Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Like your bank tells you, don't give the support person your password.

Sure, but they uploaded it to the okta portal, not to any random support person. Most users would expect that people getting files from the company portal would be cleared to see confidential and sensitive stuff.

Obviously not passwords, but still ...



Ideally, okta would clear those sessions when someone uploads a har file. That way, you don't have to trust users did the right thing...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: