14 ms·
Okta says hackers stole data for all customer support users
- wutwutwat 3y agoAt this point it might be time to stop using the service handling your company's auth, which is supposed to be the most secure link in the chain, yet is being hacked every quarter.
- tamimio 3y agoGood, so next time people learn not to use and/or reject any service that tries to ask you to register in these “identity verification” services.
- bootlooped 3y agoI think most people who use Okta probably do so because it's required by their employer.
- w-ll 3y agoHow did Okta even get that big, it seems like sso could be cheap oauth in house. I've herd they ahve many other integrations/webhooks but that doesnt seem the cost of outsourcing one of the most vital part of your org. Am I missing something, some magic other than sales and gullible pm's?
- godzillabrennus 3y agoOne place to go to deactivate many logins for an ever expanding world of SaaS systems is basically necessary in 2023 for enterprise. Okta has been building that.
- djbusby 3y agoWe've spent years telling folks that $X is too hard; so just out-source to $LIB or $PACKAGE or $VENDOR. Now we've got a whole huge group of builders, managers of makers that make these plans/calls. We should stop saying $X is too hard and start, at least, trying to help more folk realize it can be done in house. It all started when it became "too much trouble to host your own email" and then all the centralization and vendorification happened...and stay off my lawn!
- moepstar 3y agoI honestly wonder when/if there will be a time where everything will be insourced again and thus removed from the cloud.
- betaby 3y ago90% of the world's compute power is not cloud. Guesstimate from the traffic patterns at telecom (including non internet capacity).
- mango7283 3y agoTo be fair, when people host their own email we end up with them also not patching the exchange servers and subsequently getting hacked anyway.
- ffgjgf1 3y agoOn average decentralization would make it less safe not more though. Most medium/small and even some large businesses would definitely mess something up if they had to do it themselves
- CalRobert 3y agoAmazing sales team. Was working at auth0 when okta bought them and they kept going on about how great oktas sales org was.
- _AzMoo 3y ago> it seems like sso could be cheap oauth in house It's outsourcing risk. Auth is hard, we all know it (yes, it is hard), and it's cheaper to outsource to a company who has it as their core competency, than hire internal experts.
- dclowd9901 3y ago“Cheaper” is an interesting term to use when we’re talking about auth. I guess it depends on how much a company values the ability of outside entities to not have access to internal resources. Some companies would peg that value at the entire value of the company.
- recursive 3y agoSome companies also trust an outside entity to get it right more than they trust themselves.
- guitarbill 3y agoSome companies are also happy to be able to blame a third party. And there's safety in numbers. A risk mitigation of a different kind.
- redserk 3y agoA lot of companies rely on third party vendors for physical access management because who wants to in-source maintenance of locks/doors/badge readers/etc. I’m not sure why it comes across as unusual for wanting to outsource a service that is incredibly easy to get wrong to someone whose core focus is getting that right. Unfortunately Okta seems too eager to downplay these incidents, but that doesn’t mean all authentication services are equally flawed.
- mocheeze 3y agoIt's basically THE WAY to get authorizations for medical practices to get prescriptions approved for patients in the US. Ridiculous. (Along with a bunch of other medical logins.)
- deleted 3y ago[deleted]
- kopirgan 3y agoUse stronger MFA as in, not use okta?!
- The28thDuck 3y agoI know govt. contractors use Okta for authentication. Since names and emails were taken, I expect more targeted phishing attacks as a result of this. Fortunate it wasn’t sensitive data (hopefully.)
- Flipflip79 3y agoGov orgs usually would use a FedRamp tenant and those weren’t impacted (apparently, my trust in Okta right now isn’t high)
- deleted 3y ago[deleted]
- m4jor 3y agoOkta is rated as FedRAMP High...seems like their rating means fuck all imo.
- collsni 3y agoA fedramp high accreditation means you at least have your shit together. Not easy to fake that one. I guess you could have a shitty coalfire assesor
- somehnguy 3y agoHaving been involved in both sides of other certifications before (not FedRAMP specifically though) my level of trust in them is through the floor. So much meaningless box ticking & not much actual substance.
