Or is something like 1Password truly secure at its core, even if an attacker penetrates some layers of access?
1Password detects "suspicious activity" in its internal Okta account
101–110 of 125 posts
Re: 1Password detects "suspicious activity" in its internal Okta account
#102It was a minor incident, but it does remind me that centralized password managers seem to have an awful amount of concentrated risk. Or is something like 1Password truly secure at its core, even if an attacker penetrates some layers of access?
With that said, there is a lot of rebuttals to this that begin with "but, that assumes..." that I'm sure some of our fellow HN peeps will point out here :)
Re: 1Password detects "suspicious activity" in its internal Okta account
#103Earlier quoted context omitted.
> am I missing something? This comes immediately after 1P's forced transition away from local app with local storage to Web app with cloud storage, and assurances that their security stance and practices would make a breach unlikely. If they had stuck with the old model, a breach would have no chance of impacting users, but now, we're left scratching our heads and speculating about the true extent of the damage.
> If they had stuck with the old model, a breach would have no chance of impacting users, but now, we're left scratching our heads and speculating about the true extent of the damage. Well, since 1P clients are not open sourced, you always have to trust that they implement their white paper correctly, this is regardless before or after the transition. Now, if you do trust them, then you should believe when they say t…
Re: 1Password detects "suspicious activity" in its internal Okta account
#104If a SaaS is approximately as unreliable and insecure as self-managed software, the only reason to still choose it would be for liability reasons. You get to legally blame someone else if things go wrong. I'm curious whether companies have faced this hard reality and decided that buying liability insurance + doing things inhouse is more economical & better for business.
I'm not a lawyer, but I don't think that hiring a SaaS provider shields you from any liability that you would otherwise be subject to. If 1Password were to suffer a massive data breach as a result of this, historical precedent says that there'd be no liability anyway, but if there were liability I can't see them getting out of it by blaming Okta.
Now, sure, technically there may be circumstances when you can technically/legally shift liability. But your customers don't care - they have the relationship with you. So the third parties problems, are your problems.
Re: 1Password detects "suspicious activity" in its internal Okta account
#105Earlier quoted context omitted.
> am I missing something? This comes immediately after 1P's forced transition away from local app with local storage to Web app with cloud storage, and assurances that their security stance and practices would make a breach unlikely. If they had stuck with the old model, a breach would have no chance of impacting users, but now, we're left scratching our heads and speculating about the true extent of the damage.
I raised exactly this possibility with them when they announced their new model. Their support would not engage with this even as a possibility. Just assertions that everything would be completely secure. Getting access to this data is the holy grail for attackers - it is preposterous not to have a local-only or "saved on iCloud only" model. Clearly the only reason they removed this ability was the juicy, juicy subsc…
The irony is that as a user since at least version 3, I would have easily kept paying a yearly subscription fee just for the same local+sync they had before centralizing. It’s clear that most tech businesses need stable recurring revenue in order to keep doing their best work.
They could have probably done an Amanda Palmer-style patreon (donations fund the ability to make all work public) for individuals/families and a straightforward high-cost enterprise subscription and been just as big if not bigger.
Re: 1Password detects "suspicious activity" in its internal Okta account
#106Earlier quoted context omitted.
Sounds like a great idea for a service that manages this automatically for users (but using a more reasonable amount of BTC, like 0.01 BTC or ~$300 worth-- it has to be enough to be worth stealing I suppose!). Then it would automatically do the monitoring of that address and send the user the alert that they should change all their passwords when the coins move. If it happens to just that one account, then its likely…
Just spitballing on the idea of this being a service- Wonder if it would work for the canary-creator to also have a bot that watches the btc mem pool, and if it sees the .5 btc from this address being spent, it front-runs it with a transactions that has a much high transaction fee and directs the funds to a new safe wallet. Probably some risk of the bot failing to front-run, but otherwise it would have all the benefi…
Re: 1Password detects "suspicious activity" in its internal Okta account
#107Honestly, it seems to me like we are heading back to a world where everything is self-hosted again. You can't keep a giant central target secure.
Re: 1Password detects "suspicious activity" in its internal Okta account
#108Earlier quoted context omitted.
> If they had stuck with the old model, a breach would have no chance of impacting users, but now, we're left scratching our heads and speculating about the true extent of the damage. Well, since 1P clients are not open sourced, you always have to trust that they implement their white paper correctly, this is regardless before or after the transition. Now, if you do trust them, then you should believe when they say t…
> you always have to trust that they implement their white paper correctly Actually, no - if they implement their whitepaper incorrectly, and I manage to keep my insecurely-encrypted vault blob private, I'm still safe. Bad implementation is only a risk if there is also a data breach. This is defense in depth. Your argument is based on an all-or-nothing model of trust, rather than one where trust can be contextual and…
Re: 1Password detects "suspicious activity" in its internal Okta account
#109It might possibly be a bad idea for everyone to consolidate all of the credentials and all of the auth flow mechanics for all of the things to a small handful of companies.
> It might possibly be a bad idea for everyone to consolidate all of the credentials and all of the auth flow mechanics for all of the things to a small handful of companies. People have long lost the difference in meaning between "security" and "convenience". They now believe the two are interchangeable.
Okta and 1Pass are incredibly well designed and the companies do all of the right things when it comes to security and audit processes.