Okta says hackers stole data for all customer support users
bloomberg.com
bloomberg.com
There are a multitude of challenges in running any non-profit, but one that provides higher-touch services like an IdP to other businesses has some particular challenges. With something like Let’s Encrypt, there exists a single set of standards being implemented, and if you don’t like those standards and the way they’re implemented you walk away.
With an IdP, there is a huge amount of ongoing support you have to provide to users. “Why is the ‘aud’ attribute not making it through to this one application?” “Why did my directory sync suddenly stop working and the logs are blank?” and so on.
You would end up effectively needing to run a privately funded foundation, and that would require the political desire within businesses to fund and operate it.
Or do you want to see this as a privately funded enterprise?
Turnkey is harder than you think, though, because authentication, while undifferentiated in general, does get tied up in business logic. A multi-tenant B2C SaaS has different needs than B2B on-prem deployed software, to name just two use cases.
Source: I work for FusionAuth, an auth provider.
One world is based on skill, facts and deliverables. That's the world you're talking about.
Another one is based on bullshit, nepotism and politics. That's the world in which Okta thrives, alongside large consultancies, etc.
Unfortunately your success in the first world doesn't really negate that the second world is also very lucrative, and might be easier to succeed in as long as you don't have much morals.
I have this idea in my head that a cybersecurity company should have more resources than I have to keep things locked up right as a drum? Appearantly not, Okta thinks they can run their company like they’re a school district or startup and thinks they aren’t risking killing the golden goose? One error they made could have been prevented by applying a security standard to Google Chrome… that’s not hard to do or very sophisticated even.
https://openid.net/wg/connect/
How does OpenID Connect improve security
Public-key-encryption-based authentication frameworks like OpenID Connect (and its predecessors) globally increase the security of the whole Internet by putting the responsibility for user identity verification in the hands of the most expert service providers.
...Who will they replace Okta with? Everyone in security space worth mentioning has been breached - including nation-state agencies.
> Why not just use Microsoft or Google for this...
Didn't Microsoft recently have an egregious security lapse on Azure?
And Google is trying to push their identity products, but they are very far from being mature enough for enterprise needs.
I generally suspect folks making comments like this are really not familiar with the products and their uses.
Most of the folks we see are moving from Firebase rather than Google Identity Platform. Wait, I'm confused. Are they the same thing? https://cloud.google.com/identity-platform/docs/sign-in-user... uses them interchangeably.
Ah, another search turns up https://cloud.google.com/identity-platform/docs/product-comp...
So Firebase auth is built on Google Identity Platform.
I did consult other groups using Google Identity Platform at our company and some things came up:
* SMS / email templates not customizable
* Undocumented user auth rate limiting with hacky workarounds
Otherwise our devs have been quite happy with it. I've primarily settled on it because it already has approval at our org, it's simple, and fairly well documented - especially compared to something like Cognito.> I've primarily settled on it because it already has approval at our org, it's simple, and fairly well documented
Those are great reasons to select a product. If it works for you, it works for you!
> especially compared to something like Cognito.
I was half expecting a new CIAM solution from AWS at Re:Invent. I don't understand why they don't invest more in Cognito. Such an own-goal.
When I read through the details of Microsoft's hacks, it will be talking about some obscure exploit against the security professional that had a background check done of them who uses hardened locked down secure access workstation to do their tasks
https://arstechnica.com/security/2023/09/hack-of-a-microsoft...
There is a difference in the degree of egregiousness. I doubt the average business has better security practices than Microsoft, whereas I'd be pretty confident saying many businesses have better security practices than Okta. What shocks me about Okta's breaches is how easy they would be to prevent from happening if Okta cared just a little.
Auth companies will always be a high value target for state-sponsored espionage.
1.TFA
I can see the retraction already: "We have run a fully unfiltered scan, as opposed to a regular unfiltered scan, and it turns out we released the full age, name, address, and DNA sequence of every customer support user."
Source: Most breaches.
When an established company -- with something to lose; not a disposable serial startup -- outsources some IT function to a SaaS/PaaS/vendor that exhibits a pattern of problems, and then the company then gets bit by such a problem, how often does the company actually care?
Does the CTO or CISO take a hit? Do the CEO and board even know that it was a bad selection from the start?
