3 ms·
I'm really sick of companies disclosing this shit late Friday afternoon. Go fuck yourselves. Sincerely, Everyone in the industry
by Forbo 2y ago
I'm really sick of companies disclosing this shit late Friday afternoon.
Go fuck yourselves.
Sincerely,
Everyone in the industry
- pluc 2y agoIt's the second time they do that in a few weeks too, _and_ it's not on their security page [1] which promises transparency. [1] https://trust.okta.com/ https://trust.okta.com/
- slama 2y agoIt is listed on their security advisories page, which you can navigate to from that link: https://trust.okta.com/security-advisories/ https://trust.okta.com/security-advisories/
- cyberax 2y agoThank you for your feedback. Next time, we'll disclose it on Saturday evening. -- With Love, Okta.
- chanux 2y agoAlso, are there any repercussions for this kind of stuff? I don't know, fines from the organizations they get compliance certifications from or something.
- _hyn3 2y agoNo repercussions, sadly. Those compliance companies are (mostly) all just checking a box. It's (mostly) security theater from people who wouldn't know security if it bit them in the nether regions. Even if that wasn't true, there's probably no box in any compliance regime that says "Yes, we loudly promulgate our security failures from the nearest rooftop on 10am on a weekday" (and it's always five o'clock somewhere, right?) If it helps (I know it doesn't), the Executive Branch likes to do this with poor job number revisions, too, lol
- hoffs 2y agogeee, nobody is targeting you
- Forbo 2y agoDoesn't have to be targeted for it to be shitty behavior.