back

by toddmorey·2y ago·view on hn ↗
I feel like it will bounce back... this breach was the support case management system, separate from the production Okta service. Still embarrassing for sure, still risk of confidential info exposed, but doesn't seem to impact core infrastructure.
1 comments
Apparently customers upload HTTP archive files to the support system which can include session tokens for their actual systems.

So it allows attackers to compromise Okta's customers core infrastructure.