Skip to content
Techzine Global
  • Home
  • Topstories
  • Topics
    • Analytics
    • Applications
    • Collaboration
    • Data Management
    • Devices
    • Devops
    • Infrastructure
    • Privacy & Compliance
    • Security
  • Insights
    • All Insights
    • Agentic AI
    • Analytics
    • Cloud ERP
    • Generative AI
    • IT in Retail
    • NIS2
    • RSAC 2025 Conference
    • Security Platforms
    • SentinelOne
  • More
    • Become a partner
    • About us
    • Contact us
    • Terms and conditions
    • Privacy Policy
  • Techzine Global
  • Techzine Netherlands
  • Techzine Belgium
  • Techzine TV
  • ICTMagazine Netherlands
  • ICTMagazine Belgium
Techzine » News » Security » Months of logging in without a password at Okta
2 min Security

Months of logging in without a password at Okta

Berry ZwetsNovember 4, 2024 8:46 amNovember 4, 2024
Months of logging in without a password at Okta

For three months, the identity and access management service Okta allowed users to access accounts using only a username.

The vulnerability, which has been active since July, was identified in late October. The issue was in AD/LDAP Delegated Authentication (LDAP), a protocol for accessing stored usernames, passwords, e-mail addresses, and other data within directories. Okta uses LDAP to let users log in by accessing credentials from an organization’s Active Directory or Windows networked single sign-on system.

At least 52 characters

The vulnerability allowed three months to access accounts with user names of at least 52 characters. While this is an unusually long number, it does occur in practice. It allowed access without a password in certain situations, such as agent downtime and high network traffic.

The problem occurred in the cache key generation process, in which an algorithm hashes a combination of userID, username, and password. Retaining cached keys from previous successful login sessions allowed access with a longer username, provided the authentication request was associated with a cached key from previous sessions.

The vulnerability has since been fixed using a different algorithm for the hashing process. However, Okta recommends implementing additional security measures, such as multi-factor authentication, to prevent security problems better now and in the future.

Tip: The security platform beckons: what is it and what does it provide?

Tags:

Active Directory / authentication / Login / Okta

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

Stay tuned, subscribe!

Nieuwsbrieven*

Related

Traditional login with username and password disappears on Outlook

Okta hack shows how vulnerable digital authentication is

Zoom and Okta bring additional security to meetings

AuthID integrates Human Factor Authentication with Okta cloud

Editor picks

Neurometric AI & LumaDock aim to slash OpenClaw inference costs 

Neurometric AI is the inference orchestration company behind ClawPack...

Hackers easily bypass ChatGPT’s guardrails and make it create a lot of malware

ChatGPT does whatever the hacker wants after manipulation

Claude’s creator Anthropic overtakes OpenAI at the IPO game

The first IPO of an AI model developer is imminent. Anthropic, the co...

QuiX Quantum drives control tools for Photonic Quantum era

Netherlands-headquartered photonic quantum computing hardware company...

Techzine.tv

SAP executive addresses API policy and openness concerns

SAP executive addresses API policy and openness concerns

Buying GPUs doesn't deliver AI value, according to AWS

Buying GPUs doesn't deliver AI value, according to AWS

Why only 25% of teams are ready for the Cyber Resilience Act

Why only 25% of teams are ready for the Cyber Resilience Act

Your network isn't ready for AI: Here's what needs to change

Your network isn't ready for AI: Here's what needs to change

Read more on Security

Zscaler optimizes Zero Trust for agentic AI security
Top story

Zscaler optimizes Zero Trust for agentic AI security

Zscaler announces a series of security features for agentic AI. The company is expanding its Zero Trust Excha...

Berry Zwets June 9, 2026
Microsoft fixes WUSA bug during Patch Tuesday

Microsoft fixes WUSA bug during Patch Tuesday

Microsoft fixed an issue with the June 2026 Patch Tuesday: Windows updates installed via the Windows Update S...

Berry Zwets 11 hours ago
Klarrio: Security by design as the foundation for software

Klarrio: Security by design as the foundation for software

Klarrio has released a white paper on its approach to security by design in cloud-native software development...

Editorial Team 12 hours ago
The Digital Workforce calls for a new CISO
Top story

The Digital Workforce calls for a new CISO

On prompt injections, AI identities, and the hybrid workplace

Colin Baak 20 hours ago

Expert Talks

Taking the right lessons from AI success stories

Taking the right lessons from AI success stories

While a lot of the current narratives around AI focus on stalled...

Why traditional security can’t protect your enterprise against AI threats

Why traditional security can’t protect your enterprise against AI threats

Today’s AI tools are a boon for many businesses, boosting efficienc...

Power critical workloads with all-NVMe active-active storage for non-stop enterprise operations 

Enterprise infrastructure has reached a turning point where planned d...

Five tips for embracing continuous deployment as a DevOps mindset

Continuous deployment offers quicker releases and better software, bu...

Tech calendar

VivaTech

June 17, 2026 Paris Expo Porte de Versailles

GITEX AI EUROPE 2026

June 30, 2026 Messe Berlin Exhibition Center, South Entrance

GOTO Copenhagen 2026

September 28, 2026 TAP1, Raffinaderivej 10, 2300 København S, Denmark

Whitepapers

Experience Synology’s latest enterprise backup solution

Experience Synology’s latest enterprise backup solution

How do you ensure your company data is both secure and quickly recove...

How to choose the right Enterprise Linux platform?

How to choose the right Enterprise Linux platform?

"A Buyer's Guide to Enterprise Linux" comprehensively analyzes the mo...

Enhance your data protection strategy for 2025

The Data Protection Guide 2025 explores the essential strategies and...

Strengthen your cybersecurity with DNS best practices

The white paper "DNS Best Practices" by Infoblox presents essential g...

Techzine Global

Techzine focusses on IT professionals and business decision makers by publishing the latest IT news and background stories. The goal is to help IT professionals get acquainted with new innovative products and services, but also to offer in-depth information to help them understand products and services better.

Follow us

Twitter
LinkedIn
YouTube

© 2026 Dolphin Publications B.V.
All rights reserved.

Techzine Service

  • Become a partner
  • Advertising
  • About Us
  • Contact
  • Terms & Conditions
  • Privacy Statement