dormi.zone
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Leo to Technology@lemmy.worldEnglish • 2 years ago

1Password discloses security incident linked to Okta breach

www.bleepingcomputer.com

external-link
message-square
46
fedilink
  • cross-posted to:
  • technology@lemmy.ml
265
external-link

1Password discloses security incident linked to Okta breach

www.bleepingcomputer.com

Leo to Technology@lemmy.worldEnglish • 2 years ago
message-square
46
fedilink
  • cross-posted to:
  • technology@lemmy.ml
  • @pulaskiwasright@lemmy.ml
    link
    fedilink
    English
    6•2 years ago

    If they have vaults downloaded, then they can rapidly brute force the vault passwords and would like be able to decrypt a lot of them.

    • Savaran
      link
      fedilink
      English
      7•2 years ago

      1password protects against this by combining the password you choose with a cryptographically random 128bit “secret key”. That one isn’t getting brute forced easily.

      https://1passwordstatic.com/files/security/1password-white-paper.pdf

      They document their vault security highly and it’s worth reading through.

      • @pulaskiwasright@lemmy.ml
        link
        fedilink
        English
        2•2 years ago

        Good point. It’s been such a long time since I’ve had to use the secret that I forgot it existed.

    • @KairuByte@lemmy.dbzer0.com
      link
      fedilink
      English
      4•2 years ago

      It’s not as simple as brute forcing the password, it’s also encrypted using a secret key. You essentially have 2 factor encryption on the vaults.

      • @Appoxo@lemmy.dbzer0.com
        link
        fedilink
        English
        2•2 years ago

        If a user was social engineered, not very tech savy to catch on to it and revealed the master password, you’d only need to guess the encryption key, no?

        • @KairuByte@lemmy.dbzer0.com
          link
          fedilink
          English
          3•2 years ago

          Yes, but the encryption key is very likely more secure than the users password to begin with.

Technology@lemmy.world

!technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
  • 5.24K users / day
  • 9.75K users / week
  • 17K users / month
  • 35.7K users / 6 months
  • 70K subscribers
  • 14.8K Posts
  • 637K Comments
  • Modlog
  • mods:
  • @L3s@lemmy.world
  • enu
  • Technopagan
  • L4sBot
  • L3s
  • @L4s@hackingne.ws
  • BE: 0.19.3
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org