@dangoodin It sounds like the theory that it was a recorded session cookie that granted access doesn't 100% hang together because it didn't look like the relevant HAR file was accessed in the #Okta system prior to the #1Password incident. Do I understand that correctly or have I misread? If so, that seems a little disconcerting.
@dangoodin I now realize that I was basing my remark on something from another article I read, "However, there appears to be some confusion about how 1Password was breached, as Okta claims that their logs do not show that the IT employee's HAR file was accessed until after 1Password’s security incident."
But re-reading it now, having also read the 1Password internal report, it does appear that you (and your article) are correct.
And yeah, we should all be grateful to
@briankrebs for unearthing the information about the ur-hack here.
@internic @dangoodin Yes, and get ready for a lot more of these disclosures. I think Okta told the WSJ it was > 180 customers affected.
@dangoodin @internic i also like how their initial report was open to the idea that the 1password employee's Mac could have been pwned by malware, but their update rules that out based on Okta's response. Based on that, I'd assume this incident report was written some time before Okta's disclosure.
@briankrebs @dangoodin if I'm interpreting this breach correctly.. it seems 1password did everything right in response and has good policies/processes in place. Refreshing compared to lastpass.
Although I don't personally use them anymore, I recommend them to non-tech literate people (like my parents) bc the UI and recovery feel easier for them.
@flagstone @dangoodin As someone remarked in the comments on Dan's story, just about any kind of response would have been better than LastPass's public response on its breach from last year.
@briankrebs @dangoodin @internic am I the only person somewhat alarmed that their approach to dealing with the suspect mac, however, was installing malwarebytes (free edition or not)?
Shouldn't an entity in an extraordinary position of trust like 1Password have fully managed & monitored EDR on all of their devices?
@internic
Keep in mind that the internal report is from Oct. 18/19. which was before 1Password investigators knew of the Okta breach. They were still trying to figure out how the session got recorded. Now we know, thanks to @briankrebs forcing Okta to disclose this in the first place.