this post was submitted on 20 Oct 2023
77 points (97.5% liked)

Technology

59709 readers
1889 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Okta, a company that provides identity tools like multi-factor authentication and single sign-on to thousands of businesses, has suffered a security breach involving a compromise of its customer support unit, KrebsOnSecurity has learned.

top 6 comments
sorted by: hot top controversial new old
[–] [email protected] 16 points 1 year ago (1 children)
[–] [email protected] 21 points 1 year ago (1 children)

We urge Okta to consider implementing the following best practices, including:

Take any report of compromise seriously and act immediately to limit damage; in this case Okta was first notified on October 2, 2023 by BeyondTrust but the attacker still had access to their support systems at least until October 18, 2023

Holy shit, this is absolutely beyond negligent for an authentication platform.

[–] [email protected] 4 points 1 year ago (1 children)

They need to be raked over the coals by the FTC and class actions.

[–] [email protected] 4 points 1 year ago

And as a former admin for okta (as in admin access within a enterprise) I can also say their implementation can be a pain in the ass, especially if you adopt the system after someone else was fired for, in part, screwing it up.

[–] [email protected] 13 points 1 year ago

These kind of things don't look good at all for security companies.

[–] MySNsucks923 6 points 1 year ago

Work forces us to use okta to do everything. What a pain in the ass.