top | item 30769393

(no title)

thricegr8 | 4 years ago

What's really concerning is if this turns out to be true, Okta has, at a minimum 26k (yes), customers right now. A simple enumeration of subdomains reveals this. I've put them here in a paste: https://ghostbin.com/K7tIA

discuss

order

frays|4 years ago

How can you tell that these subdomains are legitimate?

Any URL *.okta.com resolves and loads an Okta login screen but doesn't mean it's an actual customer.

For example, https://fake-ycombinator.okta.com works and shows the same login screen as https://pets.okta.com/. But only the latter is on the list, how do you know it's a legitimate customer?

xeromal|4 years ago

Not saying that their process is right, but I searched for 3 small companies that I know are running with Okta and found them in this list.

thricegr8|4 years ago

Ah yes, perhaps a bit more due diligence was required.

Can someone help me out then here? I checked the domain here: https://phonebook.cz/, but manually inspecting the certificate, I don't see the * in front of okta.com to denote a wildcard domain is in use(*.okta.com). What am I missing?

twistedpair|4 years ago

Wildcard domain much?

thricegr8|4 years ago

I was wrong on this. See my comment above. I thought inspecting the certificate would be enough to tell you? I don't see the blob in any cert details. Where did I error?