Conversation

Michał "rysiek" Woźniak · 🇺🇦

This article by is so bad it's funny:
https://www.okta.com/identity-101/evil-twin-attack/

Not only do they bend over backwards to cram as many "hackers" there as possible (hackers are what editors crave!), but it also seems like they are not aware of HTTPS, HSTS, and how browsers warn users when credentials are being requested via unencrypted connections.

> [attacker] can see all the login details and save them for later use.

Not they can't. Stop parroting stuff that has not been true for a decade.

1
0
0

@rysiek

I thought they might bounce back as a company after the 2021 breach. But I guess the 2022 and 2023 breaches show that if there are any technically minded people left, they don't have any say in where the company is heading.

Full on short term shareholder value optimization and nobody to slow it down/make the core business work. This kind of writing just confirms it.

1
0
0

@makdaam @rysiek I can still hear the developers I was talking to in the late 2010s. "it's irresponsible to handle your own authentication! you should leave that to a company like okta instead, they have the expertise to do it safely"

2
0
0

@makdaam @rysiek (this was, of course, not accompanied by any sort of analysis of that expertise; the reasoning was "company's core business is authentication -> they must be good at it")

1
0
0

@joepie91 To be honest in most cases it was true back in 2010. There was a ton of OAuth misuse for SSO. And as far as I remember Okta addressed a lot of edge cases of that bending of the standard.

A lot of developers were ok with getting to the point when it works without checking when it works, but shouldn't.

But we're in 2026 now. We have OIDC. We have libraries for that. We have predominant TLS available to everyone.

@rysiek

1
0
0

@makdaam @rysiek nah, it wasn't true then either. people were making this argument in the context of "instead of just using a username and password".

0
0
0

@d_rift @makdaam @rysiek I *wish* they were making a liability argument, then I could at least concede that there was a purpose to their recommendation...

0
0
0

@d_rift @joepie91 @makdaam @rysiek It is a bit like not rolling your own crypto. That does not mean you should not perform your due diligence when choosing said authentication service/crypto libraries etc.

1
0
0

@whvholst @d_rift @makdaam @rysiek yet you wouldn't outsource your encryption to a third-party hosted service that has full control over your data because of this, and yet that's what people uncritically do with auth providers

1
0
0
incorrect dictionary definition
Show content

@joepie91 @whvholst @d_rift @makdaam @rysiek zero trust (noun): trusting okta as the sole party to not fuck shit up

0
1
4