5 ms·
Not really. Here is one of the recommendations: "Take any report of compromise seriously and act immediately to limit damage; in this case Okta was first notif
by codegeek 3y ago
Not really. Here is one of the recommendations:
"Take any report of compromise seriously and act immediately to limit damage; in this case Okta was first notified on October 2, 2023 by BeyondTrust but the attacker still had access to their support systems at least until October 18, 2023."
It is good to call Okta out here as it impacts Cloudflare's business as well and if you can't fix a critical issue for 16 days, that is bad. Remember we are talking about Auth here. A breach impacts everything.
- Bijou_x7 3y ago[flagged]
- zmgsabst 3y agoOkay — and? Do we have anything to suggest CloudFlare is factually wrong? — or was that just random conversational chaff from a brand new account distracting from the stunning incompetence of Okta in ignoring a breach for two weeks? CloudFlare has more than enough reputation to make such an allegation — and Okta should be cut from any production usage. Two weeks of failing to address auth compromise is unprofessional conduct by both Okta leadership and engineers.
- sophacles 3y agoTo be fair, it's also the second time this has happened in 2 years - I don't mean okta breaches in general, I mean it's the second time the support system has been compromized to get access to customer accounts.
- madeofpalk 3y agoSee also, https://www.beyondtrust.com/blog/entry/okta-support-unit-breach https://www.beyondtrust.com/blog/entry/okta-support-unit-bre... > We raised our concerns of a breach to Okta on October 2nd. Having received no acknowledgement from Okta of a possible breach, we persisted with escalations within Okta until October 19th when Okta security leadership notified us that they had indeed experienced a breach and we were one of their affected customers.
- wredue 3y agoSEC requires public disclosure basically immediately (within a few days. Less than a week for sure) for public companies if a hack could harm your bottom line or trade value. Hopefully they sink their teeth and give out a nice fine for this insane negligence, but I suspect okta is in for a strongly worded letter.