Live data from Hacker News

1Password detects "suspicious activity" in its internal Okta account

blog.1password.com

11–20 of 125 posts

Re: 1Password detects "suspicious activity" in its internal Okta account

#11
post #7

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

> 0.5 BTC That's one expensive alert.

The passwords in my manager could potentially cause more financial harm than 0.5 BTC going missing. Everyone has their own price for security. I've also not moved those BTC since 2014 so the price has appreciated considerably.

Re: 1Password detects "suspicious activity" in its internal Okta account

#13

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

Isn't that potentially a $15k detection method?

More like $8k net after taxes, anyways.

Re: 1Password detects "suspicious activity" in its internal Okta account

#14
post #7

Earlier quoted context omitted.

> 0.5 BTC That's one expensive alert.

The passwords in my manager could potentially cause more financial harm than 0.5 BTC going missing. Everyone has their own price for security. I've also not moved those BTC since 2014 so the price has appreciated considerably.

The point is that there are far cheaper canaries to keep in your coalmine.

Re: 1Password detects "suspicious activity" in its internal Okta account

#15

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

would be just as effective with .05 btc

Re: 1Password detects "suspicious activity" in its internal Okta account

#16
post #7

Earlier quoted context omitted.

> 0.5 BTC That's one expensive alert.

The passwords in my manager could potentially cause more financial harm than 0.5 BTC going missing. Everyone has their own price for security. I've also not moved those BTC since 2014 so the price has appreciated considerably.

High value passwords doesn't mean you need a 0.5 BTC alerting method, though?

You just went from "significant financial harm" to "significant financial harm, and 0.5 BTC".

Re: 1Password detects "suspicious activity" in its internal Okta account

#18

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

what's your plan if you receive that SMS?

Re: 1Password detects "suspicious activity" in its internal Okta account

#19
post #16

Earlier quoted context omitted.

The passwords in my manager could potentially cause more financial harm than 0.5 BTC going missing. Everyone has their own price for security. I've also not moved those BTC since 2014 so the price has appreciated considerably.

High value passwords doesn't mean you need a 0.5 BTC alerting method, though? You just went from "significant financial harm" to "significant financial harm, and 0.5 BTC".

The idea is anyone who compromised my password manager would likely go for the wallet first since it's as good as cold hard cash. Using the private keys and other secrets stored in my manager would take much more time for an attacker to exact meaningful value.

I would expect the BTC to be moved first and foremost which would hopefully give me enough time to mitigate any other damage that could be caused by the content of my password manager being exposed.

Re: 1Password detects "suspicious activity" in its internal Okta account

#20

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

I just have a canarytokens credit card stored in it, if anyone tries to auth it I get an alert
Post reply on HN