Hacker News new | ask | show | jobs
by ethbr1 970 days ago
'Malicious Okta employee' who already has privileged access in the systems the customer has chosen to outsource their auth to?

If Okta employee is a high priority threat model... then the customer is better off not using Okta.

Not that it shouldn't be considered, but if Okta top-to-bottom penetration is expected and accepted, then that's taking Zero Trust to a whole new length.