Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot
    Twelve South’s magnetic PowerBug charger is down to just

    Twelve South’s magnetic PowerBug charger is down to just $35

    April 21, 2026
    The AirPods are Tim Cook’s most underrated achievement

    The AirPods are Tim Cook’s most underrated achievement

    April 21, 2026
    SpaceX cuts a deal to maybe buy Cursor for  billion

    SpaceX cuts a deal to maybe buy Cursor for $60 billion

    April 21, 2026
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » An Okta login bug bypassed checking passwords on some long usernames
    News

    An Okta login bug bypassed checking passwords on some long usernames

    News RoomBy News RoomNovember 1, 20242 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    An Okta login bug bypassed checking passwords on some long usernames
    Illustration by Cath Virginia / The Verge | Photo from Getty Images

    On Friday evening, Okta posted an odd update to its list of security advisories. The latest entry reveals that under specific circumstances, someone could’ve logged in by entering anything for a password, but only if the account’s username had over 52 characters.

    According to the note people reported receiving, other requirements to exploit the vulnerability included Okta checking the cache from a previous successful login, and that an organization’s authentication policy didn’t add extra conditions like requiring multi-factor authentication (MFA).

    Here are the details that are currently available:

    On October 30, 2024, a vulnerability was internally identified in generating the cache key for AD/LDAP DelAuth. The Bcrypt algorithm was used to generate the cache key where we hash a combined string of userId + username + password. During specific conditions, this could allow users to authenticate by only providing the username with the stored cache key of a previous successful authentication.

    The vulnerability can be exploited if the agent is down and cannot be reached OR there is high traffic. This will result in the DelAuth hitting the cache first.

    Okta allowing login bypass for any usernames with 52+ characters is insane

    Official Security Advisory: https://t.co/3b4v30q53z pic.twitter.com/yD8FkgwSgs

    — Kinnaird McQuade ☁️ (@kmcquade3) November 1, 2024

    According to the note, the flaw has been present since an update on July 23rd until it was resolved by switching the cryptographic algorithm from Bcrypt to PBKDF2 after the vulnerability was internally identified. Okta didn’t immediately respond to a request for additional details but says customers whose setups meet the necessary conditions should check those three months of system logs.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleFortnite kicked off its remixed Chapter 2 season with a Snoop Dogg and Ice Spice concert
    Next Article Bose is taking up to 40 percent off headphones ahead of Black Friday

    Related Posts

    Twelve South’s magnetic PowerBug charger is down to just

    Twelve South’s magnetic PowerBug charger is down to just $35

    April 21, 2026
    The AirPods are Tim Cook’s most underrated achievement

    The AirPods are Tim Cook’s most underrated achievement

    April 21, 2026
    SpaceX cuts a deal to maybe buy Cursor for  billion

    SpaceX cuts a deal to maybe buy Cursor for $60 billion

    April 21, 2026
    Framework is building a better couch keyboard because everyone hates the Logitech one

    Framework is building a better couch keyboard because everyone hates the Logitech one

    April 21, 2026
    Framework announces Laptop 13 Pro, ‘the MacBook Pro for Linux users’

    Framework announces Laptop 13 Pro, ‘the MacBook Pro for Linux users’

    April 21, 2026
    ISS astronauts are in the middle of a tech overhaul

    ISS astronauts are in the middle of a tech overhaul

    April 21, 2026
    Our Picks
    The AirPods are Tim Cook’s most underrated achievement

    The AirPods are Tim Cook’s most underrated achievement

    April 21, 2026
    SpaceX cuts a deal to maybe buy Cursor for  billion

    SpaceX cuts a deal to maybe buy Cursor for $60 billion

    April 21, 2026
    Framework is building a better couch keyboard because everyone hates the Logitech one

    Framework is building a better couch keyboard because everyone hates the Logitech one

    April 21, 2026
    Framework announces Laptop 13 Pro, ‘the MacBook Pro for Linux users’

    Framework announces Laptop 13 Pro, ‘the MacBook Pro for Linux users’

    April 21, 2026
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    ISS astronauts are in the middle of a tech overhaul News

    ISS astronauts are in the middle of a tech overhaul

    By News RoomApril 21, 2026

    Even astronauts need to level up their laptops once in a while — including the…

    Tim Cook was an innovator — just not the Jobs kind

    Tim Cook was an innovator — just not the Jobs kind

    April 21, 2026
    X makes it 1,900 percent more expensive to post links

    X makes it 1,900 percent more expensive to post links

    April 21, 2026
    Oppo’s new phone has one camera too many

    Oppo’s new phone has one camera too many

    April 21, 2026
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2026 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.