Live data from Hacker News

1Password detects "suspicious activity" in its internal Okta account

blog.1password.com

71–80 of 125 posts

Re: 1Password detects "suspicious activity" in its internal Okta account

#71
post #43

So it's finally happened at least a tiny bit: one of these corporations to which we have decided to dedicate all authority has had a breach. Someday it will be much, much worse. Someday someone will manage to breach and take control of a bigger one in a bigger way, and will instantly gain root on a large subset of the entire computing ecosystem. There's a trend of even delegating things like ssh to systems under OIDC…

What’s your alternative?

A more portable standardized version of the Apple distributed Secure Enclave sort of thing as 2FA with passwords as the first factor would be great. You could also add something like a Yubikey as an emergency unlock token.

It’d be based on keys you control so there’s no way someone could hack some master database or key authority and own the entire universe. That’s a distinct possibility today.

Plausible scenario: high sophisticated nation state sponsored break at Google with cooperation from inside, used to launch a sudden mass malware infection attack against hundreds of millions of systems.

Re: 1Password detects "suspicious activity" in its internal Okta account

#72
post #37

Earlier quoted context omitted.

Would the average attacker, though? It's a question about not touching an easy $15k, in exchange for a chance at a bigger score. I'd assume most attackers wouldn't be able to resist securing the low hanging fruit first. And even if there's a parallel move, it's even less likely they would leverage everything but the $15k, so OP would still receive a realtime indicator of compromise. From a game theory perspective, it…

What is “the average attacker”? If someone is compromising your entire password manager then that’s far from average and sophisticated If OP is part of a bigger breach, those data dumps will almost certainly get analyzed automatically and multiple wallets swept at once. Passwords to interesting stuff likely aggregated and then tried. It’s not some script kiddy that browses through the vault 1by1

But OP's point is which will happen first in a breach?

(a) Trivially accessible Bitcoin is stolen or (b) passwords are used to ferret items/info of value out of additional individual sites

For OP's plan to fail, someone has to leave $15k laying on the table, in plain sight and for the taking, while they plan their subsequent moves. Which is why the amount matters.

Re: 1Password detects "suspicious activity" in its internal Okta account

#75
post #32
post #12

Earlier quoted context omitted.

To be fair, evidence of absence is close to impossible in the space of infrastructure and network security.

Full PCAP, process auditing and centralized logs are not only a thing, they have been for decades. It just simply isn't worth the investment for CIO/CTO/CISO types because it isn't sexy. To say it's impossible is just factually inaccurate. I know more than a few places doing 40gbps and 100gbps full packet capture for 30+ days. And relatively speaking, the investment isn't that large (for tens of petabytes it isn't as…

We did this 5+ years ago at a managed hosting company, just for 3 days worth of data. Was still invaluable for figuring out complex events.

Re: 1Password detects "suspicious activity" in its internal Okta account

#78
If a SaaS is approximately as unreliable and insecure as self-managed software, the only reason to still choose it would be for liability reasons. You get to legally blame someone else if things go wrong.

I'm curious whether companies have faced this hard reality and decided that buying liability insurance + doing things inhouse is more economical & better for business.

Re: 1Password detects "suspicious activity" in its internal Okta account

#79

A bit light on details but seems "Requested a report of administrative users" was the main outcome disclosed which I assume means further phishing and attack vectors on 1Password admins. Any other takes?

I’m confused why 1Password publicly reported this if there was no damage.

Re: 1Password detects "suspicious activity" in its internal Okta account

#80
post #78

If a SaaS is approximately as unreliable and insecure as self-managed software, the only reason to still choose it would be for liability reasons. You get to legally blame someone else if things go wrong. I'm curious whether companies have faced this hard reality and decided that buying liability insurance + doing things inhouse is more economical & better for business.

I'm not a lawyer, but I don't think that hiring a SaaS provider shields you from any liability that you would otherwise be subject to. If 1Password were to suffer a massive data breach as a result of this, historical precedent says that there'd be no liability anyway, but if there were liability I can't see them getting out of it by blaming Okta.
Post reply on HN