Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

OneLogin hacker swiped AWS keys, can decrypt stolen data
The Cybersecurity Source ^ | June 2, 2017 | Doug Olenick

Posted on 06/05/2017 7:29:09 PM PDT by piytar

OneLogin is reporting its recent data breach was made possible when a hacker obtained access to a set of Amazon Web Service keys through a third-party vendor. With this, the hacker was enabled entry into its U.S. data center compromising all its records.

(Excerpt) Read more at scmagazine.com ...


TOPICS: Business/Economy; Miscellaneous; Technical
KEYWORDS: 1password; aws; cloudservices; datasecurity; hacker; hacking; internet; onelogin; onepassword; tech
Navigation: use the links below to view more comments.
first 1-2021 next last
Wow, just wow.
1 posted on 06/05/2017 7:29:09 PM PDT by piytar
[ Post Reply | Private Reply | View Replies]

To: piytar

Jeff Bezos is not likely to apologize.


2 posted on 06/05/2017 7:32:26 PM PDT by ptsal ( Get your facts first, then you can distort them as you please. - M. Twain)
[ Post Reply | Private Reply | To 1 | View Replies]

To: piytar
Folks, NEVER allow a “password keeper” to put your information into a cloud. Keep it on your devices, separately, syncing passwords to devices, using a manual process (retyping, USB, bluetooth in-house, etc.).
3 posted on 06/05/2017 7:32:32 PM PDT by ConservativeMind (Trump: Befuddling Democrats, Republicans, and the Media for the benefit of the US and all mankind.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: piytar

Monumental.

This shifts the entire modern paradigm.

People and organization are ok if it’s them that screws up and lets the data out.

But they are FURIOUS if someone else does it.

AWS is the largest cloud provider in the world, and the first.

A very big deal.


4 posted on 06/05/2017 7:34:46 PM PDT by Mariner (War Criminal #18)
[ Post Reply | Private Reply | To 1 | View Replies]

To: piytar

I work in cyber security. I always have and always told my customers.

DONT PUT ANYTHING IN THE CLOUD YOU DON’T WANT EXPOSED


5 posted on 06/05/2017 7:37:53 PM PDT by taxcontrol
[ Post Reply | Private Reply | To 1 | View Replies]

To: Mariner

Didn’t AWS contract with the CIA for cloud services?


6 posted on 06/05/2017 7:38:24 PM PDT by bankwalker (groupthink is dangerous ...)
[ Post Reply | Private Reply | To 4 | View Replies]

To: bankwalker

I’m pretty sure it was the NSA that contracted with AWS...with an offer they couldn’t refuse.

EVERYTHING is recorded and backed up. It’s stored for at least 10 years.

Everything. Including these key strokes.


7 posted on 06/05/2017 7:42:34 PM PDT by Mariner (War Criminal #18)
[ Post Reply | Private Reply | To 6 | View Replies]

To: piytar

If it’s in the cloud, it isn’t your data any more.


8 posted on 06/05/2017 7:48:44 PM PDT by PAR35
[ Post Reply | Private Reply | To 1 | View Replies]

To: piytar
An up-to-date figure on the number of customers served by OneLogin is not available, but in a 2013 press release the company noted it had just signed its 12 millionth customer, including many at the corporate level.

Oops.

9 posted on 06/05/2017 7:49:35 PM PDT by TChad
[ Post Reply | Private Reply | To 1 | View Replies]

To: taxcontrol

Does this include “lastpass” password management service? Leo LaPorte will not be happy.


10 posted on 06/05/2017 7:55:14 PM PDT by Fungi (Mucor roxii is not a rock band.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: ConservativeMind

I had been thinking of a password keeper.. can you give me some dtails on using a USB device?


11 posted on 06/05/2017 8:04:50 PM PDT by momincombatboots (White Stetsons up.. let's save our country!)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Fungi
Does this include “lastpass” password management service?

That's a competitor.

http://www.pcmag.com/article2/0,2817,2491437,00.asp

PC Magazine might want to update its four star rating for OneLogin.

