On October 30, 2024, Okta disclosed a critical vulnerability in its AD/LDAP delegated authentication system due to bcrypt hashing limitations, which allowed password bypass for usernames longer than 52 characters. This incident highlights the importance of understanding algorithm limitations and validating input lengths in security practices. Organizations using Okta's services are urged to monitor for unusual authentication patterns and to consider alternative hashing algorithms for longer input lengths.