4 ms·
I don't understand how they can say "unsuccessful attempt to compromise the account of a customer support engineer" . then can say "Following the completion of
by mimikatz 5y ago
I don't understand how they can say "unsuccessful attempt to compromise the account of a customer support engineer" . then can say "Following the completion of the service provider’s investigation, we received a report from the forensics firm this week. The report highlighted that there was a five-day window of time between January 16-21, 2022, where an attacker had access to a support engineer’s laptop. This is consistent with the screenshots that we became aware of yesterday." and the screenshots of the attackers looking at Okta's support portal.
- vault 5y agoIf somebody uses my laptop, my Gmail account is not compromised; I'm being dolphined. Of course 5 days is quite a long time, but this is just to clarify what you didn't understand.
- mimikatz 5y agoIf I use your laptop to get access to your Gmail isn't your Gmail account compromised? I might not have access to your Gmail username and passwords (and MFA), but I can read your email, I can send email as you, etc etc. I feel like I have compromised your gmail account. If I steal your secure token and log into you through a cloned browser session and access your gmail have I compromised your gmail? It feels like it. Maybe it is just a distinction without a difference.
- tomnipotent 5y ago> your Gmail account compromised The access is transient and you remain in ownership over the credentials and account, because the credentials were not compromised (just the programs/browsers with pre-existing auth). Though with physical access it's probably only a mater of time before local admin passwords are brute forced and access to keychain/browser saved logins is inevitable? > If I steal your secure token It's more like you just logged in using your secure token then someone stole the device and took advantage of that. I think we can all agree there's a difference between having access to the laptop and access to the account without the laptop.
- shkkmo 5y ago> I think we can all agree there's a difference between having access to the laptop and access to the account without the laptop. There is a difference, but that difference is not the one you seem to be implying. An account can be compromised even it it hasn't been fully and permanently taken over. The temporariness of an account being compromised does not mean the account was not compromised. You can make a distinction and clarify that the account was compromised but that the account credentials were not. However if you extend that to saying that the account was not compromised when attackers did have temporary access, then you are simply lying.
- hota_mazi 5y agoIf someone has access to your email account, they more than likely will be able to password reset quite a few accounts (I'd start by searching your inbox for which banks/stock trades you use and take it from there).
- warp 5y ago"had access to a support engineer’s laptop" is very vague, they could have: 1. some kind of remote access to the support engineer's session on that laptop 2. physical access, no login 3. physical access as a different user 4. physical access, logged in as the support engineer If I have access to your laptop, logged in as you, and you have Gmail open in a browser, then your Gmail account should be considered compromised. (e.g. I could set up a forwarding address in your Gmail settings, set up a POP/IMAP password, steal your session/remember me cookies, install some dodgy software which makes sure I have remote access to your laptop in the future, etc..).
- nopcode 5y agoAccess to the laptop could also be completely unrelated. The threat actor used a breached Thin client to access Okta...
- hdlothia 5y agowhat does dolphined mean. is this a cyber security term?
- ASalazarMX 5y agoIt might be a new term that denotes someone who thinks a stranger having access to their computer doesn't compromise their accounts.
- Khaine 5y agoif its a cyber term, its not common. I've never heard it before.
- vault 5y agohttps://www.urbandictionary.com/define.php?term=Dolphining https://www.urbandictionary.com/define.php?term=Dolphining
- ralmeida 5y agoIf someone has access to your laptop with a logged-in Gmail account, they could change your password and log you out of your other devices, effectively gaining total control of your account and locking you out.
- glckr 5y agoTypically services will have you confirm your current password before allowing you to change it (for exactly this reason).
- postit 5y agoI have a bunch of screenshots in my laptop that I take for reasons like attaching to tickets and sharing on Slack. Some are very sensitive if shared outside the company. If the attacker had physical access to the laptop, that explains.
- WhyNotHugo 5y ago> If the attacker had physical access to the laptop, that explains. No full disk encryption or alike? Physical access should not be enough to access sensitive data, unless you have data unencrypted.
- jeremyjh 5y agoIt is really clever wording, but it is possible for the statements to be true, while being deliberately misleading. What they initially detected, and what the 3rd-party investigation found, were two different things. Okta initially "detected an unsuccessful attempt" - the successful attempts were not detected initially but the detected event did lead to an investigation. Now, JUST this week (presumably, in the last 72 hours to explain why disclosures have not already been sent) "we received a report from the forensics firm this week. The report highlighted that there was a five-day window of time between January 16-21, 2022, where an attacker had access to a support engineer’s laptop."
- mimikatz 5y agoThanks, I get it now.
- stevage 5y agoI didn't find this misleading at all. Just a chronology of their evolving understanding.
- nopcode 5y agoThey could just state that there was also a successful login. So far they don't do that.
- lIIIllllIIII 5y agoIt's misleading because grammatically, what one would usually say in this situation is something like "Okta detected what it believed at the time was an unsuccessful attempt", because the statement's narrative is set in the present - and we now know the attack (not "attempt") was successful. Wording it as they did in their statement obfuscates the events that took place, and certainly reads like a deliberate attempt to downplay the severity of the breach.