So it's finally happened at least a tiny bit: one of these corporations to which we have decided to dedicate all authority has had a breach. Someday it will be much, much worse. Someday someone will manage to breach and take control of a bigger one in a bigger way, and will instantly gain root on a large subset of the entire computing ecosystem. There's a trend of even delegating things like ssh to systems under OIDC…
1Password detects "suspicious activity" in its internal Okta account
51–60 of 125 posts
Re: 1Password detects "suspicious activity" in its internal Okta account
#52Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.
Sounds like a great idea for a service that manages this automatically for users (but using a more reasonable amount of BTC, like 0.01 BTC or ~$300 worth-- it has to be enough to be worth stealing I suppose!). Then it would automatically do the monitoring of that address and send the user the alert that they should change all their passwords when the coins move. If it happens to just that one account, then its likely…
Re: 1Password detects "suspicious activity" in its internal Okta account
#53Earlier quoted context omitted.
Yeah, I like to leave my Rolex Rose Gold GMT out on my nightstand when service people are working in the house to detect suspicious activity in my household. :/ Sorry man, I dunno if this is a weird flex or what, but it's kind of ridiculous to leave $15K of bitcoin as a canary for your password manager. Gotta call a spade a spade.
It all depends on how costly the fallout from a compromised password manager would be - 15k can be totally reasonable insurance policy if the other credentials in there could give them access to multiples of that?
Re: 1Password detects "suspicious activity" in its internal Okta account
#54Earlier quoted context omitted.
I think they would be more likely to copy all of the data first, in an effort to avoid detection methods like this, then make their move compromising everything in near parallel. At least that is how I would do it.
Would the average attacker, though? It's a question about not touching an easy $15k, in exchange for a chance at a bigger score. I'd assume most attackers wouldn't be able to resist securing the low hanging fruit first. And even if there's a parallel move, it's even less likely they would leverage everything but the $15k, so OP would still receive a realtime indicator of compromise. From a game theory perspective, it…
Your average attacker might be equally motivated to go for $20k, or $10k, or $5k. $1k, maybe not. $100, probably not. $1, almost certainly not.
There's an interesting game to play in minimizing the cost at no hit to efficiency.
Re: 1Password detects "suspicious activity" in its internal Okta account
#55Earlier quoted context omitted.
I think they would be more likely to copy all of the data first, in an effort to avoid detection methods like this, then make their move compromising everything in near parallel. At least that is how I would do it.
Would the average attacker, though? It's a question about not touching an easy $15k, in exchange for a chance at a bigger score. I'd assume most attackers wouldn't be able to resist securing the low hanging fruit first. And even if there's a parallel move, it's even less likely they would leverage everything but the $15k, so OP would still receive a realtime indicator of compromise. From a game theory perspective, it…
If OP is part of a bigger breach, those data dumps will almost certainly get analyzed automatically and multiple wallets swept at once. Passwords to interesting stuff likely aggregated and then tried. It’s not some script kiddy that browses through the vault 1by1
Re: 1Password detects "suspicious activity" in its internal Okta account
#56Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.
Why not fill the vault with canary accounts and tokens instead? There’s services that do it for you.
Re: 1Password detects "suspicious activity" in its internal Okta account
#57Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.
I just have a canarytokens credit card stored in it, if anyone tries to auth it I get an alert