Live data from Hacker News

1Password detects "suspicious activity" in its internal Okta account

blog.1password.com

1–10 of 125 posts

Re: 1Password detects "suspicious activity" in its internal Okta account

#4
> The files the threat actor obtained in the Okta compromise comprised HTTP archive, or HAR, files, which Okta support personnel use to replicate customer browser activity during troubleshooting sessions. Among the sensitive information they store are authentication cookies and session tokens, which malicious actors can use to impersonate valid users.

I know that troubleshooting for pwms is hard, but leaving unencrypted files to access accounts on a server that’s not governed by the same threat-model seems very negligent to me.

Re: 1Password detects "suspicious activity" in its internal Okta account

#5
Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address.

I then have a BTC node that will send me an SMS if those coins ever move.

Re: 1Password detects "suspicious activity" in its internal Okta account

#6

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

Isn't that potentially a $15k detection method?

Re: 1Password detects "suspicious activity" in its internal Okta account

#7

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

> 0.5 BTC

That's one expensive alert.

Re: 1Password detects "suspicious activity" in its internal Okta account

#8

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

https://blog.thinkst.com/2023/01/swipe-right-on-our-new-cred...

https://canarytokens.org/

https://news.ycombinator.com/item?id=34476507

Re: 1Password detects "suspicious activity" in its internal Okta account

#9

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

That sounds like an expensive notification system.

Re: 1Password detects "suspicious activity" in its internal Okta account

#10

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

Is that a $15k circuit breaker?
Post reply on HN