Okta just fixed a very weird security bug for accounts with long usernames

Okta just fixed a very weird security bug for accounts with long usernames
By: Mashable Posted On: November 02, 2024 View:

Okta just squashed a particularly unusual bug in its software.

The digital security management company posted a bug fix report to its website (as spotted by The Verge) letting users know that a glitch in the system that theoretically allowed bad actors to gain access to accounts had been ironed out. Sounds normal enough, right? Well, here's the kicker: The bug could've allowed someone to log into an account without entering the password as long as the username was 52 characters or longer.

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By signing up you agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

"During specific conditions, this could allow users to authenticate by only providing the username with the stored cache key of a previous successful authentication," Okta wrote.

It should be re-emphasized that this is no longer a concern for Okta users. The bug has been fixed. Unfortunately, it existed in the system for about three months, as Okta's report said the software had been affected since July until someone noticed on Oct. 30. That's a very long time for such a vulnerability to be present, but it's unclear at this point if anyone was negatively affected by it.

Topics Cybersecurity

Read this on Mashable



Header Banner



Note: There may be some affiliate / associate links throughout the pages of this site. By buying through the links we may receive a commission for the sale. This has no effect on the price you pay.
  Contact Us
  • We would love to hear from you
  • infobuxx@allsites.zendesk.com
  Follow Us
Site Map
Get Site Map
  About

Infobuxx: Your go-to source for the latest in entertainment, health, business, politics, sports, movies, economics, and trending news. Stay informed and entertained with updates that matter!