Live data from Hacker News

1Password detects "suspicious activity" in its internal Okta account

blog.1password.com

101–110 of 125 posts

Re: 1Password detects "suspicious activity" in its internal Okta account

#101
It was a minor incident, but it does remind me that centralized password managers seem to have an awful amount of concentrated risk.

Or is something like 1Password truly secure at its core, even if an attacker penetrates some layers of access?

Re: 1Password detects "suspicious activity" in its internal Okta account

#102

It was a minor incident, but it does remind me that centralized password managers seem to have an awful amount of concentrated risk. Or is something like 1Password truly secure at its core, even if an attacker penetrates some layers of access?

Yes, 1Password's end-to-end encryption model (explained at https://support.1password.com/1password-security/) should be secure to this even if an attacker penetrates some layers of access. The model of other password managers may or not hold up though.

With that said, there is a lot of rebuttals to this that begin with "but, that assumes..." that I'm sure some of our fellow HN peeps will point out here :)

Re: 1Password detects "suspicious activity" in its internal Okta account

#103
post #96

Earlier quoted context omitted.

> am I missing something? This comes immediately after 1P's forced transition away from local app with local storage to Web app with cloud storage, and assurances that their security stance and practices would make a breach unlikely. If they had stuck with the old model, a breach would have no chance of impacting users, but now, we're left scratching our heads and speculating about the true extent of the damage.

> If they had stuck with the old model, a breach would have no chance of impacting users, but now, we're left scratching our heads and speculating about the true extent of the damage. Well, since 1P clients are not open sourced, you always have to trust that they implement their white paper correctly, this is regardless before or after the transition. Now, if you do trust them, then you should believe when they say t…

A regular public audit by security firm would help increase confidence in a close source system. In fact, it would help in an open source system too.

Re: 1Password detects "suspicious activity" in its internal Okta account

#104
post #78

If a SaaS is approximately as unreliable and insecure as self-managed software, the only reason to still choose it would be for liability reasons. You get to legally blame someone else if things go wrong. I'm curious whether companies have faced this hard reality and decided that buying liability insurance + doing things inhouse is more economical & better for business.

I'm not a lawyer, but I don't think that hiring a SaaS provider shields you from any liability that you would otherwise be subject to. If 1Password were to suffer a massive data breach as a result of this, historical precedent says that there'd be no liability anyway, but if there were liability I can't see them getting out of it by blaming Okta.

Yah, this is why third party risk management is a thing. When I ran sec training, I always hammered home the point that a third party security issue is your issue.

Now, sure, technically there may be circumstances when you can technically/legally shift liability. But your customers don't care - they have the relationship with you. So the third parties problems, are your problems.

Re: 1Password detects "suspicious activity" in its internal Okta account

#105

Earlier quoted context omitted.

> am I missing something? This comes immediately after 1P's forced transition away from local app with local storage to Web app with cloud storage, and assurances that their security stance and practices would make a breach unlikely. If they had stuck with the old model, a breach would have no chance of impacting users, but now, we're left scratching our heads and speculating about the true extent of the damage.

I raised exactly this possibility with them when they announced their new model. Their support would not engage with this even as a possibility. Just assertions that everything would be completely secure. Getting access to this data is the holy grail for attackers - it is preposterous not to have a local-only or "saved on iCloud only" model. Clearly the only reason they removed this ability was the juicy, juicy subsc…

> juicy, juicy subscription revenue

The irony is that as a user since at least version 3, I would have easily kept paying a yearly subscription fee just for the same local+sync they had before centralizing. It’s clear that most tech businesses need stable recurring revenue in order to keep doing their best work.

They could have probably done an Amanda Palmer-style patreon (donations fund the ability to make all work public) for individuals/families and a straightforward high-cost enterprise subscription and been just as big if not bigger.

Re: 1Password detects "suspicious activity" in its internal Okta account

#106
post #61

Earlier quoted context omitted.

Sounds like a great idea for a service that manages this automatically for users (but using a more reasonable amount of BTC, like 0.01 BTC or ~$300 worth-- it has to be enough to be worth stealing I suppose!). Then it would automatically do the monitoring of that address and send the user the alert that they should change all their passwords when the coins move. If it happens to just that one account, then its likely…

Just spitballing on the idea of this being a service- Wonder if it would work for the canary-creator to also have a bot that watches the btc mem pool, and if it sees the .5 btc from this address being spent, it front-runs it with a transactions that has a much high transaction fee and directs the funds to a new safe wallet. Probably some risk of the bot failing to front-run, but otherwise it would have all the benefi…

Interesting idea. Would also be cool to try to trace back the IP of the first node that announced the transaction to the network so you could try to figure out who the thief is (assuming they aren't using a VPN).

Re: 1Password detects "suspicious activity" in its internal Okta account

#107

Honestly, it seems to me like we are heading back to a world where everything is self-hosted again. You can't keep a giant central target secure.

I actually think if a bunch of companies started hosting their own SSO, we'd hear of a lot more hacks. I'm not sure orgs would put in enough resources to do things properly other than "hey we got keycloak working"

Re: 1Password detects "suspicious activity" in its internal Okta account

#108
post #96

Earlier quoted context omitted.

> If they had stuck with the old model, a breach would have no chance of impacting users, but now, we're left scratching our heads and speculating about the true extent of the damage. Well, since 1P clients are not open sourced, you always have to trust that they implement their white paper correctly, this is regardless before or after the transition. Now, if you do trust them, then you should believe when they say t…

> you always have to trust that they implement their white paper correctly Actually, no - if they implement their whitepaper incorrectly, and I manage to keep my insecurely-encrypted vault blob private, I'm still safe. Bad implementation is only a risk if there is also a data breach. This is defense in depth. Your argument is based on an all-or-nothing model of trust, rather than one where trust can be contextual and…

[deleted]

Re: 1Password detects "suspicious activity" in its internal Okta account

#109

It might possibly be a bad idea for everyone to consolidate all of the credentials and all of the auth flow mechanics for all of the things to a small handful of companies.

> It might possibly be a bad idea for everyone to consolidate all of the credentials and all of the auth flow mechanics for all of the things to a small handful of companies. People have long lost the difference in meaning between "security" and "convenience". They now believe the two are interchangeable.

I’ve never met anyone who has made this conflation.

Okta and 1Pass are incredibly well designed and the companies do all of the right things when it comes to security and audit processes.

Re: 1Password detects "suspicious activity" in its internal Okta account

#110

Earlier quoted context omitted.

More like $8k net after taxes, anyways.

Doesn't the US have a tax free allowance for capital gains? In the UK for example you get a 15k allowance annualy

US military is quite impressive.
Post reply on HN