I'm curious if they're rethinking being on Okta.
I'm curious if they're rethinking being on Okta.
Okta deserves criticism for their failure, but this feels like CloudFlare punching down to shift blame for a miss on their part.
January 2022: https://blog.cloudflare.com/cloudflare-investigation-of-the-...
October 2023: https://blog.cloudflare.com/how-cloudflare-mitigated-yet-ano...
It's fair to "punch down" imo as that's how the credentials were originally compromised. I'd agree with you if CF were trying to minimize their own mistake but that doesn't seem to be what is happening here
I don't love CF, but IMO Okta deserves to be punched down on.
Is it really reasonable to come out and say your company utterly failed a pretty basic security practice when faced with a compromise but that it was really some other company's problem originally?
Of course it's not. It's still your company's failure. Own it.
If anything Okta is a bigger company (by revenue, by employee count) and they were founded a year earlier.
I am grandfathered in to an old MacBook that has absolutely no management software on it, from the “Early Days” when there was no IT and we just got brand new untouched laptops.
They offered me an upgrade to an M1/M2 pro, but I refused, saying that I wasn’t willing to use Okta’s login system if I have my own personal passwords or keys anywhere on my work computer.
Since that would hugely disrupt my work, I can’t upgrade. Maybe I can use incidents like this to justify my beliefs to the IT department…
* personal ChatGPT and copilot subscriptions, since company doesn’t pay for these
* Trello account for keeping track of my todo list (following up with people, running deploys)
* Obsidian for keeping notes, as a personal knowledge-base (things like technologies and reminders)
* Apple account for music, copy/paste, sharing photos from my travel with coworkers, synching docs related to my work visa and taxes
* Personal slack login for communicating with my partner in our private server
* personal GitHub account credentials for synching my private dotfiles repo with my neovim config. basically can’t work without my dotfiles, but I could theoretically email these to myself or something, to prevent this one.
And sure, I could be stubborn and not use any of this, but I’d be way less productive and kinda miserable.
Does your workplace restrict you from bringing it in?
I’m fine with it because I know there’s no management software on this laptop, but yeah it’s a totally different story if I had to use a newer one with SSO and management software
At least that's how it works in the vast majority of companies.
It’s really easy to say ‘don’t use your personal stuff at work’, but when work is some locked-down behemoth whose view of productivity software is ‘just use Office’, and you’re really trying to be better at your job, using your own tools can be the only solution.
And in my situation, yeah, they didn’t want you bringing things in. I worked in a secure area.
Finding solutions to work around the systems, on your own time and dime, only hurts in the long run.
They think everything is fine. Nothing will ever get fixed. Voice these concerns.
You might feel a sense of social obligation or solidarity with the company. I usually do. But if I was placed in a dehumanizing situation like that – forced to work inefficiently due to overly rigid policies that assume everyone’s needs are the same – well, whether I worked around it or not, my empathy for the company would be at a nadir whenever I thought about it.
The tools are the tools. There’s nothing me or my boss or theirs can do about it.
They just don’t care. But I care, because if nothing else it’s my reputation.
(HP used purely for size comparison. I’ve never worked there.)
Just because the org that hires you is a shambles doesn’t mean you give up and quit. Thank fuck we don’t all think like that.
And, again, reputation. I have a stellar reputation because I stick it out, and I care. I’ve worked with people who quit because ‘it’s shit here’. Nobody will ever work with them again.
So why raise the point in the first place if it's a minor quibble relative to your top priority(s)?
Tools enable success. Better tools make the job easier. They make the result better.
But having bad tools isn’t a reason to give up. It’s frustrating. But you just have to get on with it.
* Stack Overflow
* Job Search sites
I don't remember if Jetbrains needs a password to get to personal licenses, but they definitely do to use their bug database. I suspect they're not the only one.
Letting other people blow off steam can be an act of self-preservation. Insisting that people only ever do 100% work things at work or on work hardware slightly raises your low-but-never-zero chances of being murdered by coworkers. Or less ironically, hilariously intense bridge-burning activities.
Also most of this conversation is happening during work hours so I think we can infer that grandparent is being a little hypocritical.
I’m now understanding how people get sued when going from company to company.
> personal Obsidian for keeping meeting notes, and recording conversations as a personal knowledge-base
I'm not a lawyer, but I'm pretty sure these could subject a lot of your other personal data to potential subpoena should your employer get sued by a sufficiently determined attacker.
Don't cross the streams.
> Obsidian is free for personal and non-profit use. However, if you use Obsidian for work-related activities that generate revenue in a company with two or more people, you must purchase a commercial license for each user. Non-profit organizations are exempt from this requirement.
> Q3. Can I buy a license for myself, or do I have to ask my company to buy it for me? > Yes, you can buy a license for yourself; just put your name in the company > field. You can use such a license to work for any company.
https://help.obsidian.md/Licenses+and+payment/Commercial+lic...
You are making your work take on an extraordinary risk in hiring you.
My notes are text files on the computer, so we’d have problems regardless if they got that. But maybe I should’ve left it out of the list above in that case… nothing else seems very damning.
But you do raise a valid concern, and it’s worth reevaluating!
Also, people just do things for convenience. (Although I tend to pipe these passwords over an SSH connection, so that they're not resident on the work laptop. Though there is a good argument to be had about me permitting my work laptop SSH access to my personal laptop. From a technical standpoint, my employer could hack/compromise my personal laptop. From a legal and trust standpoint, I presume they won't.)
Absolutely none of my personal stuff ever touches a corporate machine. Ever. I wouldn't even log in to the W2 downloading app as an employee from the work machine.
Granting work ssh keys access to your personal machine is crazy; if your work machine gets compromised, they steal your entire personal system's home directory too. Why would you unnecessarily expand the blast radius of a compromise like this?
