7 ms·
Yep. All these standards are tick boxing for liability. Nothing more. They are not effective security controls and never will be and should never be a measure
by hughrr 4y ago
Yep. All these standards are tick boxing for liability. Nothing more.
They are not effective security controls and never will be and should never be a measure of that.
- disillusioned 4y agoI don't know if tick boxing was a spoonerism or intentional or a real thing but I love it and am stealing it. (Upon further review, it appears to be the more UK way of saying it! Ha!)
- hughrr 4y agoYep UK here. Normal here :)
- dvtrn 4y agoWe’ve been monitoring this internally, as customers of an Okta-like service. I’ve also been closely monitoring the responses from our CTO and VP of Security when someone from our DevOps team posted a link to the Verge article in slack this morning. Which brings me to this inquiry: How are your orgs responding to this? We have a dependency on an Okta-like provider and my first thought when reading this news was “you know, wonder if we should give our shit a sanity check”, and someone beat me to this, proposed it in slack but the idea was turned down by our SecOps team.
- hughrr 4y agoSounds about right. Here there will be a staff security training symposium that runs everyone through a training course bought in from the lowest bidder that is tangentially related to the issue followed by a self-congratulatory management meeting and that will be the whole issue resolved to satisfaction.
- lurker91283 4y agoI moved over to Azure AD this morning (we only have a few devs and were already using Azure DevOps so this was doable). I requested that Okta cancel our account and let them know the reason was the potential data breach and their CEO's response on Twitter. Okta's response was that we signed an MSA agreement and that cancelling isn't an option, nor termination of fees.
- hughrr 4y agoThey sound like they're running the organisation like a dating site. More reasons to look elsewhere.
- droopyEyelids 4y agoOkta is the Oracle of identity management. https://auth0.com https://auth0.com is the "still cares about customers" vendor I'm not affiliated with them, just traumatized by working in IT
- haneefmubarak 4y agoAuth0 was acquired by Okta (https://auth0.com/blog/okta-acquisition-announcement/ https://auth0.com/blog/okta-acquisition-announcement/), although Okta claims in the post that > There is no impact to Auth0 customers, and there is no impact to HIPAA and FedRAMP customers.
- Hawxy 4y agoAuth0 is run as an isolated subsidiary in its own infrastructure, with the old CEO still overseeing operations. Due to the massive difference in Okta & Auth0's implementations I don't see that changing anytime soon.
- stefan_ 4y agoAnd yet Okta is the ultimate in box-ticking technology. They are bought to tick the boxes. So what happens now that the box tickers are not ticking the boxes?
- hughrr 4y agoUsually a mass exodus to a similar service with the same guarantees resulting in months of capacity problems as they try and scale out from customer influx. There are no winners.
- Spooky23 4y agoThey aren’t security controls at all. Just puffery. I’d look at stuff like FedRAMP as a starting point for the control environment and explore further.