4 ms·
I don't know how I feel about this. On the one hand Okta's position in the market makes them a high value target to hack. Between the Lapsus$ hack in April and
by Decabytes 4y ago
I don't know how I feel about this. On the one hand Okta's position in the market makes them a high value target to hack. Between the Lapsus$ hack in April and this, Okta has had a rough year. At the same time I feel like they should know better, and I hated the way they handled the Lapsus$ breach, trying to hand wave the potential damage away
- TechBro8615 4y agoIt's pretty clear how to feel about this: unsurprised. Their internal infrastructure was pwned by some 16 year old chavs who broke into support software with unjustifiable "superuser" features accessible by any employee. And Okta never intended to reveal that to us until the chavs themselves made it known. This is a company that "literally" has one job - to protect the security of user accounts and facilitate login. Their product is simple and its development velocity is extremely slow. As a developer who has integrated Okta into multiple products, I've never gotten the feeling it's being run by a competent crew of software engineers, nevermind security professionals. It's entirely unsurprising to me that they would be compromised at this level. Not only are they a juicy target, but they've proven themselves generally incompetent at performing their basic job.
- atonse 4y agoThe only reason we picked okra is because a lot of our downstream vendors had Okta integration. I’m starting to wonder if there’s some kind of incentive given out or whether it’s one of those “let’s support okta cuz everyone uses it.” And then SaaS customers also say “let’s use okta cuz all our SaaS products keep mentioning it”?