4 ms·
This contains a lot of assumptions. Think of this in another context. How many reports do you think HR gets about a breach of company policy? Tons. They have to
by grobinrobin 3y ago
This contains a lot of assumptions. Think of this in another context. How many reports do you think HR gets about a breach of company policy? Tons. They have to investigate each one to determine if a policy was actually broken, if the reporter is telling the truth, and what the scope of impact the policy breach had. Meanwhile the offender can continue to keep breaking policy. Now imagine you are an HR Services company managing HR for thousands of companies....Point is it takes time to investigate and validate. Imagine the disruption if they took each report as true on face value.
I would also suggest that each of the companies that publicly posted have something to gain from doing so. We also don't know if they are telling the full story. Using the "we told okta on X date" as assuming that starts the clock on okta not disclosing a breach to the public is a pretty ridiculous take.
We still don't know the full circumstances of how this happened and Okta has not yet publicly commented on their side of this story. Presumably because the investigation is ongoing. But reading the details in the cloudfare post, access for the breach stopped on the 18th and okta told customers on the 19th. Is okta supposed to alert customers of every single report of a breach, every report that might have some credibility, etc...? Maybe there are process improvements to be made in the review process, but we have no visibility into the current level of effort they are making.
Meanwhile, other companies have had known issues for months/years (keyword is KNOWN) before disclosing. I don't want to be a victim of this more than anyone else, but I think we need to be more reasonable in our "hot takes" to these situations even if we are calling for continued improvement.