- deleted 3y ago[deleted]
- aunwick 3y ago[flagged]
- hnthrowaway0315 3y agoNice. Is it the third time this year that we have good news from Okta? I don't know why we are still using it. What other options are out there?
- webo 3y agoOn one hand, the market seems to react to these appropriately. On another hand, the market has a short-term memory and prices go back up. It's unfortunate Auth0 was acquired by them. Have used it from the beginning and it used to be a great product before the Okta acq. Now it's just constant sales emails, expensive pricing, not much new feature launches, most features are very enterprise focused, bunch of bugs, frequent outages.
- flockonus 3y agoStock 41% up in the last 12 months is not appropriate.. it basically signals, "buy at a huge discount after each incident, we'll keep it rising regardless". At this point, one could speculate they are not worth almost at all given they fail to deliver on their primary value proposition. They are not and have not been profitable either, only getting worse: https://finance.yahoo.com/quote/OKTA/financials?p=OKTA https://finance.yahoo.com/quote/OKTA/financials?p=OKTA
- faeriechangling 3y agoThis sort of business doesn’t have to immediately realize a profit they just have to expand their base of customer and dig their claws deeper into their customers core infrastructure. Once they do that they can exploit their customers for years before they’l be able to escape. Since they are frequently going to be competing in “lowest bidder wins” competitions they’re be foolhardy to try and make a profit up front honestly, counter-intuitively it would be lighting money on fire. This is also a product with pretty substantial benefits from scale, as Okta gets bigger more things integrate with them so they’re easy to integrate with so they get bigger… I’m just wondering who in the industry is still stupid enough to stick their neck out for Okta? Why are they getting new customers? Why not go with the other devil you know your cloud provider to offer mostly the same services? What is Okta offering when they seem relatively incompetent compared to the competition that often offers their products for cheaper up front?
- t-writescode 3y agoWhat is a good, alternative, external authentication solution outisde of Okta and their auth0 product, then? I was looking to use their product because I have trusted their ability to manage authentication.
- vdelitz 3y agoyou could also take at look at what we're building at Corbado (passkey-first authentication): https://www.corbado.com https://www.corbado.com
- NewJazz 3y agoWhat are you trying to do? Is self hosting keycloak an option?
- t-writescode 3y agoHonestly, I'd rather not self-host anything. Many people, such as Amazon and Auth0 provide services to handle authentication for you, so you're just given a jwt token or session information. I want to pay pennies per user to have it done right(tm)
- agarren 3y agoI didn’t realize it until looking at it just a moment ago, but Auth0 is an Okta subsidiary. They don’t have a stellar record by themselves [0]. I guess that leaves Amazon? That’s not super encouraging. [0] https://www.bleepingcomputer.com/news/security/auth0-warns-that-some-source-code-repos-may-have-been-stolen/ https://www.bleepingcomputer.com/news/security/auth0-warns-t...
- justin_oaks 3y agoAmazon Cognito is an attractive option for authentication since it has a good free tier and is relatively inexpensive even outside of the free tier. The downside I ran into is that it doesn't support SAML SSO. It is only OAuth, OpenID Connect, and JWT.
- taspeotis 3y agoWhy did they have to buy Auth0??
- CaliforniaKarl 3y agohttps://archive.ph/raRaG https://archive.ph/raRaG
- cookiengineer 3y agoYet another breach of Okta... Why are companies not running something like keycloak [1] themselves? Are administrative/maintenance costs too high or is it plausible deniability? [1] https://keycloak.org https://keycloak.org
- kaidon 3y agoKeycloak is fairly easy to maintain. I run a deploy in AWS/ECS, and nearly never needs to be touched... except when an upgrade is required. Every upgrade has been challenging, starting with change to Quarkus, followed by removing dependencies from the docker images. But when it's not being upgrade, it's fantastic. Many thanks to Red Hat.
