7 ms·
> no one has access, except Bob, because he runs the SSO server, but we really trust him you know How is Okta better? You trust people who you don't know at al
by saati 3y ago
> no one has access, except Bob, because he runs the SSO server, but we really trust him you know
How is Okta better? You trust people who you don't know at all, and they already caused numerous high-profile security incidents.
- linuxftw 3y agoYou can't use reason and logic with the security people. They have a box that needs to be checked, they don't consider any possibilities outside of that box.
- goalieca 3y agoAs a security person, agreed. Too few have ever written a line of code or shipped a product under massive constraints. However, those checkboxes do exist because engineers, IT, and everyone else involved have major lapses. I guarantee you 99% of orgs out there have a worse posture than okta and never find out they've been compromised. I think it's important to admit that _all_ organizations have been hacked. Even the NSA. Most just never find out and if they do they have little idea what was compromised.
- gizmo 3y agoOkta has a well-earned reputation for worst-in-class security practices.
- joshcanhelp 3y agoSource?
- lannisterstark 3y agoNot OP but Okta gets breached like thrice a year.
- FreakLegion 3y agoWorst-in-class is overstating it, but they've had three serious breaches in the last three years, not counting exposure of their private GitHub repos. The thing that really bothers me about Okta though is that they've been caught lying when asked if they were affected by CVEs. See this thread from one of the Duo founders responding to folks (including one of the Cloudflare founders) being stonewalled by Okta during the fallout from Log4Shell: https://nitter.net/jonoberheide/status/1506280347306188805 https://nitter.net/jonoberheide/status/1506280347306188805.
- burnte 3y agoIt's about managing liability at that point, it's not a technical concern but a legal/regulatory one. If you have a contract with Okta and they screw it up, you have better legal recourse than just firing the guy internally. Security isn't exclusively a technical concern.
- djbusby 3y agoBut you can still get sued if a breach at Otka causes damage to your clients. That is: outsourcing doesn't remove obligation or liability - you can point the finger but are still on the hook.
- hunter2_ 3y agoYou can get sued and then you can get reimbursed by suing the third party provider. You can't very well get reimbursed by a former employee.
- burnte 3y agoPrecisely.
- burnte 3y agoYs, you can sue anyone at any time for any thing, but you have to actually show cause, show harm, show standing, show breach of contract, etc. So you sue me. I said I fulfilled all of my obligations according to the contract and since the fault was with a third party you knew I already trusted, I get your case thrown out because I can demonstrate you knew this was a risk, and agreed to hold me harmless in the case of a third party breach beyond my control. Or, I settle/lose and I or my insurance company then go after Okta for my losses.
- deleted 3y ago[deleted]