3 ms·
Seems a bit premature to assume this was the vector used for those other breaches.
by photon12 5y ago
Seems a bit premature to assume this was the vector used for those other breaches.
- gurjeet 5y agoOne possible route: a Microsoft employee using an Okta protected product/service. That other product/service was compromised, which let hackers hack into MS employee’s computer, which gave them access to Azure infrastructure.
- Johnny555 5y agoThat seems like an attack vector unrelated to the Okta breach -- if it was possible to attack the MS employee's computer from a compromised app, then whether or not that app was protected by Okta seems immaterial.
- gurjeet 5y agoPerhaps the app was not compromised, to begin with. Hackers might’ve gotten into the build infrastructure of the app, rewrote it to make it compromised, and then all the users of that app are now compromised. Lesson: ask your (in this case Microsoft) employees to not use work computers for any personal use. /me goes to check if my password manager company uses Okta.
- Johnny555 5y agoAgain, this is not related to an Okta hack, employees could be using an app that has nothing to do with Okta and be compromised through this same attack vector. This is just wild speculation to make up a scenario where Microsoft could be affected by the Okta hack with no evidence to back it up.
- gurjeet 5y agoAgreed. It’s all speculation at this point. I hope I did not make it sound like I have any evidence to backup my speculation. I was just trying to come up with a threat vector to explain how it might be possible.
- cush 5y agoWhat about the build infra of an app would provide creds to log into ADO?