They are not effective security controls and never will be and should never be a measure of that.
They are not effective security controls and never will be and should never be a measure of that.
I’ve also been closely monitoring the responses from our CTO and VP of Security when someone from our DevOps team posted a link to the Verge article in slack this morning.
Which brings me to this inquiry: How are your orgs responding to this? We have a dependency on an Okta-like provider and my first thought when reading this news was “you know, wonder if we should give our shit a sanity check”, and someone beat me to this, proposed it in slack but the idea was turned down by our SecOps team.
More reasons to look elsewhere.
Interesting. Does this agreement also works the other way as well (Okta can't just decides to terminate your account no matter the reason)?
https://auth0.com is the "still cares about customers" vendor
I'm not affiliated with them, just traumatized by working in IT
> There is no impact to Auth0 customers, and there is no impact to HIPAA and FedRAMP customers.
(Upon further review, it appears to be the more UK way of saying it! Ha!)
There are no winners.
I’d look at stuff like FedRAMP as a starting point for the control environment and explore further.