Okta deserves criticism for their failure, but this feels like CloudFlare punching down to shift blame for a miss on their part.
Okta deserves criticism for their failure, but this feels like CloudFlare punching down to shift blame for a miss on their part.
January 2022: https://blog.cloudflare.com/cloudflare-investigation-of-the-...
October 2023: https://blog.cloudflare.com/how-cloudflare-mitigated-yet-ano...
If anything Okta is a bigger company (by revenue, by employee count) and they were founded a year earlier.
It's fair to "punch down" imo as that's how the credentials were originally compromised. I'd agree with you if CF were trying to minimize their own mistake but that doesn't seem to be what is happening here
I don't love CF, but IMO Okta deserves to be punched down on.
Is it really reasonable to come out and say your company utterly failed a pretty basic security practice when faced with a compromise but that it was really some other company's problem originally?
Of course it's not. It's still your company's failure. Own it.