this post was submitted on 20 Oct 2023
72 points (97.4% liked)

Technology

74180 readers
4140 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

Okta, a company that provides identity tools like multi-factor authentication and single sign-on to thousands of businesses, has suffered a security breach involving a compromise of its customer support unit, KrebsOnSecurity has learned.

you are viewing a single comment's thread
view the rest of the comments
[–] evanuggetpi@lemmy.nz 15 points 2 years ago (3 children)
[–] Unaware7013@kbin.social 19 points 2 years ago (2 children)

We urge Okta to consider implementing the following best practices, including:

Take any report of compromise seriously and act immediately to limit damage; in this case Okta was first notified on October 2, 2023 by BeyondTrust but the attacker still had access to their support systems at least until October 18, 2023

Holy shit, this is absolutely beyond negligent for an authentication platform.

[–] thepianistfroggollum@lemmynsfw.com 4 points 2 years ago (1 children)

They need to be raked over the coals by the FTC and class actions.

[–] Case@lemmynsfw.com 4 points 2 years ago

And as a former admin for okta (as in admin access within a enterprise) I can also say their implementation can be a pain in the ass, especially if you adopt the system after someone else was fired for, in part, screwing it up.