Can someone help me parse a statement I just got from Okta? I asked if the service account compromised in a recent breach was protected by MFA. The response:
"The unauthorized access to Okta’s customer support system leveraged a service account stored in the system itself. Service accounts are used for machine-to-machine functions that would be disrupted by an interactive prompt. MFA is not supported on such accounts."
Can people with experience in these sorts of environments paraphrase in plain English? How is an account "stored in the system itself" different from other sorts of accounts? Is it really not feasible to use MFA for this account?
@g I've always been curious whether systems with a TPM/secure enclave can use that to store a private key for use in machine-to-machine cryptographic challenge-response-type authentication. In that case, though the machine "knows" the private key in some sense, it is incapable of divulging it, making it more akin to the "something you have" or "something you are" of more traditional MFA. But I don't know enough about such things to know if this is actually possible in practice. Surely it's not a novel idea.