Skip to content

Comment on Okta: “We made a mistake” delaying the Lapsus$ hack disclosure

Comments

They blatantly lied. A third-party auth provider, where trust is absolutely crucial, and they lied about being breached. Repeatedly.

And even now, they are not coming out and being honest like "we lied because we were scared about liability, but the person behethis decision has been fired". It's not good enough.

Sorry, but they have some serious work to do if they want to regain that trust. I for one, will not be using their services again.

Once again, the attempted cover up is almost always worst than the original issue. Okta could have come out and leaned into the process issues they found, how they are improving, etc... and probably walked away with increased trust. Instead, they have strung out a bad situation and look worse every day.

Looks like it is worse than that they lied. If they genuinely believed that it’s just a password reset attempt and relied on their subcontractor to investigate the incident, their security is shit.

I would posit that it is more likely than not that ALL companies lie about security and intrusions. This one will pass on into the night and is unlikely to affect the company, because security is not something most people want to think about. Passwords will not be changed, protocols will not be updated, and it will happen again.

I think this take is a little bit naive given that a lot of the customers using Okta are themselves regulated by things like healthcare records legislation, financial services regulations, GDPR, and similar. It isn't an option to not use effective security or to claim that it's somebody else's responsibility when you were holding data that has been exfiltrated illegitimately

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.