news.volyx.in

Hackers claim to have breached Okta systems (twitter.com)

1158 points by obi1kenobi · 1638 days ago · 375 comments on HN

Article summary

Hackers claim to have breached Okta systems, with potential access since at least January. The breach was reported on social media, rather than through an official notice from Okta. The incident may have significant implications for Okta's customers, as the company provides identity and access management services. The full extent of the breach is not yet clear.

Main themes

  • Okta breach
  • corporate security
  • incident response
  • security tools
  • vendor solutions
  • software diversity

What commenters say

  • Implementing intrusive security tools, such as MITMing SSL, can create more problems than it solves and may even contribute to breaches.
  • Corporate security measures should prioritize preventing breaches rather than just responding to them after they occur.
  • The use of remote management tools and reliance on vendor solutions can increase the risk of total compromise.
  • Software diversity can be beneficial, but it also increases the attack surface, making it a delicate tradeoff.
  • Some companies prioritize buying vendor solutions over developing in-house solutions, even if the latter are more effective.
  • The effectiveness of security measures is often compromised by a lack of understanding of basic security principles among security engineers and management.