- madcadmium 3y agoThis is not a new breach, it is a disclosure of additional findings from the last breach.
- dclaw 3y agoI'm not sure why you keep saying this as if it makes the fact that they lied about the most recent breach any better.
- madcadmium 3y agoBecause people who don't bother to read the article assume it's a new breach, as we can see in the comments here ("another breach"). I'm not saying that it makes it better or worse.
- potatosalad21 3y agoThis is the same breach as before, with more details about what happened, not a new breach.
- ipsum2 3y agoThere has been two breaches, one in April 2022, another in October 2023. This post is about the October 2023 one.
- g-b-r 3y agoJanuary, and since it looks very similar to the more recent one (customer support breach), there seems to be a high chance that it's THE SAME, ongoing since at least that time. https://www.okta.com/blog/2022/04/okta-concludes-its-investigation-into-the-january-2022-compromise/ https://www.okta.com/blog/2022/04/okta-concludes-its-investi... https://www.okta.com/blog/2022/03/oktas-investigation-of-the-january-2022-compromise/ https://www.okta.com/blog/2022/03/oktas-investigation-of-the...
- caymanjim 3y agoIt's probably just confirmation bias because authentication system breaches get more coverage, and I pay more attention to them, but it seems like all the big players get pwned far too often. You had one job, buddy. Okta, 1Password, LastPass all had breaches or other failures. With so many self-hostable solutions available, I dunno why small/medium-sized companies trust external third parties.
- andiareso 3y agoDid 1password actually have a breach though? I think they stated due to Okta they reviewed their own systems and found nothing.
- throwaheyy 3y agoIt just never ends with this outfit.
- flerchin 3y agoJeez the hits keep coming. Every time they have to update about this Oct breach it puts FUD in my mind about this company, that I have never done business with anyway.
- mike10921 3y agoThey cant get away with "oh shiz we screwed up", this is the essential part of their business. If you're unable to perform the fundamental service you are offering, it's indefensible. Okta having a security breach is like a pizza shop owner who's unable to make a pizza.
- paulddraper 3y agoBut the shoemaker's children have no shoes?
- barbazoo 3y agoNot sure if it's reasonable to expect perfect security, people are fallible so that position won't make you very happy. We'll all get hacked, question is if we make it easy for them to gather private information which in this case didn't seem to have happened. The fact that it wasn't, probably is due to it being "the essential part of their business".
- giraffe_lady 3y agoOne of the most literal cases of "the breach is always twice as bad as the initial disclosure claims" I've seen. Also TIL the dept of defense uses okta that's reassuring for someone I'm sure.
- xGrill 3y agoThis could be potentially really dangerous. Most Okta customers who would use support would be IT admins. This is a pretty good list to start social engineering to get more information from other customers just by calling or emailing IT members impersonating corporate end users.
- skilled 3y agoIt took them almost a month to review their initial analysis? What is going on at this company that they can afford to be so aloof? > Today we are sharing new information that potentially impacts the security of our customers Maybe in another month they will conclude whether or not that “potentially” is a yes or no.
- toomuchtodo 3y agoTotal clown show running on enterprise inertia. https://en.wikipedia.org/wiki/Okta,_Inc.#Security_incidents https://en.wikipedia.org/wiki/Okta,_Inc.#Security_incidents
- rychco 3y agoI did not realize it was a $6 billion/6000 person public company. Their product is single sign-on services & they’ve got this bad of a track record? I guess I shouldn’t be surprised anymore
- dzikimarian 3y agoI assume their customers are vendor-locked to hell. Crazy what people do for convenience.
- bri3d 3y agoWhat blows my mind is that they've somehow managed to turn relatively minor incidents that aren't even compromises to their core systems into top-of-the-news-cycle meltdowns. The Lapsus$ compromise in 2022 was a third-party IT subcontractor getting their spy-on-the-employees RDP popped, and then Lapsus$ using incredibly limited access to the Okta admin tool to take some screenshots of support dashboards. Honestly it could have been spun into a "hey, our defense in depth pretty much worked!" story. Then, the most recent issue was an employee's third-party password manager getting compromised, allowing an attacker to log in to the support ticket tracker, which happened to contain HAR files with creds in them as well as details on support contacts. I bet a lot of enterprises are vulnerable to this, the HAR file thing is actually a great lesson in a highly unexpected threat vector. But somehow Okta have managed to turn it into a months-long top-of-the-news cycle incident, first by denying the compromise happened at all and then by underplaying the access the threat actor had to the support ticket tracker.
- barbazoo 3y agoA 5x3 table sure looks less embarrassing than a list of 15 items
- gvv 3y agoSpot on
- granshaw 3y agoGets cutoff on mobile too
- medler 3y agoOn my browser on iOS two columns get cut off. I thought it was a 3x3 table until I read this.
- 3-cheese-sundae 3y agoSame here. You can't even scroll to see it. I'm sure it's not intentional.
- Izkata 3y agoFor anyone confused, this comment was posted on a dup that included such a table, and the comments were moved here: https://news.ycombinator.com/item?id=38462681 https://news.ycombinator.com/item?id=38462681 The table isn't on this post.
- adolph 3y agoWill Okta pay a ransom for their own bugs? Will security companies release enterprise one-use email address products like Apple’s “Hide My Email?” Hide My Email generates unique, random email addresses that automatically forward to your personal inbox. Each address is unique to you. You can read and respond directly to emails sent to these addresses and your personal email address is kept private. https://support.apple.com/en-us/105078 https://support.apple.com/en-us/105078
- screamingninja 3y agoSee also: https://relay.firefox.com/ https://relay.firefox.com/
- sickofparadox 3y ago"For 99.6% of users in the report, the only contact information recorded is full name and email address." I can see the retraction already: "We have run a fully unfiltered scan, as opposed to a regular unfiltered scan, and it turns out we released the full age, name, address, and DNA sequence of every customer support user."
- sonicanatidae 3y agoRemember, they have to wait until there is literally not chance of the victims mitigating the issue, because releasing the info in a timely manner may affect the next quarter's numbers and the sole consequence will be a fine, paid with other people's money. Source: Most breaches.
- sylens 3y agoNames and email addresses of people likely to be an Okta admin or superadmin in your org....aka a curated target list for your next spear phishing campaign
- bri3d 3y agoIt's so strange to me that Okta have retained their CSO. None of the recent breaches seem particularly egregious in isolation, but the pattern around bungled communication and failed follow-up investigations is comical.
- jddj 3y agoWhen we propose our niche SAAS to larger customers, we're sometimes measured from a security perspective on whether we will integrate with their Okta SSO. Those discussions feel stranger by the day
- barbazoo 3y agoIf you become big enough, you'll get hacked too. Question is how hard you make it to find anything useful.
- jddj 3y agoAbsolutely. And if you get bigger still (Azure), nobody will even want to discuss it.
- TheRealDunkirk 3y agoThe product/company feels like the natural progression of the whole Oracle/Java/JS/SAML schtick, and has become the de facto when dealing with the kinds of people who base their whole company's IT personality on that stack. They're trying very, very hard to make it seem like it's another "no one got fired for buying IBM" kind of decision. Except... oops!
- emodendroket 3y agoIt seems quite unlikely you're getting fired for going with a massive vendor like this even if they have security incidents.
- deleted 3y ago[deleted]
- 23B1 3y agoClown show. Why hasn't their CSO been fired by now.
- mrweasel 3y agoBecause then the problem of handling the issue move upwards and no other C-level people would want to touch this.
