7 ms·
Sources? Genuinely curious, we use Okta and I’d like to understand why you are saying that.
by djoletina 3y ago
Sources?
Genuinely curious, we use Okta and I’d like to understand why you are saying that.
- deleted 3y ago[deleted]
- pm90 3y agoPurely anecdotal but their systems are designed very poorly, they outsource their support to some really low quality vendor (read: you get 0 support). This is not a company I would trust if I had the choice.
- Veserv 3y agoCounter question, how has Okta proven that they have integrity and are competent and can be trusted to run critical IT? What quantitive evidence have they ever demonstrated that shows they can stop the attackers who would like access to the billions of dollars of assets whose access they authenticate? A criminal enterprise can literally hire tens to hundreds of skilled hackers full time for years to target these systems and still turn a profit. The default assumption is that systems are easily hacked. Claiming protection against even small teams of moderately skilled attackers, let alone organized crime, is a extraordinary claim. Where is their extraordinary evidence?
- xyproto 3y agoThe only proof of security is the lack of counter-evidence, though. One can prove that a vault has been secure for the N last years, but not that it will be secure for eternity.
- Veserv 3y agoSo I can just give you a cardboard box and call it a vault? You can not prove me wrong upfront so you have to believe me? That is ridiculous. There is plenty of evidence you can provide to establish confidence that a certain degree of security has been achieved. Robust auditing, thorough review, formal methods, exhaustive testing, competent red teams exercises failing to find any vulnerabilities, etc. The only people throwing their hands up claiming security can not be evaluated have nothing useful to say about security because they do not even believe it is possible to know if they did anything.
- reactordev 3y agoCounter argument. Okta does all those things. Provides all the evidence, the red teams, etc. and still you don’t trust them (because they continue to have breaches) so to argue that one can prove security is false. One can only practice security and find assurance in certainty that they can identify events after or when they occur. No one can predict the future and no one can guarantee security in perpetuity. So I agree with you that Okta sucks. I also agree with the argument that you have to keep the knife sharp but you can’t just state the knife is sharp. You have to draw some blood to prove it. Likewise security postures are tested when incidents occur, through testing oneself or from another testing you. Complacency in this is when holes form. Security can only be evaluated at the moment in time. You can audit the past, but you can’t audit the future.
- ungamedplayer 3y agoSo you think they hire competent red teams? Or give them the same scope that hackers are able to achieve?
- reactordev 3y agoNo and no, but I was just providing a counter argument so we can get past our bias and get to the heart of the issue. Can we trust Okta going forward? Do they understand the scope? The risks? Or are they full of Id and Ego that they think they are untouchable? Having red teams, having audits, having scans, etc is simply not enough for some folks but in Okta’s eyes, it’s enough for C-suite talks of taking Authentication/authorization off the plate of their IT department. I firmly believe for every individual who thinks they are untouchable, there’s a hacker who knows more and is willing to throw it all away to prove a point.
- ungamedplayer 3y agoCan't agree more.
- Veserv 3y ago
- darkerside 3y agoDo they have competitors who have been able to provide evidence for those claims?
- Veserv 3y agoNot that I am aware of, which bolsters my point. If airsoft pellets keep ripping through everybody's "bulletproof" vests and they all keep telling you to have faith in their new vest, and no, they will not provide you any evidence that it works, then any sane person would be running for the hills. You should be completely skeptical that an entire industry that can not even stop airsoft pellets can suddenly able to stop bullets, 354th times the charm for sure, until they show you some extraordinary evidence. Fool me once, shame on you. Fool me 354 times in a row for three decades, shame on me.
- darkerside 3y agoSomeone needs to be liable for security. The alternative isn't running for the hills, it's sewing your own vest.
- madeofpalk 3y agoThe linked article?
- c420 3y agoThe first time was March of last year. https://blog.cloudflare.com/how-cloudflare-mitigated-yet-another-okta-compromise/ https://blog.cloudflare.com/how-cloudflare-mitigated-yet-ano...
- 4death4 3y agoIt’s actually comical that Cloudflare is trying to blame Okta for this. A Cloudflare employee uploaded secrets to Okta’s support tool. That is what caused the breach.
- ethbr1 3y ago>> It appears that in our case, the threat-actor was able to hijack a session token from a support ticket which was created by a Cloudflare employee. It's the same type of session replay attack (likely HAR) discussed in the original article, no? It seems a reasonable expectation to assume that anything sent to Okta support isn't instantly available to attackers. So, yes, valid session tokens were dumb. But also yes, Okta fucked up here too.
- 4death4 3y ago> It seems a reasonable expectation to assume that anything sent to Okta support isn't instantly available to attackers. No that’s not a reasonable assumption. Malicious Okta employee is just as significant an attack vector as compromised Okta support tool.
- ethbr1 3y ago'Malicious Okta employee' who already has privileged access in the systems the customer has chosen to outsource their auth to? If Okta employee is a high priority threat model... then the customer is better off not using Okta. Not that it shouldn't be considered, but if Okta top-to-bottom penetration is expected and accepted, then that's taking Zero Trust to a whole new length.
- NicoJuicy 3y ago
- jbverschoor 3y agoSource: search for okta on hn
- hansvm 3y agoI was at an org who started using Okta a few years ago (left a few months later, unrelated). Among the issues, it wasn't confidence inspiring that the policies that org set (like requiring the Okta app for 2FA rather than TOTP, or enforcing certain properties about the passwords you're allowed to use) were only enforced in the browser and could easily be circumvented by just sending an appropriate request. Maybe they're fine otherwise, but my rule of thumb is that every security-critical single-point-of-failure like Okta will have major problems, and they certainly haven't presented enough evidence to sway that opinion.