23 ms·
Funny how this article points that Okta was notified by a third-party of suspicious tenant activity, Okta did not find evidence of the breach, and only after s
by dotty- 3y ago
Funny how this article points that Okta was notified by a third-party of suspicious tenant activity, Okta did not find evidence of the breach, and only after some persistence from BeyondTrust did Okta re-investigate and identify the breach.
Okta published a blog post here: https://sec.okta.com/harfiles https://sec.okta.com/harfiles and kicks it off with
> Okta Security has identified adversarial activity
and no mention of the notification from the third-party. Nice transparency!
- miohtama 3y agoIt's beyond my comprehension why anyone is using Okta anymore. Authentication is the most critical piece of any IT. Okta has proven again and again to be untrusted party lacking integrity. It's just a time bomb about to go off.
- djoletina 3y agoSources? Genuinely curious, we use Okta and I’d like to understand why you are saying that.
- deleted 3y ago[deleted]
- pm90 3y agoPurely anecdotal but their systems are designed very poorly, they outsource their support to some really low quality vendor (read: you get 0 support). This is not a company I would trust if I had the choice.
- Veserv 3y agoCounter question, how has Okta proven that they have integrity and are competent and can be trusted to run critical IT? What quantitive evidence have they ever demonstrated that shows they can stop the attackers who would like access to the billions of dollars of assets whose access they authenticate? A criminal enterprise can literally hire tens to hundreds of skilled hackers full time for years to target these systems and still turn a profit. The default assumption is that systems are easily hacked. Claiming protection against even small teams of moderately skilled attackers, let alone organized crime, is a extraordinary claim. Where is their extraordinary evidence?
- xyproto 3y agoThe only proof of security is the lack of counter-evidence, though. One can prove that a vault has been secure for the N last years, but not that it will be secure for eternity.
- Veserv 3y agoSo I can just give you a cardboard box and call it a vault? You can not prove me wrong upfront so you have to believe me? That is ridiculous. There is plenty of evidence you can provide to establish confidence that a certain degree of security has been achieved. Robust auditing, thorough review, formal methods, exhaustive testing, competent red teams exercises failing to find any vulnerabilities, etc. The only people throwing their hands up claiming security can not be evaluated have nothing useful to say about security because they do not even believe it is possible to know if they did anything.
- reactordev 3y agoCounter argument. Okta does all those things. Provides all the evidence, the red teams, etc. and still you don’t trust them (because they continue to have breaches) so to argue that one can prove security is false. One can only practice security and find assurance in certainty that they can identify events after or when they occur. No one can predict the future and no one can guarantee security in perpetuity. So I agree with you that Okta sucks. I also agree with the argument that you have to keep the knife sharp but you can’t just state the knife is sharp. You have to draw some blood to prove it. Likewise security postures are tested when incidents occur, through testing oneself or from another testing you. Complacency in this is when holes form. Security can only be evaluated at the moment in time. You can audit the past, but you can’t audit the future.
- ungamedplayer 3y agoSo you think they hire competent red teams? Or give them the same scope that hackers are able to achieve?
- madeofpalk 3y agoThe linked article?
- c420 3y agoThe first time was March of last year. https://blog.cloudflare.com/how-cloudflare-mitigated-yet-another-okta-compromise/ https://blog.cloudflare.com/how-cloudflare-mitigated-yet-ano...
- 4death4 3y agoIt’s actually comical that Cloudflare is trying to blame Okta for this. A Cloudflare employee uploaded secrets to Okta’s support tool. That is what caused the breach.
- ethbr1 3y ago>> It appears that in our case, the threat-actor was able to hijack a session token from a support ticket which was created by a Cloudflare employee. It's the same type of session replay attack (likely HAR) discussed in the original article, no? It seems a reasonable expectation to assume that anything sent to Okta support isn't instantly available to attackers. So, yes, valid session tokens were dumb. But also yes, Okta fucked up here too.
- 4death4 3y ago> It seems a reasonable expectation to assume that anything sent to Okta support isn't instantly available to attackers. No that’s not a reasonable assumption. Malicious Okta employee is just as significant an attack vector as compromised Okta support tool.
- ethbr1 3y ago'Malicious Okta employee' who already has privileged access in the systems the customer has chosen to outsource their auth to? If Okta employee is a high priority threat model... then the customer is better off not using Okta. Not that it shouldn't be considered, but if Okta top-to-bottom penetration is expected and accepted, then that's taking Zero Trust to a whole new length.
- NicoJuicy 3y ago
- jbverschoor 3y agoSource: search for okta on hn
- hansvm 3y agoI was at an org who started using Okta a few years ago (left a few months later, unrelated). Among the issues, it wasn't confidence inspiring that the policies that org set (like requiring the Okta app for 2FA rather than TOTP, or enforcing certain properties about the passwords you're allowed to use) were only enforced in the browser and could easily be circumvented by just sending an appropriate request. Maybe they're fine otherwise, but my rule of thumb is that every security-critical single-point-of-failure like Okta will have major problems, and they certainly haven't presented enough evidence to sway that opinion.
- deleted 3y ago[deleted]
- eximius 3y agoThey have the best integrations. This is not an endorsement of the decision to use Okta, but I understand why.
- libraryatnight 3y agoalso vendor lock in once youre invested is very real with execs. change is hard in general its even harder when its a significantly embedded service thay takes time and money to replace plus your director likes going to sports with their sales guys. also i sincerely believe theres a little bit of not minding they suck because they can just blame okta if something happens and blame is the worry.
- ethbr1 3y agoIt's a consequence of corporate culture that punishes failure. Part of changing is admitting the previous approach isn't working, and why it isn't working.
- pjc50 3y agoPunishes internal failure. Okta aren't in the hierarchy and can't be punished.
- vladvasiliu 3y agoThey could always punish the internal person who chose Okta. But I guess they're now big enough to be into "no one was ever fired for choosing [Okta]" territory?
- ethbr1 3y agoThis. Strategic missteps happen all the time. Two things are corrosive from the executive ranks: "Everyone knows this isn't working, but the director who authorized it is now an SVP" "Not my idea, so let's do something different just so I can say it was my idea" The middle way is healthier.
- bsder 3y ago> It's beyond my comprehension why anyone is using Okta anymore. Because, if you are already using Okta, it costs budget to change that. Who is signing up to to do that? Didn't Family Circus used to have a ghost character labelled "Not Me"? And, an bunch of people who didn't like Okta went with Auth0 and then wound up with Okta, anyway.
- subjectsigma 3y agoMy company uses Okta. Several of the lower level security employees expressed concerns and management told them to go fuck themselves. IT simply does not care. So that’s probably why - ignorance and apathy.
- empath-nirvana 3y agoSwitch to another provider. They will have the same problems. Do it yourself, you will have even worse problems.
- jaaron 3y agoI know this is old, so I'm not sure if you'll see it, but I'm genuinely curious what alternatives you suggest. My experience has been: start with Google until it's too painful to continue, choose between Azure AD or Okta. Self-hosting for plenty of firms is just asking for worse scenarios. Is there some market leader I'm unaware of?
- tana750cc 3y agoThat title from Okta has to be the lamest in all history of security breach announcements!! "Tracking Unauthorized Access to Okta's Support System" Horrible title, not transparent or direct, pretty lame. and I agree, it's dreadful that Okta did not even mention that BeyondTrust told them about it on Oct 2 (30 minutes after BT uploaded their HAR file to Okta Support).