- aquaphile 3y agoRemember RSA and OPM? The RSA hack had huge implications for the Department of Defense, and was probably a state-sponsored hack (likely China). Around the same time the Office of Personnel Management (OPM) was hacked. So the state-sponsored hackers got to all the private details of anyone with classified access and clearances (which can be used for blackmail or for answering those strange "Who was your 3rd grade teacher?" auth questions to get past an identity test), and simultaneously could hack the rotating MFA codes from RSA. Auth companies will always be a high value target for state-sponsored espionage.
- 6LLvveMx2koXfwn 3y agoFields which may facilitate security questions such as those you quote are explicitly not included in the report run by the 'threat actor'. In fact "for 99.6% of users in the report, the only contact information recorded is full name and email address."[1] 1.TFA
- halJordan 3y agoMaybe you could read the flipping comment?
- halJordan 3y agoMan those were the good old days. Remember when Gemalto, the main producer of key card cryptographic materiel- including DOD CACs- was hacked?
- aquaphile 3y agoYep. Gemalto was hot stuff for a while.
- pnathan 3y agoAgain? Third major hack in two years? Yikes.
- edgarvaldes 3y agoAgain? Hackers claim to have breached Okta systems (March 22, 2022) https://news.ycombinator.com/item?id=30762520 https://news.ycombinator.com/item?id=30762520
- dilyevsky 3y agoYes they basically have a breach every year for some number of years now…
- techwizrd 3y agoEvery update to this story feels like it's being trickled out.
- eigenvalue 3y agoI really don’t understand why a big company would continue to trust Okta with the most critical parts of their security infrastructure (identity) after multiple huge security breaches. And not just breaches, but ones where the company appears to be dishonest (or at least not very forthcoming) in their responses to those breaches, where they attempt to minimize the severity and their own culpability. Why not just use Microsoft or Google for this, which seem to have better recent security track records and certainly more overall security capabilities? How is Okta still a $10b+ market cap company? I don’t get it.
- emodendroket 3y agoOkta has tie-ins with a bunch of different systems that won't interop normally, right? I think that's a big part of it. Who wants to do their own SAML integration or whatever.
- eigenvalue 3y agoThat makes some sense, but that hardly sounds like a $10b+ value proposition, right?
- faeriechangling 3y agoThe switching costs are immense because you often need to weave their identity stack into all the software you write to allow for single sign on. These companies can milk their customers dry because their customers allow these providers to hold a gun to their head. You can sell a company like this to Broadcom and make megabucks as companies take 5 years to switch away.
- toomuchtodo 3y agoWe need the non profit idp equivalent of Lets Encrypt for this function. Otherwise, the cycle continues (accumulate customers, sell out, shareholders squeeze the customer base, customers churn to new orgs, etc).
- rickreynoldssf 3y agoOkta, you had one job! I don't understand why people still trust their user data to these guys.
- deleted 3y ago[deleted]
- CMYKninja 3y agoAt least they disclosed this I think that’s the most important thing.
- neilv 3y agoA widespread problem I've been wondering about, not specific to Okta... When an established company -- with something to lose; not a disposable serial startup -- outsources some IT function to a SaaS/PaaS/vendor that exhibits a pattern of problems, and then the company then gets bit by such a problem, how often does the company actually care? Does the CTO or CISO take a hit? Do the CEO and board even know that it was a bad selection from the start? Does the company just want to be able to say it was a "partner" who was at fault (even if the company was negligent in trusting that partner)?
- etchalon 3y agoThe last one. Very much the last one.
- tcgv 3y agoI'd say that more often than not C-Levels only take a hit if the bottom line is impaired, otherwise (like just some temporary heat from bad PR) it's business as usual.
- mbb70 3y agoPart of what the enterprise is buying is someone to blame. Same can be said for consultancies, outsourcing etc. It is a very real part of the politics of decision making at large orgs.
- johndhi 3y agoNot at my org. We always recognize a vendor error is perceived as our error by customers
- sonicanatidae 3y agoSame here. The client/EndUser gives 2 entire shits about the source of the problem. What they care about is "Why isn't this working and what is this gibberish on my screen" and rightly so.