GP said nothing of the sort.
You wouldn’t keylog “random devs”, you’d keylog all of the ones doing ops.
You trust all personnel with access to your employers network?
What's more surprising is that they trust you to setup adhoc ssh connections to arbitrary endpoints; unless you're the person in charge of network security?
Would anyone notice if you, or an intruder, dumped terabytes of data over that connection?
I don't work in IT but this just doesn't feel right to me.
Well... don't do that? Why would you ever have personal anything on a work computer?
(& then just rotate the credentials on it when you part ways with the employer.)
Some of my co-workers even do a Github account per employment.
I just don’t understand any rational otherwise.
So, would you care to more explicitly tell me what you think about my intelligence or ability to behave rationally compared to you? Or is there potentially some room for nuance here?
- people tend to use company devices for private stuff, even when its explicitly prohibited, - draconian policing leads to employee dissatisfaction; you won't be able to fire that great engineer you spent 3 months hiring because he logged in to Spotify running within Chrome, and if you can - and do - soon you will be unable to hire top talent,
Thus, even with those policies in place, end user devices still need to be considered un-trusted. Specifically, that they can be key-logged and remote accessed by the attackers.
Hence, (a) anything sensitive should involve transaction level validation, not just end user authentication, (b) for logging in an out, as well as for confirming sensitive operations, proper MFA needs to be in place (physical key + token on a mobile device, for instance), (c) apply lightweight, reasonable restrictions to reduce the chances of device compromise dramatically (e.g., no downloading of 3rd party apps or binaries - but do whitelist things like Skype or Spotify, force strong password for devices, etc).
This means reasonable personal use is perfectly fine, employees happy, and you are safer vs. assuming local devices are clean.
A more senior academic?
- Is the open-source software something that the company is sponsoring?
- If not, do you have permission to use company equipment for personal use?
> A more senior academic?
?
Do you do the above? If so, do you have a personal laptop? if yes, why utilize company property instead of personal, unless given permission to do so?
An example university policy [1]
> 11.5 reasonable personal use of College IT resources is permitted provided such use does not disrupt the conduct of College business or other users. Recreational use of the Halls of Residence network is also permitted, subject to these conditions;
We have a similar policy where I work. I have a personal laptop, but I don't take it to work. I am signed in to my personal GMail account on my work computer, along with many other accounts — like this HN account. If work needed to look at an employee's computer, we'd have someone from IT + someone from HR overseeing the process, and wouldn't look at anything clearly private, e.g. a personal email account. Doing otherwise would be a breach of the GDPR.
[1] https://www.imperial.ac.uk/admin-services/ict/self-service/c...
I'm sure there are plenty of people who have access to their company's private repos through their personal GitHub accounts.
No thanks. New account per job.
Even if a tiny risk, it seems silly just to bolster the GH activity graph.
Involvement with private repositories is removed as soon as the organization removes the employee, or the employee removes themselves.
I think the horror stories could only happen if the individual's account has been used for generating many API keys or similar, but there are other reasons not to rely on that sort of thing.
I think this is fairly common for people who work on open source projects.
Okta doesn't make device management software, thats made by companies like Jamf. Okta can integrate with them but Okta isn't what manages your laptop at all.
> I wasn’t willing to use Okta’s login system if I have my own personal passwords or keys anywhere on my work computer.
Do not do this, its not a personal device.
You think nobody's logged into their personal spotify on their work computer? All those guys wearing headphones in the office have brought in CDs to play in their laptop CD drives?
And that business traveller away from their partner and kids for a week+ isn't going to video call them? Or watch some netflix in their hotel room in the evening?
That's so unrealistic, you could write IT security policy for a Fortune 100 company :)
Even companies with these policies preinstall Spotify on work computers.
I refuse to carry more than one phone or one laptop, and I sure ain’t brining a personal device into a country I wouldnt go to on vacation.
Footgun, but maybe tolerable with your chosen threat model.
Why would I use a device to do personal things that they MITM everything I do on it? Privacy is too important to me to give it away like that. I'm sure all traffic on the corporate network is logged. Why open myself up for grounds for termination if my company hits hard times and wants to lay people off?
It was a public case, but the essentially unanimous Supreme Court opinion in City of Ontario v. Quon [0, 2010] shows what expectations of privacy you should have on any work devices -- none.
Reasonable or limited private use of a work computer remains private.
https://edps.europa.eu/data-protection/data-protection/refer...
Been in the industry for a while now, no one cares if you pull out your phone. Generally, people treat others like adults not children.
I've worked for large media companies where this is exactly the only way to have music available. The production network was blocked from accessing the www. To ensure content wasn't pirated, the original media had to be used. No CD-Rs were allowed. Personal devices were kept in lockers outside the restricted areas, so no streaming from them either.
Email was from a remote session. If you were emailed an attachment necessary for production work, there was an approved workflow to scan the data and then make it available to the production network.
So, while you were trying to be sarcastic, there are networks that are set up exactly like you thought didn't exist because it was too outlandish.
I don't think anyone thinks that. No one also thinks logging into a personal account on a device owned by someone else gives you any claim of ownership over it.
The computer belongs to the company. You will do what the company says you need to with their computer.
Agreed, but I knew many devs in my career who mix personal stuff into work hardware. Maybe its just spotify/pandora, maybe some HR thing they needed their personal gmail to make it easier.
This included "senior" and other levels, it isn't just ppl out of college.
They are using zero trust and explained that it's why the scope of the security incident was extremely limited.
I wouldn't be surprised if they are working on first party IAM user support though.
For example, if Slack devops team were to exclusively communicate over Slack, then a Slack outage would be much harder to resolve because the team trying to fix it would be unable to communicate.