It is essentially inevitable that any service will get compromised eventually. The question is how often if happens and how they react when it does. So far it sounds like has mostly refused comment when contacted by reporters, and that is honestly what makes me most nervous so far. They did post a blog post about the incident (complete with a more detailed internal report that was referred to in the articles)

blog.1password.com/okta-incide

which is good, but I don't think they've yet sent out an email to users, which seems like an important part of transparency.

Well, I guess maybe it doesn't look so good, as Dan Goodin points out that most of this disclosure only came after they became aware of what he was publishing.

infosec.exchange/@dangoodin/11

Sign in to participate in the conversation
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.