12 posted on 06/05/2017 8:05:38 PM PDT by TChad
[ Post Reply | Private Reply | To 10 | View Replies]

To: taxcontrol

I think many end users (and others) don’t know what the cloud is, or how to know where their data goes. They just want the cool stuff.


13 posted on 06/05/2017 8:19:01 PM PDT by bigbob (People say believe half of what you see son and none of what you hear - M. Gaye)
[ Post Reply | Private Reply | To 5 | View Replies]

To: taxcontrol

I’m so paranoid I haven’t even used the cloud yet. Thought about it, but who wants to read my psych study research? LOL What I should have done is put my Wrath of God study on there.


14 posted on 06/05/2017 8:25:21 PM PDT by huldah1776 ( Vote Pro-life! Allow God to bless America before He avenges the death of the innocent.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: momincombatboots
I had been thinking of a password keeper.. can you give me some dtails on using a USB device?

A password keeper is a target of opportunity. I have a file with passwords that are abbreviated so someone finding it would still not know the passwords. Besides, if I were a target the attackers would log my keystrokes or the browser. If I used a password keeper they would log the password keeper password when I type it or log the browser password fields, not much different or more difficult

The other thing to think about is complex passwords created by password keepers are pointless. If a site is hacked such that the password hashes are accessed, then your personal info will be stolen instead. Or they will log passwords after HTTPS decryption but before hashing. Long and/or complex passwords don't help.

15 posted on 06/05/2017 9:10:14 PM PDT by palmer (turn into nonpaper w no identifying heading and send nonsecure)
[ Post Reply | Private Reply | To 11 | View Replies]

To: piytar
OneLogin hacker swiped AWS keys, can decrypt stolen data

There will be consequences for this behavior.

This person needs to hang from a light post like General Douglas MacArthur hung the War Criminals from Japan on Main Street for all to see.

This is called Treason and death by a firing squad or hanging from a light post is the penalty!

We need to stop this lawlessness in this country now!

16 posted on 06/05/2017 9:20:08 PM PDT by TheConservativeTejano (God Bless Texas...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: piytar

Had a notice a couple days ago from Amazon about an order being canceled. Haven’t used them in years...wonder if someone tried to use an old credit card listing.


17 posted on 06/05/2017 9:34:56 PM PDT by 1_Inch_Group (Country Before Party)
[ Post Reply | Private Reply | To 1 | View Replies]

To: 1_Inch_Group

Received one yesterday and another today. Deleted them both without opening them. Received a third stating an inquiry was being initiated. No way to tell if the email was Amazon initiated or not without opening it. When I’m good and ready I’ll sign in and see if there is a notification on the account. I haven’t done business there is some time.

Wife’s CC had unauthorized charges attempted and the bank caught them yesterday. New card in the mail.

Going Galt just isn’t in the in the cards.


18 posted on 06/05/2017 10:39:03 PM PDT by chulaivn66 (Oh stranger, tell the Lacedaemonians that we lie here, trusting their words.)
[ Post Reply | Private Reply | To 17 | View Replies]

To: piytar

This is exactly the kind of compromise I’ve warned was inherent in this model of network storage.

The cloud is for two types of customers:

1) Organizations that have a business requirement to publish large amounts of low-risk content to a large, geographically-dispersed audience; and

2) Stupid people


19 posted on 06/05/2017 10:50:27 PM PDT by thoughtomator
[ Post Reply | Private Reply | To 1 | View Replies]

To: taxcontrol
I work in cyber security. I always have and always told my customers.

DONT PUT ANYTHING IN THE CLOUD YOU DON’T WANT EXPOSED

While I don't work primarily in security, I agree 100%!

There's a saying that's quite true... "There is no cloud. It's just someone else's server."

Mark

20 posted on 06/05/2017 11:20:40 PM PDT by MarkL (Do I really look like a guy with a plan?)
[ Post Reply | Private Reply | To 5 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson