Live data from Hacker News

1Password detects "suspicious activity" in its internal Okta account

blog.1password.com

121–125 of 125 posts

Re: 1Password detects "suspicious activity" in its internal Okta account

#121
I bet there are 100 other Okta customers who saw something similar and are on reporting on it - props should be given to 1Password to publicly talk about this. All this shows how interconnected the cloud world is and there is nothing called absolute security. You want absolute security -> crawl back into the on-prem world.

Re: 1Password detects "suspicious activity" in its internal Okta account

#122

Earlier quoted context omitted.

I raised exactly this possibility with them when they announced their new model. Their support would not engage with this even as a possibility. Just assertions that everything would be completely secure. Getting access to this data is the holy grail for attackers - it is preposterous not to have a local-only or "saved on iCloud only" model. Clearly the only reason they removed this ability was the juicy, juicy subsc…

> juicy, juicy subscription revenue The irony is that as a user since at least version 3, I would have easily kept paying a yearly subscription fee just for the same local+sync they had before centralizing. It’s clear that most tech businesses need stable recurring revenue in order to keep doing their best work. They could have probably done an Amanda Palmer-style patreon (donations fund the ability to make all work…

Good point. I would have paid too had they just asked.

Re: 1Password detects "suspicious activity" in its internal Okta account

#124

Anyone else think it's odd that they scanned the laptop in question with Malwarebytes instead of, you know, a full forensic examination?

It's the go to for a lot of security teams (a fact i'm sure Malwarebytes wishes leveraged into more sales for their actual enterprise product) for routine stuff (random adware etc - no one can afford to run full forensics on all those all the time).

It's odd that they wrote that right out there on an incident report publicly shared and related to such a high profile potential breach though, for something like this it really has to be more of a 1st step triage than a definitive nope nothing wierd here...

Re: 1Password detects "suspicious activity" in its internal Okta account

#125
post #37

Earlier quoted context omitted.

Would the average attacker, though? It's a question about not touching an easy $15k, in exchange for a chance at a bigger score. I'd assume most attackers wouldn't be able to resist securing the low hanging fruit first. And even if there's a parallel move, it's even less likely they would leverage everything but the $15k, so OP would still receive a realtime indicator of compromise. From a game theory perspective, it…

Speaking of game theory, there is probably a much lower number that achieves the same goal, though. Your average attacker might be equally motivated to go for $20k, or $10k, or $5k. $1k, maybe not. $100, probably not. $1, almost certainly not. There's an interesting game to play in minimizing the cost at no hit to efficiency.

I don't play the minimization game. In 2014 when I started this strategy 0.5 BTC was like 100 bucks. Now that it's 15,000 bucks doesn't make a damn bit of difference. If they spent the time to figure out what the rest of the credentials were worth and exploited them to the maximum extent, they'd be walk away a multi-millionaire. However.... 15k in a plaintext wallet is an easy score and I argue that the vast majority of people who could compromise my password manager would take that in a heartbeat.
Post reply on HN