Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot
    Abxylute’s new Switch 2 controller prototype has one big problem

    Abxylute’s new Switch 2 controller prototype has one big problem

    February 19, 2026
    Zutec introduces AI-driven intelligence layer to activate building data for operational use

    Zutec introduces AI-driven intelligence layer to activate building data for operational use

    February 19, 2026
    The RAM shortage is coming for everything you care about

    The RAM shortage is coming for everything you care about

    February 19, 2026
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » An Okta login bug bypassed checking passwords on some long usernames
    News

    An Okta login bug bypassed checking passwords on some long usernames

    News RoomBy News RoomNovember 1, 20242 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    An Okta login bug bypassed checking passwords on some long usernames
    Illustration by Cath Virginia / The Verge | Photo from Getty Images

    On Friday evening, Okta posted an odd update to its list of security advisories. The latest entry reveals that under specific circumstances, someone could’ve logged in by entering anything for a password, but only if the account’s username had over 52 characters.

    According to the note people reported receiving, other requirements to exploit the vulnerability included Okta checking the cache from a previous successful login, and that an organization’s authentication policy didn’t add extra conditions like requiring multi-factor authentication (MFA).

    Here are the details that are currently available:

    On October 30, 2024, a vulnerability was internally identified in generating the cache key for AD/LDAP DelAuth. The Bcrypt algorithm was used to generate the cache key where we hash a combined string of userId + username + password. During specific conditions, this could allow users to authenticate by only providing the username with the stored cache key of a previous successful authentication.

    The vulnerability can be exploited if the agent is down and cannot be reached OR there is high traffic. This will result in the DelAuth hitting the cache first.

    Okta allowing login bypass for any usernames with 52+ characters is insane

    Official Security Advisory: https://t.co/3b4v30q53z pic.twitter.com/yD8FkgwSgs

    — Kinnaird McQuade ☁️ (@kmcquade3) November 1, 2024

    According to the note, the flaw has been present since an update on July 23rd until it was resolved by switching the cryptographic algorithm from Bcrypt to PBKDF2 after the vulnerability was internally identified. Okta didn’t immediately respond to a request for additional details but says customers whose setups meet the necessary conditions should check those three months of system logs.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleFortnite kicked off its remixed Chapter 2 season with a Snoop Dogg and Ice Spice concert
    Next Article Bose is taking up to 40 percent off headphones ahead of Black Friday

    Related Posts

    The RAM shortage is coming for everything you care about

    The RAM shortage is coming for everything you care about

    February 19, 2026
    The biggest app in the whole wide world

    The biggest app in the whole wide world

    February 19, 2026
    Mark Zuckerberg and his Ray-Ban entourage have their day in court

    Mark Zuckerberg and his Ray-Ban entourage have their day in court

    February 18, 2026
    Meta is reportedly planning to launch a smartwatch this year

    Meta is reportedly planning to launch a smartwatch this year

    February 18, 2026
    The RAM crunch could kill products and even entire companies, memory exec admits

    The RAM crunch could kill products and even entire companies, memory exec admits

    February 18, 2026
    Dyson turned its skinny PencilVac into a lightweight wet floor cleaner

    Dyson turned its skinny PencilVac into a lightweight wet floor cleaner

    February 18, 2026
    Our Picks
    Zutec introduces AI-driven intelligence layer to activate building data for operational use

    Zutec introduces AI-driven intelligence layer to activate building data for operational use

    February 19, 2026
    The RAM shortage is coming for everything you care about

    The RAM shortage is coming for everything you care about

    February 19, 2026
    The biggest app in the whole wide world

    The biggest app in the whole wide world

    February 19, 2026
    BrowserPod for Node.js enables secure in-browser execution for next-generation AI applications

    BrowserPod for Node.js enables secure in-browser execution for next-generation AI applications

    February 19, 2026
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Mark Zuckerberg and his Ray-Ban entourage have their day in court News

    Mark Zuckerberg and his Ray-Ban entourage have their day in court

    By News RoomFebruary 18, 2026

    Meta CEO Mark Zuckerberg entered a downtown Los Angeles courthouse in largely the same way…

    Meta is reportedly planning to launch a smartwatch this year

    Meta is reportedly planning to launch a smartwatch this year

    February 18, 2026
    The RAM crunch could kill products and even entire companies, memory exec admits

    The RAM crunch could kill products and even entire companies, memory exec admits

    February 18, 2026
    Dyson turned its skinny PencilVac into a lightweight wet floor cleaner

    Dyson turned its skinny PencilVac into a lightweight wet floor cleaner

    February 18, 2026
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2026 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.