Okta admits hackers accessed data on all customers during recent breach
techcrunch.com
techcrunch.com
How is it difficult to get web application authentication wrong at this point? It’s super well tread territory. Add your spices, a sprinkle of cookie crumbs, a token here or there, and then 2 hours in the oven and you’re done!
And that’s rolling it entirely by hand. Most web frameworks have middleware that get you going in minutes.
Adding a log in to an app is no big deal but there are more complex scenarios to consider. Maybe single auth to multiple services, SSO, 2FA, OTP, Oauth, etc.
Implementing an auth flow to specification isn't trivial at all and that is a problem. Authn and authz get mixed up, people not checking tokens or their expiration, etc pp. There is probably a minefield of security issues here and some of those come to be because it is too complicated.
Sure, there is middleware with sensible service integration, but you still need to do a lot of legwork in any case.
It's not a satisfying answer, but none of this will change until the public feels so strongly about this problem they become single-issue voters electing legislators to pass radically different laws.
MSPs have to be one of the juiciest targets, and recent history would indicate that they are.
https://www.bleepingcomputer.com/news/security/heroku-admits...
https://therecord.media/managed-service-providers-cyberattac...
https://darknetdiaries.com/transcript/103/
> This is an interesting story since the threat actor targeted MSPs to go after their customers and then carry out their objectives from there. MSPs are pretty common. More and more companies are outsourcing their IT infrastructure, so to target them makes a lot of sense if your goal is to steal intellectual property. It’s sort of like going after the janitor’s key ring which can get you access into many buildings in town.
Auth companies will always be a high value target for state-sponsored espionage.
If you're talking about orgs that don't have a dev team and buy everything off the shelf / through SaaS... well, this is unfortunately part of the risk those orgs run. If you're manufacturing and shipping widgets in boxes, and your box supplier starts using cheaper materials that don't hold up to shipping, the only option is to switch box providers. Same here - if you're org relies on an IAM tool to allow employees to log into SaaS or other hosted software platforms and the IAM leaks data, the only real options are to switch providers or work with the existing provider to fix the damage.
Why not write your own OS? Then you can control the vulns!
Why not design your own hardware? You can secure the hardware comms channels better.
Why not invent your own coding language? You can ensure it's written with zero vulns.
Why not invent a new base-30 numbering system? With out extra efforts, they can't even read your excel spreadsheets!
Your solution works in a select few companies that have monster dev farms, but everyone else cannot implement this and it's silly to tout it as a solution.
There are zero perfect solutions.
The way we do this in the real world, is patch, read up on vulns that might affect us, monitor, control access, and audit.
It's still not perfect, since nothing is, but in 30+ years of managing Healthcare IT and being senior technical, I've had exactly 1 breach and she did it with pencil and paper, at an HIS workstation, who's job is to look at many medical records, daily.
Your Mileage Will Vary.