4 ms·
There's something about Okta that just scares me. If Okta is ever compromised, so are the thousands of companies that rely on it for IdP. How do companies mitig
by invokestatic 6y ago
There's something about Okta that just scares me. If Okta is ever compromised, so are the thousands of companies that rely on it for IdP. How do companies mitigate this risk? Or do they?
- JMTQp8lwXL 6y agoWhat if AWS was compromised and every DynamoDB instance was accessible?
- invokestatic 6y agoI think the difference is that the scope of DynamoDB is limited. A breach in authentication could result in the complete compromise of a company.
- sebmellen 6y agoBut use of S3, for example, is not limited much at all. It is very dominant.
- londons_explore 6y agoI suspect that a breach of most companies AWS accounts would lead to a complete breach of that company. Somewhere in the mountains of data stored in an AWS account and all it's associated EC2 instances and backups on S3 will be credentials or information to thoroughly breach all other systems.
- codingslave 6y agoYou literally just made this up based on nothing
- tekno45 6y agoSomeone is able to bypass very strict security and even if I went with a different or self hosted solution, if I was the target i would be got.
- temuze 6y agoThat's the same fear some people have about password managers... IMO, the answer is simple: I would rather security be done by a company where security is THE feature. In other words, I trust 1Password's security team over, say, Hulu's or something.
- rurp 6y agoSure, but it's not a 1-1 comparison. If Hulu gets compromised you only lose your (hopefully unique) Hulu credentials. If your password manager gets compromised a single attacker gets access to _all_ of your accounts. The security standard for a password manager is much, much higher than pretty much any other service. Password managers are still the best option for most cases, but having to put such an incredible amount of trust in a single company certainly makes me nervous.
- JMTQp8lwXL 6y agoThe problem is a password manager becomes such a valuable target. Sure, they have more security resources given the nature of their business, but it's that password management company's security staff versus a world's-sized quantity of potential bad actors, and one of those two groups has more resources than the other.
- stormbeta 6y agoExactly. I felt a lot safer using something like KeePass, and synchronizing the encrypted database using something like Dropbox. There's not a central target that would get caught up in large scale attacks aside from Dropbox itself - and even if they get access to that somehow, they'd then have to care about me specifically enough to run expensive offline attacks on the encrypted database. Anyone targeting me directly with those kinds of resources already has better avenues of attack.
- jokethrowaway 6y agoNot only password managers, popular OS as well. We may extend it to hardware as well but that's even harder to tell. I don't trust password managers for sensitive data but they're fine for most web account with limited capabilities. I made my own secret manager based on gpg/age (literally a 5 lines bash script) and I don't run it from any proprietary OS, like Mac OS X or Android. I trust my Arch Linux installation a bit more as I know which packages are installed or updated and I know what's running on it. Also I think an attack is less likely. I also have a separate system to share secrets across devices which allow me to setup a public/private keypair (+password) on every device and then share links on unsafe channels (like consumer chat applications or email).
- bonestamp2 6y agoI have okta accounts with a few companies and they all require 2FA. I hope Okta is configured so that if Okta itself were compromised, the 2FA would still be required to leverage the authentication vectors in okta.
- jfengel 6y agoIf Okta is ever compromised, they have a team of people working 24 hours a day to deal with it as quickly as possible. And, of course, to prevent it from happening. When it comes to security, it's often a pretty good idea to put all of your eggs in one basket, and then make sure it's a really, really good basket. Unless you're certain you can make a better basket yourself -- and when it comes to auth, there are a lot of ways to make bad baskets -- it's better to use somebody else's basket. It's not perfect, but I know I'm not an expert in auth. I use Auth0 and then get on with the rest of my work.
- the_duke 6y agoYou are arguing from the perspective of a single company, while the parent is arguing from an ecosystem perspective. Sure, for a single customer it's good to have a widely used product with a big ops and security response team. But if so many companies use a single provider, the fallout of a compromise also becomes much larger. This makes attacking the system more appealing and attracts more sophisticated adversaries, including state actors. Also, size doesn't necessarily lead to a better, more secure product. It often does for well-run, modern IT companies. But any familiarity with the enterprise software space is quite sobering in this regard.
- mooreds 6y agoMonocultures are more efficient, until they aren't.
- invokestatic 6y agoI've heard the exact opposite for security: defense-in-depth. For example, IdP with Okta and 2FA with Duo. This seems much better to me.
- diatone 6y agoAgreed. To add something useful to the conversation & giving the benefit of the doubt: maybe the parent was describing a situation where an org didn't have a cohesive security plan. If half your people are using one service, and the other half are using another, you've got a problem. I suppose this can blow out in complexity, and maybe risk(?), once you're stacking services (IdP, MFA, ...).
- adrr 6y agoOffice365 is larger and it was compromised. Onelogin was compromised and I had my secret keys stored in their vault. I spent all weekend rolling new keys.