Okta has not learned their lesson with security with this hack, especially when they got themselves breached before in January.
Okta has not learned their lesson with security with this hack, especially when they got themselves breached before in January.
> Okta does not rely on the confidentiality of its source code as a means to secure its services.
Would it be more professional for them to host their code in a public repo?
They were trying to keep their source code secure, and they failed. Not a great look for a company that ask you to trust them with all of your user accounts.
In my experience, security is usually an afterthought in most tech companies. Just look at how many MongoDB instances in production were running on open ports with the default password, which was... no password.
Frankly, as an employee, security is not my problem.
Unless you're in a tiny or ass-backward company that doesn't even have a policy that covers such things.