Live data from Hacker News

1Password detects "suspicious activity" in its internal Okta account

blog.1password.com

51–60 of 125 posts

Re: 1Password detects "suspicious activity" in its internal Okta account

#51
post #43

So it's finally happened at least a tiny bit: one of these corporations to which we have decided to dedicate all authority has had a breach. Someday it will be much, much worse. Someday someone will manage to breach and take control of a bigger one in a bigger way, and will instantly gain root on a large subset of the entire computing ecosystem. There's a trend of even delegating things like ssh to systems under OIDC…

LastPass had a breach recently where entire vaults where stolen encrypted. Older entries were stored using worse (key derived using KDF with too few iterations) encryption than more recent ones.

Re: 1Password detects "suspicious activity" in its internal Okta account

#52

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

Sounds like a great idea for a service that manages this automatically for users (but using a more reasonable amount of BTC, like 0.01 BTC or ~$300 worth-- it has to be enough to be worth stealing I suppose!). Then it would automatically do the monitoring of that address and send the user the alert that they should change all their passwords when the coins move. If it happens to just that one account, then its likely…

This exact service exists, and has been featured on HN at least once!

Re: 1Password detects "suspicious activity" in its internal Okta account

#53

Earlier quoted context omitted.

Yeah, I like to leave my Rolex Rose Gold GMT out on my nightstand when service people are working in the house to detect suspicious activity in my household. :/ Sorry man, I dunno if this is a weird flex or what, but it's kind of ridiculous to leave $15K of bitcoin as a canary for your password manager. Gotta call a spade a spade.

It all depends on how costly the fallout from a compromised password manager would be - 15k can be totally reasonable insurance policy if the other credentials in there could give them access to multiples of that?

Why do 15 when $100, $250, or $1k would do the same trick?

Re: 1Password detects "suspicious activity" in its internal Okta account

#54
post #37
post #23

Earlier quoted context omitted.

I think they would be more likely to copy all of the data first, in an effort to avoid detection methods like this, then make their move compromising everything in near parallel. At least that is how I would do it.

Would the average attacker, though? It's a question about not touching an easy $15k, in exchange for a chance at a bigger score. I'd assume most attackers wouldn't be able to resist securing the low hanging fruit first. And even if there's a parallel move, it's even less likely they would leverage everything but the $15k, so OP would still receive a realtime indicator of compromise. From a game theory perspective, it…

Speaking of game theory, there is probably a much lower number that achieves the same goal, though.

Your average attacker might be equally motivated to go for $20k, or $10k, or $5k. $1k, maybe not. $100, probably not. $1, almost certainly not.

There's an interesting game to play in minimizing the cost at no hit to efficiency.

Re: 1Password detects "suspicious activity" in its internal Okta account

#55
post #37
post #23

Earlier quoted context omitted.

I think they would be more likely to copy all of the data first, in an effort to avoid detection methods like this, then make their move compromising everything in near parallel. At least that is how I would do it.

Would the average attacker, though? It's a question about not touching an easy $15k, in exchange for a chance at a bigger score. I'd assume most attackers wouldn't be able to resist securing the low hanging fruit first. And even if there's a parallel move, it's even less likely they would leverage everything but the $15k, so OP would still receive a realtime indicator of compromise. From a game theory perspective, it…

What is “the average attacker”? If someone is compromising your entire password manager then that’s far from average and sophisticated

If OP is part of a bigger breach, those data dumps will almost certainly get analyzed automatically and multiple wallets swept at once. Passwords to interesting stuff likely aggregated and then tried. It’s not some script kiddy that browses through the vault 1by1

Re: 1Password detects "suspicious activity" in its internal Okta account

#56

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

I don’t know if you though about this but the first thing a hacker would do after gaining access to your 1password vault is export all data.

Why not fill the vault with canary accounts and tokens instead? There’s services that do it for you.

Re: 1Password detects "suspicious activity" in its internal Okta account

#57
post #20

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

I just have a canarytokens credit card stored in it, if anyone tries to auth it I get an alert

That looks like a great approach indeed. https://www.canarytokens.org/generate

Re: 1Password detects "suspicious activity" in its internal Okta account

#58

Earlier quoted context omitted.

yeah, that is a lot of money in a developing country

That's a lot of money in any country.

$150 is barely enough to buy a piece of furniture here. Usually you'd be paying over 10 times that just to rent a small apartment. Not a lot of money.

Re: 1Password detects "suspicious activity" in its internal Okta account

#59
Seems like 1P took the right steps and is being transparent about the incident. It wasn't even an on their systems - but one of their vendors support systems. A lower quality organization would just conveniently not disclose the incident at all - justifying it by saying something along the lines of nothing was breached, it wasn't even our system. I think we should applaud 1P's transparency here. Or am I missing something?

Re: 1Password detects "suspicious activity" in its internal Okta account

#60

Earlier quoted context omitted.

Isn't that potentially a $15k detection method?

More like $8k net after taxes, anyways.

Doesn't the US have a tax free allowance for capital gains? In the UK for example you get a 15k allowance annualy
Post reply on HN