HN user

adam0c

20 karma
Posts2
Comments37
View on HN

Copy / Paste from Lapsuss telegram ;)

https://www.okta.com/blog/2022/03/updated-okta-statement-on-...

I do enjoy the lies given by Okta.

1. We didn't compromise any laptop? It was a thin client.

2. "Okta detected an unsuccessful attempt to compromise the account of a customer support engineer working for a third-party provider." - I'm STILL unsure how its a unsuccessful attempt? Logged in to superuser portal with the ability to reset the Password and MFA of ~95% of clients isn't successful?

4. For a company that supports Zero-Trust. Support Engineers seem to have excessive access to Slack? 8.6k channels? (You may want to search AKIA* on your Slack, rather a bad security practice to store AWS keys in Slack channels )

5. Support engineers are also able to facilitate the resetting of passwords and MFA factors for users, but are unable to obtain those passwords. - Uhm? I hope no-one can read passwords? not just support engineers, LOL. - are you implying passwords are stored in plaintext?

6. You claim a laptop was compromised? In that case what suspicious IP addresses do you have available to report?

7. The potential impact to Okta customers is NOT limited, I'm pretty certain resetting passwords and MFA would result in complete compromise of many clients systems.

8. If you are committed to transparency how about you hire a firm such as Mandiant and PUBLISH their report? I'm sure it would be very different to your report :)

_________________________________________________________________________________________________________________________________________________________________________________________________________ https://www.okta.com/sites/default/files/2021-12/okta-securi...

21. Security Breach Management. a) Notification: In the event of a Security Breach, Okta notifies impacted customers of such Security Breach. Okta cooperates with an impacted customer’s reasonable request for information regarding such Security Breach, and Okta provides regular updates on any such Security Breach and the investigative action and corrective action(s) taken. -

But customers only found out today? Why wait this long?

9. Access Controls. Okta has in place policies, procedures, and logical controls that are designed:

b. Controls to ensure that all Okta personnel who are granted access to any Customer Data are based on leastprivilege principles;

kkkkkkkkkkkkkkk

1. Security Standards. Okta’s ISMP includes adherence to and regular testing of the key controls, systems and procedures of its ISMP to validate that they are properly implemented and effective in addressing the threats and risks identified. Such testing includes: a) Internal risk assessments; b) ISO 27001, 27002, 27017 and 27018 certifications; c) NIST guidance; and d) SOC2 Type II (or successor standard) audits annually performed by accredited third-party auditors (“Audit Report”).

I don't think storing AWS keys within Slack would comply to any of these standards?

I think this can be pretty much summed up along the lines of: way back when colour was introduced into film people wanted to show it off more, it was something magical whereas now everyone wants to be all edgy and gritty.

Or.... it's the lizard people controlling the world and making everyone miserable by using only dark grim colours?!

O.mg Cable 5 years ago

that opening line of needing a million dollar budget LOL if anyone follows @_MG_ you'll know that this has been a very long project thats really not been that expensive the dude dropped a load around defcon then hak5 came in and said hey we can charge and arm and a leg for these...

step 1: did you apply for it...? yes / no > yes: it's more than likely real, but remember with anything always go directly to the source and don't click links willy nilly.

no: then its 99.9% fake / phishing.

Surprisingly these attacks and other forms of phishing are on the rise ever since that facebook leak... coincidence? that joincidence with a c! ;)

Amazon Sidewalk 5 years ago

name one original thing apple has done that is even good, besides the original ipod? even that isn't! original

I'll also jump on the band wagon that deleting it is a bit of a bad idea as much as i hate facebook too, but if you actually read the full terms and privacy you can opt out of moat things and they only really effect you if you have other services in the "facebook company" group much like how google tracks you across everything with their ad ID it's the same with facebook. read the terms and privacy thoroughly and you'll see it's not all that bad and this is coming from a strong hater of facebook

there's a very limited amount of people around the world that actually care about this those of us do our best to not allow this to happen but then there is the others, the people that don't read terms, that live for the gram etc these are the main demographic target because they're quite simply dumb. People constantly make jokes at me for wanting to be off the grid for trying to keep a low profile etc for complaining about having to accept cookies for any website you want to use these days. data mining has been big bucks for far too long and will remain that way until the masses join us which I sadly fear they never will along with the fact that these big data companies are all working with bigger government and political groups. its been this way for a long time as others have pointed out and its a sad fact that it will remain this way for the foreseeable future unless people educate themselves on these matters because the companies getting away with it will continue to and not educate the masses as that means a loss of profit.