Live data from Hacker News

1Password detects "suspicious activity" in its internal Okta account

blog.1password.com

91–100 of 125 posts

Re: 1Password detects "suspicious activity" in its internal Okta account

#91
So, a company that is supposed to protect your most valued secrets and therefore should have paranoid security is using an external support system without any 2FA, and with fully unprotected session tokens/cookies, which in addition appear to have an insane timeout (how else could someone re-use the HAR files?).

Wow.

In general I would regard anyone using a password manager that uses a cloud service and/or phones home to be unreasonable. But even if you believe that this is a good idea, at this point everyone should drop 1Password as they clearly do not have the competence to run such a service.

Re: 1Password detects "suspicious activity" in its internal Okta account

#92

A bit light on details but seems "Requested a report of administrative users" was the main outcome disclosed which I assume means further phishing and attack vectors on 1Password admins. Any other takes?

I’m confused why 1Password publicly reported this if there was no damage.

This is effectively best security practices IMHO.

Re: 1Password detects "suspicious activity" in its internal Okta account

#93

A bit light on details but seems "Requested a report of administrative users" was the main outcome disclosed which I assume means further phishing and attack vectors on 1Password admins. Any other takes?

I’m confused why 1Password publicly reported this if there was no damage.

Bingo.

Re: 1Password detects "suspicious activity" in its internal Okta account

#94
post #78

If a SaaS is approximately as unreliable and insecure as self-managed software, the only reason to still choose it would be for liability reasons. You get to legally blame someone else if things go wrong. I'm curious whether companies have faced this hard reality and decided that buying liability insurance + doing things inhouse is more economical & better for business.

> If a SaaS is approximately as unreliable and insecure as self-managed software

IF that were true. No way would it be cost effective at my company to try to internally reimplement 1Password's functionality though. I also would not trust it to be more reliable or more secure than 1Password.

Re: 1Password detects "suspicious activity" in its internal Okta account

#95

A bit light on details but seems "Requested a report of administrative users" was the main outcome disclosed which I assume means further phishing and attack vectors on 1Password admins. Any other takes?

I’m confused why 1Password publicly reported this if there was no damage.

I appreciate their transparency. I'm not a 1Password customer, but this earned some respect from me.

Re: 1Password detects "suspicious activity" in its internal Okta account

#96

Seems like 1P took the right steps and is being transparent about the incident. It wasn't even an on their systems - but one of their vendors support systems. A lower quality organization would just conveniently not disclose the incident at all - justifying it by saying something along the lines of nothing was breached, it wasn't even our system . I think we should applaud 1P's transparency here. Or am I missing some…

> am I missing something? This comes immediately after 1P's forced transition away from local app with local storage to Web app with cloud storage, and assurances that their security stance and practices would make a breach unlikely. If they had stuck with the old model, a breach would have no chance of impacting users, but now, we're left scratching our heads and speculating about the true extent of the damage.

> If they had stuck with the old model, a breach would have no chance of impacting users, but now, we're left scratching our heads and speculating about the true extent of the damage.

Well, since 1P clients are not open sourced, you always have to trust that they implement their white paper correctly, this is regardless before or after the transition.

Now, if you do trust them, then you should believe when they say that "IdP is only used for authenticate downloads of _encrypted_ secrets and the decryption only happens on device with a local credential", in which case a breach of IdP still would have no chance of impacting users.

I have a lot of rants about this transition, but the storage location of encrypted data is never something I worry about. In the past it was my personal iCloud/Dropbox accounts, now it's my 1Passowrd.com account. Am I missing something?

Re: 1Password detects "suspicious activity" in its internal Okta account

#97

It might possibly be a bad idea for everyone to consolidate all of the credentials and all of the auth flow mechanics for all of the things to a small handful of companies.

> It might possibly be a bad idea for everyone to consolidate all of the credentials and all of the auth flow mechanics for all of the things to a small handful of companies. People have long lost the difference in meaning between "security" and "convenience". They now believe the two are interchangeable.

I don't know how many people believe the two words are interchangeable (vs balancing factors), but one of your worst security nightmares could be when your employees fight against your security team. Making things inconvenience is one way to have it.

Re: 1Password detects "suspicious activity" in its internal Okta account

#98

It might possibly be a bad idea for everyone to consolidate all of the credentials and all of the auth flow mechanics for all of the things to a small handful of companies.

> It might possibly be a bad idea for everyone to consolidate all of the credentials and all of the auth flow mechanics for all of the things to a small handful of companies. People have long lost the difference in meaning between "security" and "convenience". They now believe the two are interchangeable.

> People have long lost the difference in meaning between "security" and "convenience". They now believe the two are interchangeable.

Not sure they're wrong. There are so many IT departments and websites that force dumb practices which are detrimental to both: frequent password changes, required low-entropy recovery question options, etc. And then on the other side, some really convenient flows with reasonable security, e.g. streaming apps that show you a short temporary credential you can copy from your Roku's screen to your signed-in computer/phone rather than requiring you downgrade your permanent password to something easier to enter on the Roku keyboard. So while fundamentally you're right that "security" and "convenience" are in tension, in practice I think the bigger factor is competence and care of the dev and admin teams.

Re: 1Password detects "suspicious activity" in its internal Okta account

#99
post #96

Earlier quoted context omitted.

> am I missing something? This comes immediately after 1P's forced transition away from local app with local storage to Web app with cloud storage, and assurances that their security stance and practices would make a breach unlikely. If they had stuck with the old model, a breach would have no chance of impacting users, but now, we're left scratching our heads and speculating about the true extent of the damage.

> If they had stuck with the old model, a breach would have no chance of impacting users, but now, we're left scratching our heads and speculating about the true extent of the damage. Well, since 1P clients are not open sourced, you always have to trust that they implement their white paper correctly, this is regardless before or after the transition. Now, if you do trust them, then you should believe when they say t…

> you always have to trust that they implement their white paper correctly

Actually, no - if they implement their whitepaper incorrectly, and I manage to keep my insecurely-encrypted vault blob private, I'm still safe. Bad implementation is only a risk if there is also a data breach. This is defense in depth. Your argument is based on an all-or-nothing model of trust, rather than one where trust can be contextual and partial.

Would you be comfortable uploading your vault somewhere 100% public, rather than behind authentication with iCloud/Dropbox/1P, since it's safely encrypted?

Re: 1Password detects "suspicious activity" in its internal Okta account

#100

Earlier quoted context omitted.

That's a lot of money in any country.

$150 is barely enough to buy a piece of furniture here. Usually you'd be paying over 10 times that just to rent a small apartment. Not a lot of money.

0.05 BTC is $1500 not $150
Post reply on HN