It might possibly be a bad idea for everyone to consolidate all of the credentials and all of the auth flow mechanics for all of the things to a small handful of companies.
> It might possibly be a bad idea for everyone to consolidate all of the credentials and all of the auth flow mechanics for all of the things to a small handful of companies. People have long lost the difference in meaning between "security" and "convenience". They now believe the two are interchangeable.
1Password detects "suspicious activity" in its internal Okta account
111–120 of 125 posts
Re: 1Password detects "suspicious activity" in its internal Okta account
#112What action should a user of 1Password take?
Re: 1Password detects "suspicious activity" in its internal Okta account
#113Gentle reminder: the absence of evidence is not evidence of absence.
> Despite what the expression may seem to imply, a lack of evidence can be informative. For example, when testing a new drug, if no harmful effects are observed then this suggests that the drug is safe. https://en.m.wikipedia.org/wiki/Evidence_of_absence
or the harmful effects were missed, and the drug is dangerous
Re: 1Password detects "suspicious activity" in its internal Okta account
#114Honestly, it seems to me like we are heading back to a world where everything is self-hosted again. You can't keep a giant central target secure.
I actually think if a bunch of companies started hosting their own SSO, we'd hear of a lot more hacks. I'm not sure orgs would put in enough resources to do things properly other than "hey we got keycloak working"
Re: 1Password detects "suspicious activity" in its internal Okta account
#115A bit light on details but seems "Requested a report of administrative users" was the main outcome disclosed which I assume means further phishing and attack vectors on 1Password admins. Any other takes?
I’m confused why 1Password publicly reported this if there was no damage.
Re: 1Password detects "suspicious activity" in its internal Okta account
#116“found no compromise of user data or other sensitive systems, either employee-facing or user-facing” Does not mean it didn’t happen
Re: 1Password detects "suspicious activity" in its internal Okta account
#117A bit light on details but seems "Requested a report of administrative users" was the main outcome disclosed which I assume means further phishing and attack vectors on 1Password admins. Any other takes?
I’m confused why 1Password publicly reported this if there was no damage.
1. because people want to know if their for-money proprietary password storage company got hacked 1. because if in the future they actually get owned, "oh yeah, it sorta happened another time also but we didn't say anything" is a terrible look
Re: 1Password detects "suspicious activity" in its internal Okta account
#118Honestly, it seems to me like we are heading back to a world where everything is self-hosted again. You can't keep a giant central target secure.
simultaneously, Okta seems rather bad at their job of not getting hacked and having proper fucking audit logs
Re: 1Password detects "suspicious activity" in its internal Okta account
#119What action should a user of 1Password take?
ie nothing has changed really
Re: 1Password detects "suspicious activity" in its internal Okta account
#120Earlier quoted context omitted.
> Despite what the expression may seem to imply, a lack of evidence can be informative. For example, when testing a new drug, if no harmful effects are observed then this suggests that the drug is safe. https://en.m.wikipedia.org/wiki/Evidence_of_absence
Seems a very liberal use of the word “safe” unless I’m misunderstanding. It could mean either the drug is 100% safe, or that our methods of observation were insufficient to find the risk. Safe until proven unsafe and the class action lawsuits start, as it goes with many drugs. Doesn’t seem like a particularly strong counter-argument, unless the point is that sometimes we humans like to err on the side of recklessness…