An Okta login bug bypassed checking passwords on some long usernames

Illustration of a password above an open combination lock, implying a data breach.
Illustration by Cath Virginia / The Verge | Photo from Getty Images

On Friday evening, Okta posted an odd update to its list of security advisories. The latest entry reveals that under specific circumstances, someone could’ve logged in by entering anything for a password, but only if the account’s username had over 52 characters.

According to the note people reported receiving, other requirements to exploit the vulnerability included Okta checking the cache from a previous successful login, and that an organization’s authentication policy didn’t add extra conditions like requiring multi-factor authentication (MFA).

Here are the details that are currently available:

On October 30, 2024, a vulnerability was internally identified in generating the cache key for AD/LDAP DelAuth. The Bcrypt algorithm was…

Continue reading…

Go to Source
Author: Richard Lawler

Some iPhone 14 Plus phones have a camera issue, but Apple may fix it for free

iPhone 14 Plus on a MacBook Air.
Photo by Allison Johnson / The Verge

Apple announced a new service program to fix iPhone 14 Plus phones that have rear cameras that won’t show a preview.

Here’s Apple’s specific definition of the affected phones, according to the service program page:

Apple has determined that the rear camera on a very small percentage of iPhone 14 Plus devices may exhibit no preview. Affected devices were manufactured between April 10, 2023 to April 28, 2024.

If your iPhone 14 Plus is affected — and you can enter your serial number on the program page to see if yours is — Apple says it or an Authorized Service Provider will service your phone for free. If you’ve already paid to have the camera repaired, Apple says to reach out to ask if you can get a refund.

Eligible phones will be…

Continue reading…

Go to Source
Author: Jay Peters

Hyundai’s cutesy Inster EV doesn’t need to be quick

light green colored little car
This will fit in most parking spots. | Image: Hyundai

The reviews for Hyundai’s little electric SUV that could are trickling in, and it’s clear that the Inster is a delightful way to move about town — regardless of its lack of quickness compared to other similarly-sized EVs. The Inster’s top speed for the long-range version is about 93 miles per hour (or 150 km/h), and it has a zero to 62 mph (100km/h) acceleration in 10.6 seconds, according to the specs Hyundai published today.

Hyundai also revealed more details about the Inster’s price, with European reviewers saying it’s expensive compared to similar competition at £23,495 (about $25,477). In the US, however, that’s a price we can only dream about since our most affordable options include the $35,000 Chevy Equinox EV or the hope Tesla…

Continue reading…

Go to Source
Author: Umar Shakir

Fortnite kicked off its remixed Chapter 2 season with a Snoop Dogg and Ice Spice concert

Snoop Dogg in Fortnite.
Image: Epic Games

Fortnite is rewinding the clock once again. After a bit of teasing, Epic is about to kick off a new period in the battle royale game dubbed The Remix: Chapter 2 — and it’s not only looking back in time, it’s integrating music in an ambitious new way.

The launch of the remixed season was preceded by a musical event, similar to the Eminem concert that teased a new era for Fortnite. This time around, Snoop Dogg and Ice Spice took the stage — both in the game and IRL at Times Square in New York — and once the season kicks off, the musical aspects will go a step farther.

Image: Epic Games

As the name implies, the new mini season brings back many of the characters, gameplay elements, and locations of the game’s second…

Continue reading…

Go to Source
Author: Andrew Webster

Best AT&T Phones in 2024

From the iPhone 16 to the Samsung Galaxy S24 series and the Google Pixel 9: Here are the best AT&T phones you can buy — all tested and handpicked by CNET editors.

Go to Source
Author: Andrew Lanxon