Live data from Hacker News

1Password detects "suspicious activity" in its internal Okta account

blog.1password.com

31–40 of 125 posts

Re: 1Password detects "suspicious activity" in its internal Okta account

#32
post #12
post #2

Gentle reminder: the absence of evidence is not evidence of absence.

To be fair, evidence of absence is close to impossible in the space of infrastructure and network security.

Full PCAP, process auditing and centralized logs are not only a thing, they have been for decades.

It just simply isn't worth the investment for CIO/CTO/CISO types because it isn't sexy. To say it's impossible is just factually inaccurate.

I know more than a few places doing 40gbps and 100gbps full packet capture for 30+ days. And relatively speaking, the investment isn't that large (for tens of petabytes it isn't as expensive as you might think).

Re: 1Password detects "suspicious activity" in its internal Okta account

#34
post #2

Gentle reminder: the absence of evidence is not evidence of absence.

> Despite what the expression may seem to imply, a lack of evidence can be informative. For example, when testing a new drug, if no harmful effects are observed then this suggests that the drug is safe.

https://en.m.wikipedia.org/wiki/Evidence_of_absence

Re: 1Password detects "suspicious activity" in its internal Okta account

#35
post #12
post #2

Gentle reminder: the absence of evidence is not evidence of absence.

To be fair, evidence of absence is close to impossible in the space of infrastructure and network security.

As someone who's entire job is to maintain a gigantic qradar cluster (IBM won't sell us larger licenses), I sure hope 1p have to logs to back their claims because I know that it is possible that they do.

Re: 1Password detects "suspicious activity" in its internal Okta account

#36
post #7

Earlier quoted context omitted.

> 0.5 BTC That's one expensive alert.

The passwords in my manager could potentially cause more financial harm than 0.5 BTC going missing. Everyone has their own price for security. I've also not moved those BTC since 2014 so the price has appreciated considerably.

You could get the exact same alerting benefit with 1/10 the Bitcoin, or less.

There is no tax penalty for moving bitcoin. You should definitely move most of this elsewhere.

Re: 1Password detects "suspicious activity" in its internal Okta account

#37
post #23

Earlier quoted context omitted.

The idea is anyone who compromised my password manager would likely go for the wallet first since it's as good as cold hard cash. Using the private keys and other secrets stored in my manager would take much more time for an attacker to exact meaningful value. I would expect the BTC to be moved first and foremost which would hopefully give me enough time to mitigate any other damage that could be caused by the conten…

I think they would be more likely to copy all of the data first, in an effort to avoid detection methods like this, then make their move compromising everything in near parallel. At least that is how I would do it.

Would the average attacker, though?

It's a question about not touching an easy $15k, in exchange for a chance at a bigger score.

I'd assume most attackers wouldn't be able to resist securing the low hanging fruit first.

And even if there's a parallel move, it's even less likely they would leverage everything but the $15k, so OP would still receive a realtime indicator of compromise.

From a game theory perspective, it's a pretty compelling trap for OP to get what they want.

Re: 1Password detects "suspicious activity" in its internal Okta account

#38

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

a cheaper way would be to have a highly valuable token in the address without any of the chain’s native asset to pay for moving it

then just alert yourself when the native asset is moved to that address, because then someone is trying to sweep. your node can also send some some of the same asset faster at a higher transaction fee and move all of your tokens somewhere safe

people already do this

mostly as a scam to take the tiny amount of funds that thieves send to try to move the more lucrative bounty

you can take this one step further and have many assets worth sweeping, including assets that merely look like lucrative tokens. one of those is backdoored so that the transfer() function is nonstandard and transfers all the assets out of the attackers address when they try to move yours. or you can at least get just your own assets back if you want to be morally superior, moved to a safe address. this wont work if they dont take your backdoored token though. but all other parts about intercepting your assets before accepted into a block still would.

Re: 1Password detects "suspicious activity" in its internal Okta account

#39

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

Yeah, I like to leave my Rolex Rose Gold GMT out on my nightstand when service people are working in the house to detect suspicious activity in my household. :/ Sorry man, I dunno if this is a weird flex or what, but it's kind of ridiculous to leave $15K of bitcoin as a canary for your password manager. Gotta call a spade a spade.

It all depends on how costly the fallout from a compromised password manager would be - 15k can be totally reasonable insurance policy if the other credentials in there could give them access to multiples of that?

Re: 1Password detects "suspicious activity" in its internal Okta account

#40
post #7

Earlier quoted context omitted.

> 0.5 BTC That's one expensive alert.

The passwords in my manager could potentially cause more financial harm than 0.5 BTC going missing. Everyone has their own price for security. I've also not moved those BTC since 2014 so the price has appreciated considerably.

It sounds like you should be using 2FA with a hardware security token rather than setting up a honey pot that may or may not be triggered.
Post reply on HN