Gentle reminder: the absence of evidence is not evidence of absence.
> Despite what the expression may seem to imply, a lack of evidence can be informative. For example, when testing a new drug, if no harmful effects are observed then this suggests that the drug is safe. https://en.m.wikipedia.org/wiki/Evidence_of_absence
1Password detects "suspicious activity" in its internal Okta account
41–50 of 125 posts
Re: 1Password detects "suspicious activity" in its internal Okta account
#42Re: 1Password detects "suspicious activity" in its internal Okta account
#43Someday it will be much, much worse. Someday someone will manage to breach and take control of a bigger one in a bigger way, and will instantly gain root on a large subset of the entire computing ecosystem. There's a trend of even delegating things like ssh to systems under OIDC control, so I'm not using root metaphorically.
But hey, OIDC is convenient and that's all that matters in computing.
Re: 1Password detects "suspicious activity" in its internal Okta account
#44Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.
would be just as effective with .05 btc
Re: 1Password detects "suspicious activity" in its internal Okta account
#45Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.
Yeah, I like to leave my Rolex Rose Gold GMT out on my nightstand when service people are working in the house to detect suspicious activity in my household. :/ Sorry man, I dunno if this is a weird flex or what, but it's kind of ridiculous to leave $15K of bitcoin as a canary for your password manager. Gotta call a spade a spade.
Re: 1Password detects "suspicious activity" in its internal Okta account
#46Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.
Yeah, I like to leave my Rolex Rose Gold GMT out on my nightstand when service people are working in the house to detect suspicious activity in my household. :/ Sorry man, I dunno if this is a weird flex or what, but it's kind of ridiculous to leave $15K of bitcoin as a canary for your password manager. Gotta call a spade a spade.
Re: 1Password detects "suspicious activity" in its internal Okta account
#47Earlier quoted context omitted.
would be just as effective with .05 btc
Debatable - the objective is to play on an attacker's greed and convince them to go for the BTC before any other credentials. Too low of an amount and the other credentials in there might start to look more interesting.
Re: 1Password detects "suspicious activity" in its internal Okta account
#48So it's finally happened at least a tiny bit: one of these corporations to which we have decided to dedicate all authority has had a breach. Someday it will be much, much worse. Someday someone will manage to breach and take control of a bigger one in a bigger way, and will instantly gain root on a large subset of the entire computing ecosystem. There's a trend of even delegating things like ssh to systems under OIDC…
Re: 1Password detects "suspicious activity" in its internal Okta account
#49Does not mean it didn’t happen