The reason I think that is because if they really had keys for production machines it seems very unlikely they wouldn't have used them to produce some more damaging collateral than they've presented.
We get alerts when folks are sharing tutorial code with fake keys like DEADBEEF in them. It's nice to know DPL works, if you use it.
#Dick
#Harry
Of course, you still wouldn't have 8500 channels. That's a lot of incidents.
Once.
Thanks for bringing back the nightmares, friend.
Somewhere, there’s some project manager that says “Wow, I bet spooky23 would love to know about my spreadsheet sorting project”.
Much like the OP here I'm in hundreds of teams, and almost all of them do all their talking in #general and they wonder why people never respond to notifications.
The Teams UX and general paradigm is awful. Right now I'm in 3 group chats and two channels (in two Teams) discussing the Okta incident. Huge overlap of them, but not 100% so some people aren't getting all the information.
The context switch between a mostly useless teams tab and a needlessly full screen IM window is too heavy for me.
> Security Standards. Okta's ISMP includes adherance to and regular testing of the key controls, systems and procedures of its ISMP to validate that they are properly implemented and effective in addressing the threats and risks identified. Such testing includes:
> a) Internal risk assessments;
> b) ISO 27001, 27002, 27017 and 27018 certifications;
> c) NIST guidance; and
> d) SOC2 Type II (or successor standard) audits annually performed by accredited third-party auditors ("Audit Report").
I don't think storing AWS keys within Slack would comply to any of these standards?
They are not effective security controls and never will be and should never be a measure of that.
(Upon further review, it appears to be the more UK way of saying it! Ha!)
I’ve also been closely monitoring the responses from our CTO and VP of Security when someone from our DevOps team posted a link to the Verge article in slack this morning.
Which brings me to this inquiry: How are your orgs responding to this? We have a dependency on an Okta-like provider and my first thought when reading this news was “you know, wonder if we should give our shit a sanity check”, and someone beat me to this, proposed it in slack but the idea was turned down by our SecOps team.
More reasons to look elsewhere.
https://auth0.com is the "still cares about customers" vendor
I'm not affiliated with them, just traumatized by working in IT
> There is no impact to Auth0 customers, and there is no impact to HIPAA and FedRAMP customers.
Interesting. Does this agreement also works the other way as well (Okta can't just decides to terminate your account no matter the reason)?
There are no winners.
I’d look at stuff like FedRAMP as a starting point for the control environment and explore further.
The decision makers have absolutely no idea how any of this stuff works.
Mostly picking apart logical inconsistencies in the language and / or re-emphasising the already disclosed info. Does not seem like they were able to produce any hard collateral to contradict anything Okta stated which probably means it's at least ball park accurate.
https://de.catbox.moe/ovt7t7.jpeg
I remember healing a while ago that certain Telegram channels would be blocked on iOS devices due to Apple's content policy, that's what this seems to be about. Update: Yeah I can view them on desktop just fine.
Yeah, this is the fabled content moderation block for App Store distributed apps. The Mac App Store version of Telegram also blocks it, but the direct download dmg does not. I think the direct download apps are also updated more frequently, but I could be wrong on this.