Can someone help me parse a statement I just got from Okta? I asked if the service account compromised in a recent breach was protected by MFA. The response:

"The unauthorized access to Okta’s customer support system leveraged a service account stored in the system itself. Service accounts are used for machine-to-machine functions that would be disrupted by an interactive prompt. MFA is not supported on such accounts."

Can people with experience in these sorts of environments paraphrase in plain English? How is an account "stored in the system itself" different from other sorts of accounts? Is it really not feasible to use MFA for this account?

@dangoodin MFA as a concept doesn’t translate well to system access. Something you have / know / are… all the system has access to is secrets, which can be like passwords, encryption keys, etc

Follow

@g I've always been curious whether systems with a TPM/secure enclave can use that to store a private key for use in machine-to-machine cryptographic challenge-response-type authentication. In that case, though the machine "knows" the private key in some sense, it is incapable of divulging it, making it more akin to the "something you have" or "something you are" of more traditional MFA. But I don't know enough about such things to know if this is actually possible in practice. Surely it's not a novel idea.

Sign in to participate in the conversation
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.