5 ms·
> Recommendations for Okta Seems a bit haughty to publicly chastise another company. The tone of this article is a bit off-putting for me personally.
by uncomputation 3y ago
> Recommendations for Okta
Seems a bit haughty to publicly chastise another company. The tone of this article is a bit off-putting for me personally.
- kalupa 3y agohaughty? https://news.ycombinator.com/item?id=37959904 https://news.ycombinator.com/item?id=37959904
- uncomputation 3y agoYes. No one likes a sore winner. Providing your customers with assurances? Good. Providing tips to Okta customers? Sure. Publicly chastising another company you do business with? Unnecessary. That should be kept private. Just my opinion
- toomuchtodo 3y agoI am responsible for spending several hundred thousand dollars a year with Cloudflare (out of my budget). I like this style. Don’t want to get called out, get your org fixed. This is somewhere between the third and fifth breach, depending on how you’re counting.
- landemva 3y agoAre you going to move your spend, or is having a 3rd party sling words good enough for you?
- toomuchtodo 3y agoEdit: removed for subthread cleanup.
- landemva 3y agoMy bad ... cf not okta.
- deleted 3y ago[deleted]
- tchbnl 3y agoThis is the _second_ time this has happened, and it's clear Octa hasn't learned any lessons. So Cloudflare is right to call them out, and Okta should be embarrassed. What surprised me about this post is that they didn't say they were dropping them. Okta is a vulnerability to any organization.
- forkerenok 3y ago> Publicly chastising another company you do business with? Unnecessary. I think this makes more sense for strategic business partners. In the Cloudflare-Okta case I'd wager that their relationship is fairly transactional.
- StressedDev 3y agoI am not sure I would call CloudFlare a “winner” in this case. They did not win anything by getting hacked.
- Kinrany 3y agoThey do win some points on having better security than a popular security product, considering Cloudflare's own security posture is also quite important to their customers.
- StressedDev 3y agoAgrees - CloudFlare and its employees did outstanding work. My main point was calling CloudFlare a sore winner did not make sense because they did not win anything. Also, I think CloudFlare’s blog post was very good.
- djbusby 3y agoBut the recommendations are good?
- codegeek 3y agoNot really. Here is one of the recommendations: "Take any report of compromise seriously and act immediately to limit damage; in this case Okta was first notified on October 2, 2023 by BeyondTrust but the attacker still had access to their support systems at least until October 18, 2023." It is good to call Okta out here as it impacts Cloudflare's business as well and if you can't fix a critical issue for 16 days, that is bad. Remember we are talking about Auth here. A breach impacts everything.
- Bijou_x7 3y ago[flagged]
- zmgsabst 3y agoOkay — and? Do we have anything to suggest CloudFlare is factually wrong? — or was that just random conversational chaff from a brand new account distracting from the stunning incompetence of Okta in ignoring a breach for two weeks? CloudFlare has more than enough reputation to make such an allegation — and Okta should be cut from any production usage. Two weeks of failing to address auth compromise is unprofessional conduct by both Okta leadership and engineers.
- sophacles 3y agoTo be fair, it's also the second time this has happened in 2 years - I don't mean okta breaches in general, I mean it's the second time the support system has been compromized to get access to customer accounts.
- madeofpalk 3y agoSee also, https://www.beyondtrust.com/blog/entry/okta-support-unit-breach https://www.beyondtrust.com/blog/entry/okta-support-unit-bre... > We raised our concerns of a breach to Okta on October 2nd. Having received no acknowledgement from Okta of a possible breach, we persisted with escalations within Okta until October 19th when Okta security leadership notified us that they had indeed experienced a breach and we were one of their affected customers.
- StressedDev 3y agoFirst, Okta got hacked and that hack allowed CloudFlare to get hacked. That is bad. Second, one of Okta’s other customers reported the hack and Okta either ignored the report, or investigated the report and did not find the hack. That is not good. Third, Cloud Flare’s response was professional. They asked a company providing a very important service to improve because that company’s product and practices endangered CloudFlare. If Okta does not want its customers to publically complain about its actions, Okta needs to improve and do better. In particular, if someone says they have been hacked, listen to them and keep digging until you find the problem.
- deleted 3y ago[deleted]
- cybersister 3y agoAgree. CF wont have the inside scoop and they use another company's statement to bolster own thoughts. I wonder about the BeyondTrust statement too. This just doesn't sound right....and, so far, although it could happen this week, there have been no SEC filings by Okta - which would have to happen if this was a bad situation for them.