Hacker News new | ask | show | jobs
by toddmorey 975 days ago
I feel like it will bounce back... this breach was the support case management system, separate from the production Okta service. Still embarrassing for sure, still risk of confidential info exposed, but doesn't seem to impact core infrastructure.
1 comments

Apparently customers upload HTTP archive files to the support system which can include session tokens for their actual systems.

So it allows attackers to compromise Okta's customers core infrastructure.