Live data from Hacker News

1Password detects "suspicious activity" in its internal Okta account

blog.1password.com

21–30 of 125 posts

Re: 1Password detects "suspicious activity" in its internal Okta account

#21

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

Yeah, I like to leave my Rolex Rose Gold GMT out on my nightstand when service people are working in the house to detect suspicious activity in my household. :/

Sorry man, I dunno if this is a weird flex or what, but it's kind of ridiculous to leave $15K of bitcoin as a canary for your password manager. Gotta call a spade a spade.

Re: 1Password detects "suspicious activity" in its internal Okta account

#22

Earlier quoted context omitted.

The passwords in my manager could potentially cause more financial harm than 0.5 BTC going missing. Everyone has their own price for security. I've also not moved those BTC since 2014 so the price has appreciated considerably.

The point is that there are far cheaper canaries to keep in your coalmine.

More succinctly, this is plain dumb. And especially to tell people about it in public.

Re: 1Password detects "suspicious activity" in its internal Okta account

#23
post #16

Earlier quoted context omitted.

High value passwords doesn't mean you need a 0.5 BTC alerting method, though? You just went from "significant financial harm" to "significant financial harm, and 0.5 BTC".

The idea is anyone who compromised my password manager would likely go for the wallet first since it's as good as cold hard cash. Using the private keys and other secrets stored in my manager would take much more time for an attacker to exact meaningful value. I would expect the BTC to be moved first and foremost which would hopefully give me enough time to mitigate any other damage that could be caused by the conten…

I think they would be more likely to copy all of the data first, in an effort to avoid detection methods like this, then make their move compromising everything in near parallel. At least that is how I would do it.

Re: 1Password detects "suspicious activity" in its internal Okta account

#24
post #12
post #2

Gentle reminder: the absence of evidence is not evidence of absence.

To be fair, evidence of absence is close to impossible in the space of infrastructure and network security.

OTOH every tech CEO knows this and they always say "We have no evidence of compromise" right before they discover evidence of compromise

Re: 1Password detects "suspicious activity" in its internal Okta account

#25

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

One should always use caution when using password managers with anything crpyto related.

Re: 1Password detects "suspicious activity" in its internal Okta account

#26

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

would be just as effective with .05 btc

yeah, that is a lot of money in a developing country

Re: 1Password detects "suspicious activity" in its internal Okta account

#27
post #7

Earlier quoted context omitted.

> 0.5 BTC That's one expensive alert.

The passwords in my manager could potentially cause more financial harm than 0.5 BTC going missing. Everyone has their own price for security. I've also not moved those BTC since 2014 so the price has appreciated considerably.

I don't think it needs to be 15k in value to entice someone to steal it. You could also get compromised by someone who doesn't know anything about btc or misses that note and you would not know.

Re: 1Password detects "suspicious activity" in its internal Okta account

#28

This is an incident report from 1Password that I found more readable (PDF): https://blog.1password.com/files/okta-incident/okta-incident...

Yes that's much better, the original article felt mixed up.

So the culprit seems to have been the session information in the har. It made me wonder a few questions. What were they troubleshooting with Okta that required sending a har over, of their own interaction with Okta. And why are the session lengths so long, wouldn't Okta dogfood and use their own JWTs with limited lifetime?

Re: 1Password detects "suspicious activity" in its internal Okta account

#29

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

Yeah, I like to leave my Rolex Rose Gold GMT out on my nightstand when service people are working in the house to detect suspicious activity in my household. :/ Sorry man, I dunno if this is a weird flex or what, but it's kind of ridiculous to leave $15K of bitcoin as a canary for your password manager. Gotta call a spade a spade.

Yeah, I like to leave my Rolex Rose Gold GMT out on my nightstand when service people are working in the house to detect suspicious activity in my household. :/

i don't think that is a bad idea . It can be a cheaper one or a replica. The idea is it's a small price to pay when being deceived costs far more

Re: 1Password detects "suspicious activity" in its internal Okta account

#30

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

Sounds like a great idea for a service that manages this automatically for users (but using a more reasonable amount of BTC, like 0.01 BTC or ~$300 worth-- it has to be enough to be worth stealing I suppose!). Then it would automatically do the monitoring of that address and send the user the alert that they should change all their passwords when the coins move. If it happens to just that one account, then its likely the user's account was hacked. If it happens to a bunch of accounts at the same time, it's more likely that the password manager service was hacked. Like a canary with a bounty attached to it.
Post reply on HN