Skip to content
Techzine Global
  • Home
  • Topstories
  • Topics
    • Analytics
    • Applications
    • Collaboration
    • Data Management
    • Devices
    • Devops
    • Infrastructure
    • Privacy & Compliance
    • Security
  • Insights
    • All Insights
    • Agentic AI
    • Analytics
    • Cloud ERP
    • Generative AI
    • IT in Retail
    • NIS2
    • RSAC 2025 Conference
    • Security Platforms
    • SentinelOne
  • More
    • Become a partner
    • About us
    • Contact us
    • Terms and conditions
    • Privacy Policy
  • Techzine Global
  • Techzine Netherlands
  • Techzine Belgium
  • Techzine TV
  • ICTMagazine Netherlands
  • ICTMagazine Belgium
Techzine » News » Security » Months of logging in without a password at Okta
2 min Security

Months of logging in without a password at Okta

Berry ZwetsNovember 4, 2024 8:46 amNovember 4, 2024
Months of logging in without a password at Okta

For three months, the identity and access management service Okta allowed users to access accounts using only a username.

The vulnerability, which has been active since July, was identified in late October. The issue was in AD/LDAP Delegated Authentication (LDAP), a protocol for accessing stored usernames, passwords, e-mail addresses, and other data within directories. Okta uses LDAP to let users log in by accessing credentials from an organization’s Active Directory or Windows networked single sign-on system.

At least 52 characters

The vulnerability allowed three months to access accounts with user names of at least 52 characters. While this is an unusually long number, it does occur in practice. It allowed access without a password in certain situations, such as agent downtime and high network traffic.

The problem occurred in the cache key generation process, in which an algorithm hashes a combination of userID, username, and password. Retaining cached keys from previous successful login sessions allowed access with a longer username, provided the authentication request was associated with a cached key from previous sessions.

The vulnerability has since been fixed using a different algorithm for the hashing process. However, Okta recommends implementing additional security measures, such as multi-factor authentication, to prevent security problems better now and in the future.

Tip: The security platform beckons: what is it and what does it provide?

Tags:

Active Directory / authentication / Login / Okta

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

Stay tuned, subscribe!

Nieuwsbrieven*

Related

Okta hack shows how vulnerable digital authentication is

1Password suffers from Okta hack

Okta’s source code has been stolen

Okta confirms breach: up to 366 customers affected by Lapsus$

Editor picks

The AI agent presents a new identity puzzle

Agents have been given their own identity within Okta solutions. Wher...

Why etching LLMs into silicon won’t remove the biggest bottleneck

With the acquisition of Taalas, AMD has bought itself a "pioneer in s...

Tricentis acquires Tabnine: Did context-aware code quality engineering just happen?

Agentic quality engineering company Tricentis, recently acquired Tabn...

Open Secure AI Alliance shares SAFE guidelines for AI incidents

The Open Secure AI Alliance, which now comprises more than 120 organi...

Techzine.tv

SAP executive addresses API policy and openness concerns

SAP executive addresses API policy and openness concerns

Why OpenSearch doubled downloads under open governance

Why OpenSearch doubled downloads under open governance

No backdoors, no excuses: Cisco bets big on sovereign infrastructure

No backdoors, no excuses: Cisco bets big on sovereign infrastructure

How Mirantis helps neoclouds maximize GPU ROI with k0rdent AI

How Mirantis helps neoclouds maximize GPU ROI with k0rdent AI

Read more on Security

WinRAR vulnerability being exploited in ransomware attacks, CISA warns

WinRAR vulnerability being exploited in ransomware attacks, CISA warns

The U.S. Cybersecurity and Infrastructure Security Agency ( CISA) reports that the WinRAR vulnerability CVE-2...

Erik van Klinken 18 hours ago
Thousands of servers at risk due to old BMC vulnerabilities

Thousands of servers at risk due to old BMC vulnerabilities

Vulnerabilities in Baseboard Management Controllers (BMCs) pose an underestimated risk to enterprise servers....

Mels Dees 2 days ago
The AI agent presents a new identity puzzle
Top story

The AI agent presents a new identity puzzle

Agents have been given their own identity within Okta solutions. Where previously only human and machine iden...

Erik van Klinken 2 days ago
FOMO in AI: Meta also reports incident involving a hacking AI model
Top story

FOMO in AI: Meta also reports incident involving a hacking AI model

The timing of security incidents among AI players is remarkable. Following OpenAI and Anthropic, Meta has now...

Sander Almekinders 2 days ago

Expert Talks

AMD “Helios”: Building rack-scale AI Infrastructure for EMEA Enterprises

AMD “Helios”: Building rack-scale AI Infrastructure for EMEA Enterprises

AMD recently introduced the “Helios” rack-scale AI architecture, ...

Taking the right lessons from AI success stories

Taking the right lessons from AI success stories

While a lot of the current narratives around AI focus on stalled...

Why traditional security can’t protect your enterprise against AI threats

Today’s AI tools are a boon for many businesses, boosting efficienc...

Power critical workloads with all-NVMe active-active storage for non-stop enterprise operations 

Enterprise infrastructure has reached a turning point where planned d...

Tech calendar

Dreamforce

September 15, 2026 San Francisco

GOTO Copenhagen 2026

September 28, 2026 TAP1, Raffinaderivej 10, 2300 København S, Denmark

NetApp INSIGHT 2026

September 29, 2026 Las Vegas

Manhattan EMEA Exchange

October 12, 2026 Milan

Whitepapers

Experience Synology’s latest enterprise backup solution

Experience Synology’s latest enterprise backup solution

How do you ensure your company data is both secure and quickly recove...

How to choose the right Enterprise Linux platform?

How to choose the right Enterprise Linux platform?

"A Buyer's Guide to Enterprise Linux" comprehensively analyzes the mo...

Enhance your data protection strategy for 2025

The Data Protection Guide 2025 explores the essential strategies and...

Strengthen your cybersecurity with DNS best practices

The white paper "DNS Best Practices" by Infoblox presents essential g...

Techzine Global

Techzine focusses on IT professionals and business decision makers by publishing the latest IT news and background stories. The goal is to help IT professionals get acquainted with new innovative products and services, but also to offer in-depth information to help them understand products and services better.

Follow us

Twitter
LinkedIn
YouTube

© 2026 Dolphin Publications B.V.
All rights reserved.

Techzine Service

  • Become a partner
  • Advertising
  • About Us
  • Contact
  • Terms & Conditions
  • Privacy Statement