|
|
|
|
|
by jrockway
970 days ago
|
|
That is fascinating: > A member of the IT team was engaged with Okta support, and at their request, created a HAR
file from the Chrome Dev Tools and uploaded it to the Okta Support Portal. This HAR file
contains a record of all traffic between the browser and the Okta servers, including sensitive
information such as session cookies. In the early morning hours of Friday, Sept. 29th, an
unknown actor used the same Okta session that was used to create the HAR file to access the
Okta administrative portal Like your bank tells you, don't give the support person your password. |
|
Sure, but was the user aware what the HAR-file actually contained?
At the least all active sessions should be cleared after sharing something like that. But that hinges on you knowing about it. Support should also make it mandatory/automatic.