The goal is not absolute security, rather practically secure systems against attackers with moderate resources.
We can’t prove that a security company will not be breached. But once they have a significant breach, it might be time to move on. They likely have other problems. I’m looking at you LastPass!
Okta holds the keys to the castle. It has had a security incidence in the past. A compromise of the Okta systems will have a huge impact on its users. The margin for error is small.
The default assumption is that they can all be breached, the burden of proof is on them to prove they will not get compromised. It would only seem prudent to wait for positive proof of the extraordinary claim that they can not get hacked rather than extending the benefit of the doubt to serial incompetents.
when a breach can be caused by an unknown CVE in the future?
That seems impossible to prove, I mean I understand you can patch, audit, encrypt, your way to a safer system, but proof (by definition) is a very high bar.
What is an acceptable demonstration of proof given unknown future events? How does one define proof in the sense “will not get compromised” (future tense is used in your phrasing so a proof would have to include all possible future outcomes)
To go a step further, you can apply this to any acceptance criteria. What evidence is there that any of these systems meet any meaningful acceptance criteria. What evidence is there that Okta has systems that can protect billions of dollars worth of assets from the teams of professional and state attackers that currently target their systems?
To then get to your direct question, if you really need “should never get hacked”, you could provide machine checked mathematical proofs of correctness, robust and exhaustive validations, and NSA penetration test reports showing zero identified vulnerabilities like what was done for the F-35. I mean, I guess that is only like 1000x better than prevailing commercial IT systems and not completely foolproof, but it is certainly a good starting point. You can probably think of some ways to evaluate even more robust security if you need more assurance than the US air force.
Sounds pretty stupid, right?
Okay, now replace slingshot with tank.
Now it does not sound so stupid.
Turns out you can learn something based on the effort needed to breach a defense.
As it turns out, the entire commercial IT industry is basically incapable of stopping small teams of moderately skilled attackers as has been demonstrated to death. A team with just 1-2 M$ of resources is basically unstoppable even with 100 M$- 1 G$ budgets. That is the definition of gross inadequacy.
It seems a problem with the provider. You're problem is probably not even going to be checked without fulfilling their request.
Okta should have revoked the token after the file was no longer needed.
Should I remind you that multiple customers were compromised because of this and that Cloudflare was probably the only one that wasn't breached AND notified Okta...
This is why anyone even slightly concerned about this should use offline, self-hosted, or self-built alternatives.
A honeypot is a trap set to catch attackers. It does not include real data.
https://en.wikipedia.org/wiki/Honeypot_(computing)
Seeing this misuse a lot lately!
These services are attractive targets, but they are not honeypots.
Some of them might also run honeypots separately from their core service, but that is not under discussion presently.
Says a lot about security discussions around
Way to ignore my point, and nitpick about semantics.
No, this forms part of the definition.