Does the company just want to be able to say it was a "partner" who was at fault (even if the company was negligent in trusting that partner)?
Every time you suggest anything remotely complicated (that your average sysadmin could and did run a decade ago without making a fuss about it) such as running Keycloak or other $ON_PREM_SOFTWARE_PACKAGE is immediately met with lots of hostility. Of course the cloud companies and other SaaS vendors love this.
It's quite puzzling - one one hand it's encouraged to build overcomplicated FAANG-wannabe engineering playgrounds full of microservices, yet a fairly mundane task of "run this self-contained piece of open-source software, monitor logs and apply reasonable security principles" (that every company did till a decade ago) is now considered out of range of mere mortals.
The table isn't on this post.
It's unfortunate Auth0 was acquired by them. Have used it from the beginning and it used to be a great product before the Okta acq. Now it's just constant sales emails, expensive pricing, not much new feature launches, most features are very enterprise focused, bunch of bugs, frequent outages.
At this point, one could speculate they are not worth almost at all given they fail to deliver on their primary value proposition. They are not and have not been profitable either, only getting worse: https://finance.yahoo.com/quote/OKTA/financials?p=OKTA
I’m just wondering who in the industry is still stupid enough to stick their neck out for Okta? Why are they getting new customers? Why not go with the other devil you know your cloud provider to offer mostly the same services? What is Okta offering when they seem relatively incompetent compared to the competition that often offers their products for cheaper up front?
But self hosting is non-trivial. You have to deal with DNS, TLS certificates, configuring Keycloak, data backups, and redundancy.
I set it up once so I could evaluate it. I may yet choose to self host but I'm not under any illusions that it's easier than paying for a service.
Edit: Elest will do it, https://elest.io/open-source/authentik
https://www.okta.com/blog/2022/04/okta-concludes-its-investi...
https://www.okta.com/blog/2022/03/oktas-investigation-of-the...
> Today we are sharing new information that potentially impacts the security of our customers
Maybe in another month they will conclude whether or not that “potentially” is a yes or no.
The Lapsus$ compromise in 2022 was a third-party IT subcontractor getting their spy-on-the-employees RDP popped, and then Lapsus$ using incredibly limited access to the Okta admin tool to take some screenshots of support dashboards. Honestly it could have been spun into a "hey, our defense in depth pretty much worked!" story.
Then, the most recent issue was an employee's third-party password manager getting compromised, allowing an attacker to log in to the support ticket tracker, which happened to contain HAR files with creds in them as well as details on support contacts. I bet a lot of enterprises are vulnerable to this, the HAR file thing is actually a great lesson in a highly unexpected threat vector. But somehow Okta have managed to turn it into a months-long top-of-the-news cycle incident, first by denying the compromise happened at all and then by underplaying the access the threat actor had to the support ticket tracker.
It's the same reason most news stories are shit today. They aren't about conveying information or educating anyone about events in the world.
They are clickbait garbage, meant solely to drive traffic in for Ad revenue and in recent history, they are slanted based on a bias that the owner wants, not any sort of factual, unbiased reporting that one may have erroneously expected from the 4th Estate.
What a shit world humans have created.
https://marketplace.atlassian.com/apps/1232593/securely-for-...
If anyone else is interested: https://github.com/cloudflare/har-sanitizer/blob/main/src/li... is the scrubbing logic for cloudflare.
Unfortunately, this scrubber would be problematic for Okta staff (or staff for any other authentication provider support team) because when someone is having issues with logging in, you need to examine Authorization and other authentication headers and data.
So I think the best course is to:
* caution users to not send production data, but rather to set up a test system and share the HAR file from that
* make sure you do defense in depth and lock down access to support tickets
* remove HAR files from closed support tickets. Here's a zendesk article about that: https://support.zendesk.com/hc/en-us/community/posts/6185912...
[0] https://www.bleepingcomputer.com/news/security/auth0-warns-t...
The downside I ran into is that it doesn't support SAML SSO. It is only OAuth, OpenID Connect, and JWT.
Also, sharding user records into Cognito pools was a bit frustrating. Hopefully AWS has invested in fixing these issues.
Okta's whole value prop was that they do it "right"... Oops.
Our UI is native to your website (no redirects) and the auth logic sits within your backend api layer - giving you a lot more control
Okta is nuts. 5th time in two years. Who the F*** is running that place?
I agree completely, except with the obvious stipulation that Google seems to be only SaaS and thus extremely high-value target, but Google's security has always been top notch and you can tell they actually care.
Ping Identity seems to be doing pretty well (now owned by Thoma Bravo) and haven't heard of any publicly disclosed leaks.
LastPass has had several well-publicized breaches recently, though.
It's an open-source IAM solution. It offers a cloud-based SaaS option and can also be downloaded for self-hosting. You can try the hosted cloud version for free - https://zitadel.com/signin
It provides:
- authentication and authorization capabilities (including SSO, IdP Federation)
- auditing
- custom extensions
- support for standards such as OIDC/OAuth/SAML/LDAP
- full API support
- various authorization strategies, including Role-Based Access Control (RBAC) and Delegated Access, making it a great choice for both B2C and B2B scenarios.
It mostly aims to ensure ease of operation and scalability (users love the simplicity). The community and team actively contribute towards development and support.
You can download it and host it yourself - https://zitadel.com/docs/self-hosting/deploy/overview
Github- https://github.com/zitadel/zitadel
Case studies and testimonials - https://zitadel.com/blog/tags/successstory
In this case, introducing a third-party doesn't help. You can still screw up the integration (or merely configuration - a general-purpose IdP has lots of features that may not apply to your use-case, yet misconfiguring them could leave a large security hole without even realizing it), and you are still on the hook for security regardless (if your app is vulnerable, it doesn't matter how secure the IdP is as they can just bypass it).
We're a commercial offering with self-hosted and SaaS options. I don't have a ton of insight into your needs, but it is a solid, well documented external authentication system.
We have a free option available here: https://fusionauth.io/download or you can pay us for premium features, hosting or support.
Those discussions feel stranger by the day
Not easy to fake that one. I guess you could have a shitty coalfire assesor
Hackers claim to have breached Okta systems (March 22, 2022)
https://www.oxebridge.com/emma/okta-breach-occurred-while-co...
I know Chris is a very controversial personality in the ISO ecosystem, but he's also got a disturbing habit of being right an awful lot of the time. I'd feel a lot more comfortable if someone could show me how he's just another crank.
(Obviously you should always lock your screen when you step away from your workstation... but people seem pretty bad about that. At my last in-person job, I don't think anyone ever locked their screen when stepping away. So that's what makes this something I would worry about.)
Yikes.
Will security companies release enterprise one-use email address products like Apple’s “Hide My Email?”
Hide My Email generates unique, random email addresses that automatically forward to your personal inbox. Each address is unique to you. You can read and respond directly to emails sent to these addresses and your personal email address is kept private.
Why are companies not running something like keycloak [1] themselves? Are administrative/maintenance costs too high or is it plausible deniability?
But when it's not being upgrade, it's fantastic. Many thanks to Red Hat.
I wonder how many of the commenters run a 30k+ users company IT Dept or are the CISO of such a company.
Well, everything is not a 2 years old startup with a Typescript stack on Postgres. Sometimes you have plenty of legacy systems, on prem services and a budget/headcount that allows you to go only that far by yourself.
Or an Exchange system basically abandoned by MS, so you either go for some roundcube install or M365.
Not all of your IT teams are either incompetent idiots, or psychopaths looking at making your life difficult. Sometimes they need to optimize and you see this optimization as idiotic while it may make sense in average.
Sure, I would prefer to have genius SaaS companies that provide a service that is fantastic, or just host Internet myself but sometimes it is not possible and you choose the least bad of the bad.
While Okta seems to have a number of issues, they don't represent all companies handling access management.
Am I missing something, some magic other than sales and gullible pm's?
We should stop saying $X is too hard and start, at least, trying to help more folk realize it can be done in house.
It all started when it became "too much trouble to host your own email" and then all the centralization and vendorification happened...and stay off my lawn!
It's outsourcing risk. Auth is hard, we all know it (yes, it is hard), and it's cheaper to outsource to a company who has it as their core competency, than hire internal experts.
I’m not sure why it comes across as unusual for wanting to outsource a service that is incredibly easy to get wrong to someone whose core focus is getting that right.
Unfortunately Okta seems too eager to downplay these incidents, but that doesn’t mean all authentication services are equally flawed.