Connect with us

Hi, what are you looking for?

Tech News

An Okta login bug bypassed checking passwords on some long usernames

Illustration by Cath Virginia / The Verge | Photo from Getty Images

On Friday evening, Okta posted an odd update to its list of security advisories. The latest entry reveals that under specific circumstances, someone could’ve logged in by entering anything for a password, but only if the account’s username had over 52 characters.

According to the note people reported receiving, other requirements to exploit the vulnerability included Okta checking the cache from a previous successful login, and that an organization’s authentication policy didn’t add extra conditions like requiring multi-factor authentication (MFA).

Here are the details that are currently available:

On October 30, 2024, a vulnerability was internally identified in generating the cache key for AD/LDAP DelAuth. The Bcrypt algorithm was…

Continue reading…

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

Investing

Sarama Resources Ltd. (“Sarama” or the “Company”) (ASX:SRR, TSX- V:SWA) is a Canadian-incorporated mineral exploration and development company whose principal business objective is to...

Politics

As President Biden meets with Chinese President Xi Jinping on Wednesday, the House select committee examining the United States’ relationship with China is set...

Stock

Shopify (SHOP) share value jumped by over 20% Thursday morning after stunning analysts with a sharp earnings beat and rosy guidance. The stock reached...

Politics

In the weeks after the 2020 election, an obscure Republican lawmaker from Louisiana led a congressional effort to overturn the presidential results in four...