This includes not only Okta but Auth0 (Okta acquired), Authy, and Duo.
This includes not only Okta but Auth0 (Okta acquired), Authy, and Duo.
1. All software has security bugs. This includes on-prem software.
2. Many IT groups do not have the expertise to run and secure a directory. You don’t just install some software, setup some accounts, and leave the box in the corner. You have to make sure the system survives disasters, you have to test backups, you have to figure how to determine if you were hacked, etc. This is very hard work.
3. No one has ever shown that on-prem IT security is better than cloud vender IT security. My experience has been that some on-prem IT departments have very poor security. Here are some examples:
- One IT department I worked with used a VPN which used an MD5 certificate. This was between 2010 and 2020. MD5 was cracked and it meant anyone could preform a man in the middle attack.
- One IT department I worked with deployed a web service which allowed unauthenticated users to access person customer information (national ID/tax number, address, name, phone number, etc.). Note the person doing this knew he was doing something unethical and did it anyway.
- One IT department I know of supples nurses with an add supported text editor to type up patient notes. Adware is not know to value privacy and should never be used to process sensitive information.
- One IT group I know of will not update Redcap to a supported version. The version of Redcap the IT department uses has known security bugs and the IT department was told about them. The official excuse for not upgrading it is the IT group does not like Redcap.
I think Redcap is a piece of software which stores information used in medical studies and used to calculate public health statistics. It contains lots of sensitive data.
My main point is moving from the cloud to on-prem may or may not improve security. It really depends on the capability of individual IT groups and many IT groups are not capable of running an identity service like Okta.
The other thing to consider is cloud venders typically have much larger budgets and can spread costs over many customers. This means they can afford more security specialists, spend more on securing systems, spend more on detecting breaches, etc.
Then there also is the question of cascading effects. E.g. if someone compromises a cloud provider and gains SSO access to Org A and Org B at the same time they might be able to do more harm
Running the same software as everyone else on-prem doesn’t make it more secure — it might even do the opposite unless you’re quick to do security updates.
And that's not 'on prem' but usually colocated hosting.
Whether it might improve security is definitely questionable. But it does limit the impact to only one org. Even if multiple orgs use the same product, the local implementations might differ and increase friction to scale the exploit over large swaths of companies.
Using Okta, every random support person at Okta is a super-admin within your organization able to grant themselves access to all of your stuff.
Sure, everyone deploying things on-prem will mean attackers will focus on the software instead of the cloud vendor. But that's A∨B vs. only B.
> - One IT department I worked with used a VPN which used an MD5 certificate. This was between 2010 and 2020. MD5 was cracked and it meant anyone could preform a man in the middle attack.
MD5's collision resistance has been broken. Corporate VPNs are often deployed by shipping the cert's pubkey on each client. In that case you're not using PKI which means the switcheroo attack involving collisions aren't relevant and you only need to rely on MD5's preimage resistance which is still ok.
So while using MD5 doesn't smell great it's not necessarily an open barn.
Source: I see this communication at (large enterprise) workplace and so many other grand cloud migration pronouncements on internet by executives of F500 companies.
You actually can write and test software on a system that never gets connected. (Shockingly true!)
I also can’t tell if it’s satire, which goes to show maybe communicating mysteriously has ran its course.
Say what you mean, mean what you say.