Okta vulnerability allowed accounts with long usernames to log in without a password

In a brand new safety advisory, Okta has revealed that its system had a vulnerability that allowed folks to log into an account with out having to offer the right password. Okta bypassed password authentication if the account had a username that had 52 or extra characters. Additional, its system needed to detect a “saved cache key” of a earlier profitable authentication, which implies the account’s proprietor needed to have earlier historical past of logging in utilizing that browser. It additionally did not have an effect on organizations that require multi-factor authentication, in response to the notice the company sent to its users.

Nonetheless, a 52-character username is less complicated to guess than a random password — it might be so simple as an individual’s e mail handle that has their full title together with their group’s web site area. The corporate has admitted that the vulnerability was launched as a part of a typical replace that went out on July 23, 2024 and that it solely found (and glued) the problem on October 30. It is now advising clients who meet all the vulnerability’s situations to verify their entry log over the previous few months.

Okta offers software program that makes it simple for firms so as to add authentication providers to their software. For organizations with a number of apps, it offers customers entry to a single, unified log-in so they do not should confirm their identities for every software. The corporate did not say whether or not it is conscious of anyone who’s been affected by this particular difficulty, but it surely promised to “talk extra quickly with clients” prior to now after the menace group Lapsus$ accessed a few customers’ accounts.

Trending Merchandise

0
Add to compare
Shoprub Plastic Desktop Mobile Phone Tabletop Stand, Mobile Holder Adjustable & Foldable Mobile Stand for Mobile Phone and Tablets
0
Add to compare
349.00
46%
0
Add to compare
theKiteco. Wall Mounted Mobile Holder Storage Case for Remote, Wall Mounted Mobile Stand/Multi Purpose Stand with Hole for Phone Charging (White)
0
Add to compare
169.00
58%
0
Add to compare
CRATIX 360°Rotatable and Retractable Car Phone Holder, Rearview Mirror Phone Holder [Upgraded] Universal Phone Mount for Car Adjustable Rear View Mirror Car Mount for All Smartphones
0
Add to compare
489.00
51%
0
Add to compare
Tukzer Fully Foldable Tabletop Desktop Tablet Mobile Stand Holder – Angle & Height Adjustable for Desk, Cradle, Dock, Compatible with Smartphones & Tablets (White)
0
Add to compare
226.00
83%
0
Add to compare
Laprite, Cartoon 3D Design Protective Case for 18W 20W iPhone 14 13 12 11 Pro Max Fast Charging Cable Adapter Charger, Cute Cartoon Lightning Data Cable Case for iPhone Charger (Cute Dinosaur)
0
Add to compare
429.00
71%
0
Add to compare
Amkette iGrip Drive Compact Car Phone Holder with Quick Release Function | Strong and Durable | Silicone Base Clamp | Sticky Gel Pad | 360 Degree Rotation | Drive Assist Companion App | (Black)
0
Add to compare
699.00
42%
0
Add to compare
SKYVIK TRUHOLD StickOn Magnetic Mount Mobile or Remote Holder for Car-Bike-Scooter-Home-Kitchen-Office-Desk-(Silver)
0
Add to compare
949.00
53%
0
Add to compare
Car Phone Holder Mount, [Military-Grade Suction & Super Sturdy Base] Universal Phone Mount for Car Dashboard Windshield Air Vent Hands Free Car Phone Mount for iPhone Android All Smartphones
0
Add to compare
279.00
72%
0
Add to compare
WeCool B1 Mobile Holder for Bikes or Bike Mobile Holder for Maps and GPS Navigation, one Click Locking, Firm Gripping, Anti Shake and Stable Cradle Clamp with 360° Rotation Phone Mount
0
Add to compare
559.00
72%
.

We will be happy to hear your thoughts

Leave a reply

Tech
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart