Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, but they lose competency points for sharing a HAR file with an active Okta session token.


If you have a problem and your provider asks for the active HAR file.

It seems a problem with the provider. You're problem is probably not even going to be checked without fulfilling their request.

Okta should have revoked the token after the file was no longer needed.

Should I remind you that multiple customers were compromised because of this and that Cloudflare was probably the only one that wasn't breached AND notified Okta...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: