Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.
Sounds like a great idea for a service that manages this automatically for users (but using a more reasonable amount of BTC, like 0.01 BTC or ~$300 worth-- it has to be enough to be worth stealing I suppose!). Then it would automatically do the monitoring of that address and send the user the alert that they should change all their passwords when the coins move. If it happens to just that one account, then its likely…
1Password detects "suspicious activity" in its internal Okta account
61–70 of 125 posts
Re: 1Password detects "suspicious activity" in its internal Okta account
#62This is an incident report from 1Password that I found more readable (PDF): https://blog.1password.com/files/okta-incident/okta-incident...
Re: 1Password detects "suspicious activity" in its internal Okta account
#63Also, don't use 1Password or LastPass. KeePassXC, PasswordSafe, Dashlane, or properly-configured Bitwarden.
Re: 1Password detects "suspicious activity" in its internal Okta account
#64Earlier quoted context omitted.
High value passwords doesn't mean you need a 0.5 BTC alerting method, though? You just went from "significant financial harm" to "significant financial harm, and 0.5 BTC".
The idea is anyone who compromised my password manager would likely go for the wallet first since it's as good as cold hard cash. Using the private keys and other secrets stored in my manager would take much more time for an attacker to exact meaningful value. I would expect the BTC to be moved first and foremost which would hopefully give me enough time to mitigate any other damage that could be caused by the conten…
An intruder will rifle through the top drawers and go for the obvious stuff and let's face it half a BTC is a bit of a shiner. You seem to be able to afford to lose it, given that its loss will trigger the shutters coming down and hopefully allow you to secure the rest of your stuff.
I get that and hopefully that is close to the last resort in your defence in depth approach to security.
Re: 1Password detects "suspicious activity" in its internal Okta account
#65Re: 1Password detects "suspicious activity" in its internal Okta account
#66Gentle reminder: the absence of evidence is not evidence of absence.
> Despite what the expression may seem to imply, a lack of evidence can be informative. For example, when testing a new drug, if no harmful effects are observed then this suggests that the drug is safe. https://en.m.wikipedia.org/wiki/Evidence_of_absence
Doesn’t seem like a particularly strong counter-argument, unless the point is that sometimes we humans like to err on the side of recklessness in the name of progress.
Re: 1Password detects "suspicious activity" in its internal Okta account
#67Earlier quoted context omitted.
The point is that there are far cheaper canaries to keep in your coalmine.
More succinctly, this is plain dumb. And especially to tell people about it in public.
Museums and galleries etc put their wares on show in public - can you be sure that what is shown is what you think it is or secured as you think it is?
Please don't describe anyone as dumb - its as much demeaning to you as it is anyone else.
Re: 1Password detects "suspicious activity" in its internal Okta account
#68Seems like 1P took the right steps and is being transparent about the incident. It wasn't even an on their systems - but one of their vendors support systems. A lower quality organization would just conveniently not disclose the incident at all - justifying it by saying something along the lines of nothing was breached, it wasn't even our system . I think we should applaud 1P's transparency here. Or am I missing some…
This comes immediately after 1P's forced transition away from local app with local storage to Web app with cloud storage, and assurances that their security stance and practices would make a breach unlikely. If they had stuck with the old model, a breach would have no chance of impacting users, but now, we're left scratching our heads and speculating about the true extent of the damage.
Re: 1Password detects "suspicious activity" in its internal Okta account
#69Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.
Isn't that potentially a $15k detection method?
Re: 1Password detects "suspicious activity" in its internal Okta account
#70Honestly, it seems to me like we are heading back to a world where everything is self-hosted again. You can't keep a giant central target secure.
Complacency will result in more leaks and less knowledge of them maybe?
I reckon “passwords on a notepad in pen and ink” is safer plus passkeys like yubi.
If someone breaks into your home you got other concerns..