The plan for Obsidian is to never grow beyond 10-12 people, never take VC funding, never collect personal data or analytics.
Continue building with the assumption that software is ephemeral, files matter more than apps. Use formats that are open and durable.
See our manifesto:
https://obsidian.md/about
Elon Musk Still Doesn’t Understand How Wikipedia Works https://www.vice.com/en_us/article/7kxd8a/elon-musk-still-doesnt-understand-how-wikipedia-works
I just finished writing a draft of the first part of my free ebook:
The Hacktivist Field Manual: Reverse engineering
This field manual is aimed at hackers and reverse engineerings who which to navigate the difficult grounds of legislation when reverse engineering.
I'll be posting Part 1 of this manual this week to subscribers of my newsletter over at https://0x0v1.com
_-_*_-_*_-_*_-_*_-_*_-_*_-_*_-_*_-_
More about the newsletter:
I'll be posting Part 1 of the ebook on my website this week, hopefully by Friday. This will be released as part of my weekly newsletter (which I changed from being every Friday, because deadlines just suck and I couldn't make them - sorry!)
You can sign up to get this newsletter on my website: https://www.0x0v1.com/
Other stuff I'll be mentioning in the newsletter:
- Hacking menstrual cycle tracking apps
- Online hacktivist hackerspace! Get involved.
- Translating malware into art
1Password detects “suspicious activity” in its internal Okta account
1Password, a password manager used by millions of people and more than 100,000 businesses, said it detected suspicious activity on a company account provided by Okta, the identity and authentication service that disclosed a breach on Friday.
“On September 29, we detected suspicious activity on our Okta instance that we use to manage our employee-facing apps,” 1Password CTO Pedro Canahuati wrote in an email. “We immediately terminated the activity, investigated, and found no compromise of user data or other sensitive systems, either employee-facing or user-facing.”
Since then, Canahuati said, his company had been working with Okta to determine the means that the unknown attacker used to access the account. On Friday, investigators confirmed it resulted from a breach Okta reported hitting its customer support management system.
Okta said then that a threat actor gained unauthorized access to its customer support case management system and, from there, viewed files uploaded by some Okta customers. The files the threat actor obtained in the Okta compromise comprised HTTP archive, or HAR, files, which Okta support personnel use to replicate customer browser activity during troubleshooting sessions. Among the sensitive information they store are authentication cookies and session tokens, which malicious actors can use to impersonate valid users.
Security firm BeyondTrust said it discovered the intrusion after an attacker used valid authentication cookies in an attempt to access its Okta account. The attacker could perform “a few confined actions,” but ultimately, BeyondTrust access policy controls stopped the activity and blocked all access to the account. 1Password now becomes the second known Okta customer to be targeted in a follow-on attack.
Monday’s statement from 1Password provided no further details about the incident, and representatives didn’t respond to questions. A report dated October 18 and shared on an internal 1Password Notion workspace said the threat actor obtained a HAR file a company IT employee had created when recently engaging with Okta support. The file contained a record of all traffic between the 1Password employee’s browser and Okta servers, including session cookies.
@internic @dangoodin Yes, and get ready for a lot more of these disclosures. I think Okta told the WSJ it was > 180 customers affected.
For those of you not on the other platforms where scientists hang out, biologist Michael Eisen was just removed from the chief editor position of the prestigious journal @eLife, allegedly for retweeting an Onion piece sympathetic to Palestinians.
@1password I'm happy to see you posting a blog post with details about the incident. Are you planning to send an email out to users as well (since presumably most do not read your blog regularly)?
We detected suspicious activity on our Okta instance but confirmed no user data was accessed.
Pedro Canahuati, our CTO, provides more information in a blog post, which includes our internal Okta Incident Report for additional details.
@dangoodin I now realize that I was basing my remark on something from another article I read, "However, there appears to be some confusion about how 1Password was breached, as Okta claims that their logs do not show that the IT employee's HAR file was accessed until after 1Password’s security incident."
But re-reading it now, having also read the 1Password internal report, it does appear that you (and your article) are correct.
And yeah, we should all be grateful to
@briankrebs for unearthing the information about the ur-hack here.
(ref previous post in thread)
> As part of these support cases, Okta routinely asks customers to upload HTTP Archive (HAR) files to troubleshoot customer problems. However, these HAR files contain sensitive data, including authentication cookies and session tokens
Browsers really should offer a way to exclude data from HAR files before saving; I recently went to quite a lot of effort to hand-edit the JSON in a HAR file to exclude my password or session cookie; it was tedious, and not something users should be expected to do. Likewise we shouldn't expect users to send un-censored HAR files by way of debugging.
#1Password #infosec #ux #browser #webDev
@dangoodin It sounds like the theory that it was a recorded session cookie that granted access doesn't 100% hang together because it didn't look like the relevant HAR file was accessed in the #Okta system prior to the #1Password incident. Do I understand that correctly or have I misread? If so, that seems a little disconcerting.
It is essentially inevitable that any service will get compromised eventually. The question is how often if happens and how they react when it does. So far it sounds like #1Password has mostly refused comment when contacted by reporters, and that is honestly what makes me most nervous so far. They did post a blog post about the incident (complete with a more detailed internal report that was referred to in the articles)
https://blog.1password.com/okta-incident/
which is good, but I don't think they've yet sent out an email to users, which seems like an important part of transparency.
@arstechnica The phrase "...the threat actor updated ... an IDP ... used to authenticate to a production environment.." in the article is tantalizingly vague. I'm guessing that there was no more detail about the nature of the "production environment" @dangoodin?
Scoop: Hackers Stole Access Tokens from Okta’s Support Unit
Okta, a company that provides identity tools like multi-factor authentication and single sign-on to thousands of businesses, has suffered a security breach involving a compromise of its customer support unit, KrebsOnSecurity has learned. Okta says the incident affected a “very small number” of customers, however it appears the hackers responsible had access to Okta’s support platform for at least two weeks before the company fully contained the intrusion.
https://krebsonsecurity.com/2023/10/hackers-stole-access-tokens-from-oktas-support-unit/
1Password detects “suspicious activity” in its internal Okta account
1Password CTO says investigation found no compromise of user data or sensitive systems.
Persian mathematician Muḥammad ibn Mūsā al-Khwārizmī was born ~780. He not only revolutionized algebra, but his contributions in mathematics, astronomy & geography have been central to hundreds of years of scientific advances.
Known as the father of algebra, al-Khwārizmī became one of the most influential thinkers of all time. The terms algebra & algorithm are derived from his name & work. https://www.loc.gov/item/2021666184/ #HistoryRemix #history #science #math
@franksting Given the zero-knowledge architecture of 1Password (including secret additional keys so that the encryption keys for the vaults don't merely rely on key stretching), I would think that the primary danger would be someone inserting malicious code into the client software, which is also a risk if your authentication data is only stored locally by an application.
@BleepingComputer @Taco_lad
Theoretical physicist by training (PhD in quantum open systems/quantum information), University lecturer for a bit, and currently paying the bills as an engineer working in optical communication (implementation) and quantum communication (concepts), though still pursuing a little science on the side. I'm interested in physics and math, of course, but I enjoy learning about really any area of science, philosophy, and many other academic areas as well. My biggest other interest is hiking and generally being out in nature.