Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot
    GE made a smaller version of its nugget ice maker that needs less counter space

    GE made a smaller version of its nugget ice maker that needs less counter space

    February 19, 2026
    The speech police came for Colbert

    The speech police came for Colbert

    February 19, 2026
    Abxylute’s new Switch 2 controller prototype has one big problem

    Abxylute’s new Switch 2 controller prototype has one big problem

    February 19, 2026
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » An Okta login bug bypassed checking passwords on some long usernames
    News

    An Okta login bug bypassed checking passwords on some long usernames

    News RoomBy News RoomNovember 1, 20242 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    An Okta login bug bypassed checking passwords on some long usernames
    Illustration by Cath Virginia / The Verge | Photo from Getty Images

    On Friday evening, Okta posted an odd update to its list of security advisories. The latest entry reveals that under specific circumstances, someone could’ve logged in by entering anything for a password, but only if the account’s username had over 52 characters.

    According to the note people reported receiving, other requirements to exploit the vulnerability included Okta checking the cache from a previous successful login, and that an organization’s authentication policy didn’t add extra conditions like requiring multi-factor authentication (MFA).

    Here are the details that are currently available:

    On October 30, 2024, a vulnerability was internally identified in generating the cache key for AD/LDAP DelAuth. The Bcrypt algorithm was used to generate the cache key where we hash a combined string of userId + username + password. During specific conditions, this could allow users to authenticate by only providing the username with the stored cache key of a previous successful authentication.

    The vulnerability can be exploited if the agent is down and cannot be reached OR there is high traffic. This will result in the DelAuth hitting the cache first.

    Okta allowing login bypass for any usernames with 52+ characters is insane

    Official Security Advisory: https://t.co/3b4v30q53z pic.twitter.com/yD8FkgwSgs

    — Kinnaird McQuade ☁️ (@kmcquade3) November 1, 2024

    According to the note, the flaw has been present since an update on July 23rd until it was resolved by switching the cryptographic algorithm from Bcrypt to PBKDF2 after the vulnerability was internally identified. Okta didn’t immediately respond to a request for additional details but says customers whose setups meet the necessary conditions should check those three months of system logs.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleFortnite kicked off its remixed Chapter 2 season with a Snoop Dogg and Ice Spice concert
    Next Article Bose is taking up to 40 percent off headphones ahead of Black Friday

    Related Posts

    GE made a smaller version of its nugget ice maker that needs less counter space

    GE made a smaller version of its nugget ice maker that needs less counter space

    February 19, 2026
    The speech police came for Colbert

    The speech police came for Colbert

    February 19, 2026
    The RAM shortage is coming for everything you care about

    The RAM shortage is coming for everything you care about

    February 19, 2026
    The biggest app in the whole wide world

    The biggest app in the whole wide world

    February 19, 2026
    Mark Zuckerberg and his Ray-Ban entourage have their day in court

    Mark Zuckerberg and his Ray-Ban entourage have their day in court

    February 18, 2026
    Meta is reportedly planning to launch a smartwatch this year

    Meta is reportedly planning to launch a smartwatch this year

    February 18, 2026
    Our Picks
    The speech police came for Colbert

    The speech police came for Colbert

    February 19, 2026
    Abxylute’s new Switch 2 controller prototype has one big problem

    Abxylute’s new Switch 2 controller prototype has one big problem

    February 19, 2026
    Zutec introduces AI-driven intelligence layer to activate building data for operational use

    Zutec introduces AI-driven intelligence layer to activate building data for operational use

    February 19, 2026
    The RAM shortage is coming for everything you care about

    The RAM shortage is coming for everything you care about

    February 19, 2026
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    The biggest app in the whole wide world News

    The biggest app in the whole wide world

    By News RoomFebruary 19, 2026

    Last summer, Bria Sullivan was getting ready to launch her app, an adorable companion called…

    BrowserPod for Node.js enables secure in-browser execution for next-generation AI applications

    BrowserPod for Node.js enables secure in-browser execution for next-generation AI applications

    February 19, 2026
    Mark Zuckerberg and his Ray-Ban entourage have their day in court

    Mark Zuckerberg and his Ray-Ban entourage have their day in court

    February 18, 2026
    Meta is reportedly planning to launch a smartwatch this year

    Meta is reportedly planning to launch a smartwatch this year

    February 18, 2026
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2026 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.