4 ms·
We are completely locked out of our Atlas account and the support portal right now. We Okta-auth with Mongo and all attempts to auth right now are failing with
by iaresee 3y ago
We are completely locked out of our Atlas account and the support portal right now. We Okta-auth with Mongo and all attempts to auth right now are failing with "The request contained invalid data." displayed on their login screen.
Of course, the support portal requires you to auth to use it...to get help with auth failing.
Anyone else seeing issues getting in to their dashboard?
Edit: Auth started working for us and dashboard access became available for us around 5:15 pm ET.
- alexzeitler 3y agoupstream request timeout when trying to sign in
- iaresee 3y agoOn our side, Okta is saying the auth is good. I'm trying my personal account as well and it's telling me MFA isn't set up (it is) and it's making me go through the MFA setup flow again. All attempts to setup another 2FA code in 1Password or to get even an SMS code sent to my phone are failing. Edit: Personal account with a TOTP 2FA is working again now as well. This is feeling worse than they're letting on to.
- alexzeitler 3y agoSign in now worked once and sent me into the MFA setup loop but it failed.
- deleted 3y ago[deleted]
- ThePowerOfFuet 3y agoYou really should not be using SMS for 2FA.
- iaresee 3y agoYou really aren't following along closely enough: all other options were failing for me.
- speedgoose 3y agoBut you have setup SMS 2FA enabled, which is convenient this time but a big security hole. You should consider disabling it once the situation comes back to normal.
- iaresee 3y ago> But you have setup SMS 2FA enabled No. I did not. Nor do I now. I had a TOTP setup in 1Password and Mongo was telling me MFA _wasn't_ set up and sending me through the MFA setup flow again. All options, SMS included, were failing in that MFA setup flow they pushed me in to. They're back now and my existing TOTP token is generating one time use passwords that work now.
- rezonant 3y agoI bet that's because different parts of their stack disagreed. Obviously a two factor setup should not be acceptable when one is already in place-- if the frontend thought it wasn't but the backend/auth services thought it was, it could explain that.
- salil999 3y agoFor my own knowledge, if the options were between using SMS for 2FA or not having 2FA at all then what is better? I've heard mixed things about this.
- mtremsal 3y agoSMS 2FA is better than no MFA at all, despite the very valid concerns about SMS. It at least protects against credential stuffing and similar automated attacks.
- calyhre 3y agoSame here with Google SSO
- iaresee 3y agoWe regained dashboard access around 5:15 pm ET.
- mdaniel 3y agoSeeing that reminded me of this recent onoz, which one should fold into their threat model: https://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/ https://trufflesecurity.com/blog/google-oauth-is-broken-sort... <https://news.ycombinator.com/item?id=38670644 https://news.ycombinator.com/item?id=38670644>
- meghan 3y agoMongoDB employee posting: The login issues are unrelated to the security incident. We notified all of our customers and users concurrently resulting in a spike in login attempts. Please try again in a few minutes if you are still having trouble logging in. Please continue to monitor our alerts page: https://www.mongodb.com/alerts https://www.mongodb.com/alerts
- asdfsadfkljlkj 3y agoI mean that totally sounds related (hah!) although I guess we all know what they mean
- cowthulhu 3y agoThat’s a funny point, I guess I never really though of whether “related” was more correlation or causation.