Hacker News new | ask | show | jobs
by lolinder 969 days ago
I'm not a lawyer, but I don't think that hiring a SaaS provider shields you from any liability that you would otherwise be subject to. If 1Password were to suffer a massive data breach as a result of this, historical precedent says that there'd be no liability anyway, but if there were liability I can't see them getting out of it by blaming Okta.
1 comments

Yah, this is why third party risk management is a thing. When I ran sec training, I always hammered home the point that a third party security issue is your issue.

Now, sure, technically there may be circumstances when you can technically/legally shift liability. But your customers don't care - they have the relationship with you. So the third parties problems, are your problems.