Live data from Hacker News

1Password detects "suspicious activity" in its internal Okta account

blog.1password.com

111–120 of 125 posts

Re: 1Password detects "suspicious activity" in its internal Okta account

#111

It might possibly be a bad idea for everyone to consolidate all of the credentials and all of the auth flow mechanics for all of the things to a small handful of companies.

> It might possibly be a bad idea for everyone to consolidate all of the credentials and all of the auth flow mechanics for all of the things to a small handful of companies. People have long lost the difference in meaning between "security" and "convenience". They now believe the two are interchangeable.

On the topic of security vs convenience, for someone looking to migrate from Lastpass as conveniently as possible, what are my options now that this event has ocurred ?

Re: 1Password detects "suspicious activity" in its internal Okta account

#113
post #34
post #2

Gentle reminder: the absence of evidence is not evidence of absence.

> Despite what the expression may seem to imply, a lack of evidence can be informative. For example, when testing a new drug, if no harmful effects are observed then this suggests that the drug is safe. https://en.m.wikipedia.org/wiki/Evidence_of_absence

> , if no harmful effects are observed then this suggests that the drug is safe

or the harmful effects were missed, and the drug is dangerous

Re: 1Password detects "suspicious activity" in its internal Okta account

#114

Honestly, it seems to me like we are heading back to a world where everything is self-hosted again. You can't keep a giant central target secure.

I actually think if a bunch of companies started hosting their own SSO, we'd hear of a lot more hacks. I'm not sure orgs would put in enough resources to do things properly other than "hey we got keycloak working"

Maybe SSO as such is not the greatest idea?

Re: 1Password detects "suspicious activity" in its internal Okta account

#115

A bit light on details but seems "Requested a report of administrative users" was the main outcome disclosed which I assume means further phishing and attack vectors on 1Password admins. Any other takes?

I’m confused why 1Password publicly reported this if there was no damage.

It's almost a standard practice now, most companies do this.

Re: 1Password detects "suspicious activity" in its internal Okta account

#116

“found no compromise of user data or other sensitive systems, either employee-facing or user-facing” Does not mean it didn’t happen

No, it does not. But one can’t assert something one doesn’t know. Therefore this assertion is as good as they can do.

Re: 1Password detects "suspicious activity" in its internal Okta account

#117

A bit light on details but seems "Requested a report of administrative users" was the main outcome disclosed which I assume means further phishing and attack vectors on 1Password admins. Any other takes?

I’m confused why 1Password publicly reported this if there was no damage.

what's confusing?

1. because people want to know if their for-money proprietary password storage company got hacked 1. because if in the future they actually get owned, "oh yeah, it sorta happened another time also but we didn't say anything" is a terrible look

Re: 1Password detects "suspicious activity" in its internal Okta account

#118

Honestly, it seems to me like we are heading back to a world where everything is self-hosted again. You can't keep a giant central target secure.

random IT departments won't do a better job securing IDP than google or microsoft or whatever, self-hosting that stuff will just lead to more, mostly smaller breaches.

simultaneously, Okta seems rather bad at their job of not getting hacked and having proper fucking audit logs

Re: 1Password detects "suspicious activity" in its internal Okta account

#119
post #65

What action should a user of 1Password take?

ensure you have some way to bootstrap your world again if 1password data is lost and perhaps consider adding canarytokens.org things to your store.

ie nothing has changed really

Re: 1Password detects "suspicious activity" in its internal Okta account

#120
post #34

Earlier quoted context omitted.

> Despite what the expression may seem to imply, a lack of evidence can be informative. For example, when testing a new drug, if no harmful effects are observed then this suggests that the drug is safe. https://en.m.wikipedia.org/wiki/Evidence_of_absence

Seems a very liberal use of the word “safe” unless I’m misunderstanding. It could mean either the drug is 100% safe, or that our methods of observation were insufficient to find the risk. Safe until proven unsafe and the class action lawsuits start, as it goes with many drugs. Doesn’t seem like a particularly strong counter-argument, unless the point is that sometimes we humans like to err on the side of recklessness…

I think you are misunderstanding, the article doesn't just say "safe", the article says "suggests it is safe" (the "suggests" part implies not being 100% certain).
Post reply on HN