely interested in learning more, I'd suggest looking at our security certifications: https://www.okta.com/security/ https://www.okta.com/security/ or reading the blog posts by our in-house security team: https://www.okta.com/security-blog/ https://www.okta.com/security-blog/
- jonny_eh 8y agoThanks for the clarification!