Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Can someone explain why people still choose Okta?

Most people don't choose Okta. Somebody at the executive level chooses Okta and everybody else gets to deal with it.

Yubikeys mean that your IT department now does customer support for every single password issue instead of handing it off to the outsourcing company.

MFA has two problems: the technical one (technical security aspects of implementing keys, fobs, phones, SMS, whatever) which is almost irrelevant and the social one (customer support, forgotten passwords, key through the wash, can't get email, etc.) which is the gigantic one.

Everybody wants to outsource the gigantic, dumbass customer support role of security. The problem is that everybody is also incentivized to cut corners once having done so.

Which gives you Okta ...



Aren't Yubikeys for MFA and Okta for iDP somewhat orthogonal? A common pattern that I've seen is companies use both.


Yes, they are unrelated. I brought up Yubikeys just because it was an interesting tidbit in the report.


They are, my point (which wasn't very clear) was that somebody needs to do the customer support.

If you just do YubiKeys but not Okta, your staff takes all the calls. Yubi sure isn't going to do the customer support when Employee #46 can't log into Office 365 today.

That's why people outsource this to Okta and its ilk.


So - I work for a company that uses Okta. Our Infosec/IT group also rolled out Yubikeys. I need to work with IT when I'm having problems with my Yubikeys.

When we SSO to Okta - they will for some applications (VPN, Github, etc..) require us to MFA with our Yubikey. But for some other, lower risk applications, MFA isn't required.

When an employee has difficulty connecting to one of the 84 applications that we SSO via Okta - they file a ticket with IT, not Okta. There is no way any employee would even know how to contact Okta, and there isn't any way that Okta could troubleshoot for the employee anyways - the source of truth for their password (first factor) would be the corporate Active Directory server.

Okta doesn't (to my knowledge) provide any customer support (I guess they might work with IT if there is a service-outage) to our employees. It's just an IdP SaaS.


Can Okta actually manage your enterprise's Yubikeys for you? I wasn't aware that was a thing since I've never heard anybody use it - everybody just endured the burden of managing their Yubikeys themselves.


I think your point is still confusing. No one is suggesting replacing Okta with a Yubikey, so whether one chooses Okta to offload support requests or not has no bearing on Yubikeys.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: