Okta just squashed a particularly unusual bug in its software.
The digital security management company posted a bug fix report to its website (as spotted by The Verge) letting users know that a glitch in the system that theoretically allowed bad actors to gain access to accounts had been ironed out. Sounds normal enough, right? Well, here's the kicker: The bug could've allowed someone to log into an account without entering the passwordas long as the username was 52 characters or longer.
"During specific conditions, this could allow users to authenticate by only providing the username with the stored cache key of a previous successful authentication," Okta wrote.
It should be re-emphasized that this is no longer a concern for Okta users. The bug has been fixed. Unfortunately, it existed in the system for about three months, as Okta's report said the software had been affected since July until someone noticed on Oct. 30. That's a very long time for such a vulnerability to be present, but it's unclear at this point if anyone was negatively affected by it.
Copyright © 2023 Powered by
Okta just fixed a very weird security bug for accounts with long usernames-寸地尺天网
sitemap
文章
753
浏览
93658
获赞
78485
Trudeau, Johnson, and other NATO leaders caught on video apparently gossiping about Trump
For anyone whose job is to keep a straight face around Donald Trump, dozens of private conversationsRace organizers and athletes turn to simulators amid coronavirus
For cycling world champion Annemiek van Vleuten, March usually means racing over bumpy roads in ItalGoogle Duo raises video chat limit amid coronavirus pandemic
If you're still looking for that perfect group video chat app, maybe it's time to take another lookThe case for listening to music in the shower
This is You Won't Regret It, a new weekly column featuring recommendations, tips, and unsolicited adDyson introduces air purifier that destroys formaldehyde
Remember the terrible smell in ninth-grade biology when you dissected a frog? That's formaldehyde, aHere are the worst tweets of World Emoji Day
Unfortunately, Tuesday is World Emoji Day.If the absolute curse of The Emoji Moviewasn't enough to mApple's iPhone SE (2020) is finally here and it's only $399
Apple isn't letting the coronavirus pandemic stop it from launching a new smartphone. On Wednesday,Sophie Turner looks bored sitting on a toilet in Brooklyn Beckham's cover shoot
Sophie Turner is, of course, most recognisable to us when dressed up in her Sansa Stark garb. Her laFacebook engineer quits, says company is 'profiting off hate'
A Facebook engineer has published a scathing resignation letter accusing the company of "profiting oiPhone replacement parts are in short supply and Apple's partly to blame
It seems Apple's anti-right-to-repair recalcitrance has come back to bite it.Like many companies depU.S. wireless carriers face $200 million in FCC fines for mishandling customer data
Verizon, T-Mobile, Sprint, and AT&T can definitely hear the FCC now. The nation's largest mobileApple's Magic Keyboard for iPad Pro is now available to order
You'll no longer have to wait until May to get your hands on Apple's Magic Keyboard for the iPad Pro5 Great Chrome Extensions You Should Install
With almost 60 percent share of the browser market, Chrome is around three times more popular than iGoop is finally hiring a fact
Goop — Gwyneth Paltrow's snake oil-peddling lifestyle enterprise known for its questionable "hSophie Turner looks bored sitting on a toilet in Brooklyn Beckham's cover shoot
Sophie Turner is, of course, most recognisable to us when dressed up in her Sansa Stark garb. Her la