This is not an endorsement of the decision to use Okta, but I understand why.
also i sincerely believe theres a little bit of not minding they suck because they can just blame okta if something happens and blame is the worry.
Two things are corrosive from the executive ranks:
"Everyone knows this isn't working, but the director who authorized it is now an SVP"
"Not my idea, so let's do something different just so I can say it was my idea"
The middle way is healthier.
Because, if you are already using Okta, it costs budget to change that. Who is signing up to to do that? Didn't Family Circus used to have a ghost character labelled "Not Me"?
And, an bunch of people who didn't like Okta went with Auth0 and then wound up with Okta, anyway.
Genuinely curious, we use Okta and I’d like to understand why you are saying that.
What quantitive evidence have they ever demonstrated that shows they can stop the attackers who would like access to the billions of dollars of assets whose access they authenticate? A criminal enterprise can literally hire tens to hundreds of skilled hackers full time for years to target these systems and still turn a profit.
The default assumption is that systems are easily hacked. Claiming protection against even small teams of moderately skilled attackers, let alone organized crime, is a extraordinary claim. Where is their extraordinary evidence?
One can prove that a vault has been secure for the N last years, but not that it will be secure for eternity.
There is plenty of evidence you can provide to establish confidence that a certain degree of security has been achieved. Robust auditing, thorough review, formal methods, exhaustive testing, competent red teams exercises failing to find any vulnerabilities, etc. The only people throwing their hands up claiming security can not be evaluated have nothing useful to say about security because they do not even believe it is possible to know if they did anything.
Having red teams, having audits, having scans, etc is simply not enough for some folks but in Okta’s eyes, it’s enough for C-suite talks of taking Authentication/authorization off the plate of their IT department.
I firmly believe for every individual who thinks they are untouchable, there’s a hacker who knows more and is willing to throw it all away to prove a point.
So yeah, show me a red team exercise with 10 M$ of funding, they get a 30 person hacking team and 1 year fulltime, that failed to find any vulnerabilities and failed to gain access to any sensitive data, then we can talk about if they provided evidence of adequate security. I bet all they have is what everybody else has which is red team exercises that had 3 people for a month that reported 27 serious vulnerabilities, then another red team exercise that found a different 23 vulnerabilities, then another, then another, then another, always finding new ones because their systems are actually at the 100 K$ quality level. Those exercises do provide evidence and confidence in their security, you can be extremely confident their systems are grossly inadequate for their threat landscape. I have not looked, but the same can almost certainly be said about their certifications, audits, etc. since the gold standard that everyone aspires to is, when looked at objectively, grossly inadequate.
So that they never have to pay it. Up to them to decide how to upskill their red team now.
Barring such a bug bounty, there is no way to trust them.
And you can substanciate a claim that an an online service is secure without proving it.
I mean, do you seriously think that if person A says: “My vault is secure for 15 minutes against a human with a crowbar.” And person B says “Prove it.” That person A would ever respond with: “I can not because a vault is not a mathematical object and therefore proof is impossible, but I can substantiate it.” That would be ridiculous beyond belief. That is what you are doing.
https://blog.cloudflare.com/how-cloudflare-mitigated-yet-ano...
It's the same type of session replay attack (likely HAR) discussed in the original article, no?
It seems a reasonable expectation to assume that anything sent to Okta support isn't instantly available to attackers.
So, yes, valid session tokens were dumb. But also yes, Okta fucked up here too.
No that’s not a reasonable assumption. Malicious Okta employee is just as significant an attack vector as compromised Okta support tool.
If Okta employee is a high priority threat model... then the customer is better off not using Okta.
Not that it shouldn't be considered, but if Okta top-to-bottom penetration is expected and accepted, then that's taking Zero Trust to a whole new length.
It's literally a policy from Okta to investigate issues, which isn't Cloudflare's fault. The tool from Okta got compromised and all clients that needed support from Okta could/have been damaged as well.
Additionally, it was Cloudflare that SAW something was off and notified Okta. Cloudflare didn't get breached at all.
> The root cause is that Okta got compromised.
It's even suprising that Cloudflare's policies are so good in detection that they detected this at all, before Okta.
My experience has been: start with Google until it's too painful to continue, choose between Azure AD or Okta. Self-hosting for plenty of firms is just asking for worse scenarios. Is there some market leader I'm unaware of?