[HN Gopher] Cloudflare's investigation of the January 2022 Okta ...
___________________________________________________________________
Cloudflare's investigation of the January 2022 Okta compromise
Author : jgrahamc
Score : 54 points
Date : 2022-03-22 16:59 UTC (6 hours ago)
(HTM) web link (blog.cloudflare.com)
(TXT) w3m dump (blog.cloudflare.com)
| memish wrote:
| Why outsource this to Okta in the first place? Cloudflare has the
| expertise and resources to do it themselves. So why rely on a 3rd
| party.
| corobo wrote:
| https://twitter.com/eastdakota/status/1506160414106611712
|
| They didn't want to get into the market (until now?) by the
| looks of things
| SahAssar wrote:
| Selling something publicly and using it internally are two
| very different things. The parent is talking about using
| something else internally, while the tweet is talking about
| selling it publicly.
| weekay wrote:
| "We are also in contact with Okta with a number of requests for
| additional logs and information. " - is it a common practice to
| share the logs with customers ? Seems unusual .
| jgrahamc wrote:
| What we're asking for is logs corresponding to access to our
| Okta account. Not asking for something that doesn't pertain to
| us as a customer of Okta.
| ktsayed wrote:
| Matthew Prince has a lot of tweets today about how he might
| have to begrudgingly enter the IAM space given how
| disappointed he is, how serious are you guys about this?
| jeffrallen wrote:
| Cloudflare should do anything that they can do better than
| the incumbents. Which at this point seems to be just about
| everything they touch.
| jgrahamc wrote:
| What features would you like?
| Melatonic wrote:
| Better integration with other security products - Ping,
| Okta, etc all have marketing that claims they integrate
| with tons of different vendors but when you actually
| attempt to implement it often times nobody really knows
| how it works or if it works at all
| [deleted]
| tiffanyh wrote:
| I'd love if Cloudflare became a IdP.
|
| Just a thought, most people's corporate identity is
| linked to their corporate email. Cloudflare does email
| routing.
|
| Would be interesting to extend your email routing service
| to have Identity attached to it and Cloudflare is the
| Identity Provider (IdP).
| toomuchtodo wrote:
| Cloudflare Identity. Auth0 or Okta offerings but built
| and managed by Cloudflare.
|
| I do not feel comfortable sending clients to Auth0 or
| Okta, but I would be comfortable sending them to
| Cloudflare for identity services, and an engineering
| first org is better suited for providing this sort of
| critical service.
| billpg wrote:
| Since you're (probably going to be) proxying my website
| anyway, what if you intercepted /login and handled
| registration, email address validation, login-with-X,
| passwords, MFA, etc. Once you've authenticated that user,
| pass on further HTTP requests to my server but with a
| token indicating that the user is valid and some means
| for looking up information on them.
|
| I don't want to be storing user data on a machine I keep
| in my lounge next to my TV if I don't have to.
| SahAssar wrote:
| Put your resources behind keycloak or ory or similar. If
| there is demand provide a hosted version, but please
| don't just reinvent the wheel without a reason.
| ktsayed wrote:
| The clarity and communication here have been top tier
___________________________________________________________________
(page generated 2022-03-22 23:02 UTC)