- Nextgrid 3y ago
- jrockway 3y agoLocking sessions to a single ASN is probably a good idea. I always worry about the "insider threats" where your coworker sitting next to you grabs your cookie out of the Chrome inspector while you're in the bathroom, and this doesn't really help with that situation. But, it does help a lot with the attack that compromised Okta here, so I think it's a good idea in general. (Obviously you should always lock your screen when you step away from your workstation... but people seem pretty bad about that. At my last in-person job, I don't think anyone ever locked their screen when stepping away. So that's what makes this something I would worry about.)
- bdsa 3y agoLock your computer when you go to the bathroom
- BrandoElFollito 3y agoI am reading the comments and it's all how dumb IT is to use that instead of self hosting, how bad the saas companies are, etc. I wonder how many of the commenters run a 30k+ users company IT Dept or are the CISO of such a company. Well, everything is not a 2 years old startup with a Typescript stack on Postgres. Sometimes you have plenty of legacy systems, on prem services and a budget/headcount that allows you to go only that far by yourself. Or an Exchange system basically abandoned by MS, so you either go for some roundcube install or M365. Not all of your IT teams are either incompetent idiots, or psychopaths looking at making your life difficult. Sometimes they need to optimize and you see this optimization as idiotic while it may make sense in average. Sure, I would prefer to have genius SaaS companies that provide a service that is fantastic, or just host Internet myself but sometimes it is not possible and you choose the least bad of the bad.
- redserk 3y agoAlso, self-hosting does not inherently make something more secure, especially if it's sitting on the public internet. It requires consistent monitoring and correctly setting up alarms for strange behavior. If monitoring is done wrong, it could be a while to find out someone gained access, if the malicious access is even noticed. While Okta seems to have a number of issues, they don't represent all companies handling access management.
- scient 3y agoSelf hosting likely makes it much much worse. I'm willing to bet a lot on the fact that most authors of these comments do not have any kind of experience with serious security or compliance programs.
- bberenberg 3y agoIf you happen to be operating a Jira based support desk and want to reduce the risk of leaking customer data via HAR files, I took the HAR Scrubber that Cloudflare made and built a Jira plugin out of it: https://marketplace.atlassian.com/apps/1232593/securely-for-jira-har-cleaner-compliance-automation-free?tab=overview&hosting=cloud https://marketplace.atlassian.com/apps/1232593/securely-for-...
- mooreds 3y agoThanks for the pointer to that. If anyone else is interested: https://github.com/cloudflare/har-sanitizer/blob/main/src/lib/har_sanitize.tsx https://github.com/cloudflare/har-sanitizer/blob/main/src/li... is the scrubbing logic for cloudflare. Unfortunately, this scrubber would be problematic for Okta staff (or staff for any other authentication provider support team) because when someone is having issues with logging in, you need to examine Authorization and other authentication headers and data. So I think the best course is to: * caution users to not send production data, but rather to set up a test system and share the HAR file from that * make sure you do defense in depth and lock down access to support tickets * remove HAR files from closed support tickets. Here's a zendesk article about that: https://support.zendesk.com/hc/en-us/community/posts/6185912438682-I-want-to-delete-all-the-attachments-in-the-tickets-for-specific-period-of-time-eg-2021-year-is-it-possible-?page=1#community_comment_6186302454554 https://support.zendesk.com/hc/en-us/community/posts/6185912...
- MilStdJunkie 3y agoSomething interesting to note is that Okta held an ISO 27001 Certification issued third-party from Schellman. Chris Paris adds the note that Equifax also got nailed under the same arrangement, but with extra spice of CoI rules violations. https://www.oxebridge.com/emma/okta-breach-occurred-while-company-held-iso-27001-certification-from-schellman/ https://www.oxebridge.com/emma/okta-breach-occurred-while-co... I know Chris is a very controversial personality in the ISO ecosystem, but he's also got a disturbing habit of being right an awful lot of the time. I'd feel a lot more comfortable if someone could show me how he's just another crank.