3 ms·
Do you have any proof Okta is better or worse than any other solution? Measuring security is very hard. Here is the evidence I have seen regarding Okta's secu
by StressedDev 3y ago
Do you have any proof Okta is better or worse than any other solution? Measuring security is very hard.
Here is the evidence I have seen regarding Okta's security:
1. The had a breach last year.
2. They just had another breach. The breach was in their customer service department/system.
3. They may or may not have been slow to disclose the breach (remember, they may not have realized they were breached because they may get a lot of false breach reports and they may not have found evidence of a breach until recently).
4. They did not give credit to the customer who first reported the breach.
5. They may not have communicated with the customer after the customer reported the breach.
Here is what we don't know:
A. How skilled was the attacker. Skilled attackers are better at covering their tracks and harder to catch.
B. How many breaches has each ID provider had?
C. How many breaches has each ID provider detected?
D. How many breaches has each ID provider detected and covered up?
E. How many security bugs are in each provider's service? How serious are the bugs? How easy are they to find?
F. How good is the provider at detecting breaches?
G. How well are the provider's employees trained?
H. What percentage of the ID provider's employees care about security. A lot of people in the tech industry (software engineers, IT/sys admins/devops, managers, etc.) claim they care about security but their actions say otherwise. Examples include using easily guessed passwords, not patching software/dependencies, writing insecure code (buffer overflows, SQL injection, cross site scripting errors, etc.).
My main point is bashing Okta because they reported a breach does not prove Okta's product is any worse than any other product because we just don't have the information. We don't know how good other products are and it is even possible Okta is better than some or all of its competitors (it could also be worse).
- wepple 3y agoUnless you’re a tiny company, there are legal/regulatory requirements to disclose breaches. When it comes to AuthN, the right number of breaches is 0. Same argument for password managers, and why I advise people to stay clear of lastpass. We all know that breaches do occur, it’s impossible to be 100% secure etc. but having multiple breaches when you’re a security service provider is simply unacceptable. And when the timeline shows you were slow to react, it’s negligible for anyone to continue using that service provider. Data is great, but in lieu of it, that’s enough for me.