3 ms·
At my own workplace (a SaaS service), we cannot change passwords, we can only send reset links (and the reset email goes to the end user). I can't see any plac
by socks 5y ago
At my own workplace (a SaaS service), we cannot change passwords, we can only send reset links (and the reset email goes to the end user).
I can't see any place in the screenshots where they are setting a user's password, only sending reset links (which would do nothing if the support user does not have access to system email or end users email).
Also at my workplace, 2FA is not enforced by an IdP (like Okta), but by our own application (and therefore could not be disabled at the IdP level).
- ctvo 5y agoIs your workplace Okta? They built a custom internal tool. Until they enumerate exactly what the attacker had access to it’s hard to infer anything.
- sb8244 5y agoThe article specifically addresses this, right? They log every interaction from support engineers and are going to report to the affected customers what actions were performed. As others have mentioned, the slack access is potentially more concerning.
- adrr 5y agoHow do you send a reset password email with a SSO platform that gates email?
- oneweekwonder 5y agoIf you have 2FA a OTP can be sent to a trusted device or app to allow a password reset without having access to email?