Live data from Hacker News

1Password detects "suspicious activity" in its internal Okta account

blog.1password.com

81–90 of 125 posts

Re: 1Password detects "suspicious activity" in its internal Okta account

#81
post #78

If a SaaS is approximately as unreliable and insecure as self-managed software, the only reason to still choose it would be for liability reasons. You get to legally blame someone else if things go wrong. I'm curious whether companies have faced this hard reality and decided that buying liability insurance + doing things inhouse is more economical & better for business.

> only reason to still choose it would be for liability reasons

That’s not a reason. Haven’t you read any terms of service and user agreements? The vendor never accepts responsibility.

Re: 1Password detects "suspicious activity" in its internal Okta account

#82

A bit light on details but seems "Requested a report of administrative users" was the main outcome disclosed which I assume means further phishing and attack vectors on 1Password admins. Any other takes?

I’m confused why 1Password publicly reported this if there was no damage.

I'm encouraged by this, and the steps they took to implement additional precautions for the future. I would guess that was the goal of this release.

Re: 1Password detects "suspicious activity" in its internal Okta account

#84
post #78

If a SaaS is approximately as unreliable and insecure as self-managed software, the only reason to still choose it would be for liability reasons. You get to legally blame someone else if things go wrong. I'm curious whether companies have faced this hard reality and decided that buying liability insurance + doing things inhouse is more economical & better for business.

> only reason to still choose it would be for liability reasons That’s not a reason. Haven’t you read any terms of service and user agreements? The vendor never accepts responsibility.

I'm more referring to SLAs and the like.

Re: 1Password detects "suspicious activity" in its internal Okta account

#85

Want to know how I detect suspicious activity in my password manager? I have a plaintext bitcoin private key in my password manager as a note. The name is 'bitcoin wallet'. It contains 0.5 BTC. If my password manager ever get compromised, I can reasonably expect the bitcoins to be move from that wallet address. I then have a BTC node that will send me an SMS if those coins ever move.

what's your plan if you receive that SMS?

Change the password to the account that has 5 BTC?

Re: 1Password detects "suspicious activity" in its internal Okta account

#86

Seems like 1P took the right steps and is being transparent about the incident. It wasn't even an on their systems - but one of their vendors support systems. A lower quality organization would just conveniently not disclose the incident at all - justifying it by saying something along the lines of nothing was breached, it wasn't even our system . I think we should applaud 1P's transparency here. Or am I missing some…

> am I missing something? This comes immediately after 1P's forced transition away from local app with local storage to Web app with cloud storage, and assurances that their security stance and practices would make a breach unlikely. If they had stuck with the old model, a breach would have no chance of impacting users, but now, we're left scratching our heads and speculating about the true extent of the damage.

I raised exactly this possibility with them when they announced their new model. Their support would not engage with this even as a possibility. Just assertions that everything would be completely secure.

Getting access to this data is the holy grail for attackers - it is preposterous not to have a local-only or "saved on iCloud only" model. Clearly the only reason they removed this ability was the juicy, juicy subscription revenue, which requires them to hold the data.

They may have avoided a breach this time but have they previously been breached? Will they be breached in future? The possibility of each is non-zero.

Needless to say, I'm still using the older version and am planning how to transition once it stops working after an OS update.

Re: 1Password detects "suspicious activity" in its internal Okta account

#87

Honestly, it seems to me like we are heading back to a world where everything is self-hosted again. You can't keep a giant central target secure.

Companies don't force their cloud hosting solutions because it's good for users, they do it because they can make more money. Unfortunately I think things will have to get a lot worse before companies have to reverse course on this.

Re: 1Password detects "suspicious activity" in its internal Okta account

#88

It might possibly be a bad idea for everyone to consolidate all of the credentials and all of the auth flow mechanics for all of the things to a small handful of companies.

> It might possibly be a bad idea for everyone to consolidate all of the credentials and all of the auth flow mechanics for all of the things to a small handful of companies.

People have long lost the difference in meaning between "security" and "convenience". They now believe the two are interchangeable.

Re: 1Password detects "suspicious activity" in its internal Okta account

#89

It might possibly be a bad idea for everyone to consolidate all of the credentials and all of the auth flow mechanics for all of the things to a small handful of companies.

> It might possibly be a bad idea for everyone to consolidate all of the credentials and all of the auth flow mechanics for all of the things to a small handful of companies. People have long lost the difference in meaning between "security" and "convenience". They now believe the two are interchangeable.

In the real world they often are—complicated-but-secure processes usually lead to work arounds that are worse than if you had just planned for convenience from the beginning. The classic example of this is the sticky note with the password on it.

Securing a large organization populated by regular human beings is extremely difficult, and is an exercise in balancing theoretical security with convenience.

Re: 1Password detects "suspicious activity" in its internal Okta account

#90
post #78

If a SaaS is approximately as unreliable and insecure as self-managed software, the only reason to still choose it would be for liability reasons. You get to legally blame someone else if things go wrong. I'm curious whether companies have faced this hard reality and decided that buying liability insurance + doing things inhouse is more economical & better for business.

A base level of competency is expected as well. An SMB with a small staff that sells something non-tech still needs POS, payroll, and other systems and the ability to give employees access to those systems. “Outsourcing security” makes sense for businesses with zero IT staff.

For large companies, however, it seems like a liability, but I would hope an IdP would still be more competent, on average, then internal IT staff (obviously there are tech companies that have needed to deal with this for a long time with success). If a large business’s competency is not tech, there is some likelihood they can’t evaluate the robustness of their IT infrastructure.

Post reply on HN