Close
Results 1 to 9 of 9
  1. #1
    COAR SpecOps Team Leader theGinsue's Avatar
    Join Date
    Mar 2008
    Location
    Colo Spr
    Posts
    21,974
    Blog Entries
    4

    Default OneLogin Users - They've Been Hacked

    For those of you who are users of the password & account management site OneLogin, you need to be aware that they've been hacked. I don't use this service, or others like it for this very reason.

    According to everything I've read, the hackers were able to decrypt encrypted passwords, making all of your information on any linked site vulnerable. If you use the OneLogin site, particularly to access this site, CHANGE YOUR PASSWORDS IMMEDIATIELY!



    Quote Originally Posted by LA Times Article
    Hackers have gained access to OneLogin, an online password manager that offers a single sign-on to multiple websites and services.OneLogin said in a blog post that it couldn't rule out the possibility that hackers got keys to reading encrypted data, such as stored passwords.

    Published reports, however, say OneLogin informed customers that the hackers indeed got that capability. OneLogin didn't immediately respond to a request for comment.

    Password managers help people keep track of passwords for a growing array of websites and services that require one. Instead of having to remember complex passwords for each one, people can just remember a master password. The password service then unlocks other accounts as needed.


    You can read more info on this breach from an online Security site:
    https://krebsonsecurity.com/2017/06/...-decrypt-data/
    Ginsue - Admin
    Proud Infidel Since 1965

    "You can't spell genius without Ginsue." -Ray1970, Apr 2020

    Ginsue's Feedback

  2. #2
    BIG PaPa ray1970's Avatar
    Join Date
    Feb 2010
    Location
    Thornton
    Posts
    18,799
    Blog Entries
    1

    Default

    Might have to let my step dad know. Not sure what it is he uses but it's something similar.

  3. #3
    Machine Gunner th3w01f's Avatar
    Join Date
    Nov 2010
    Location
    Castle Rock, CO
    Posts
    1,626

    Default

    WOW, that would really suck. I use roboform and two days ago I lost one login/pass combo on an airsoft site and had to change about 50 passwords. I have over 500 in roboform so that would be a really long night. The one I lost was my most common but one I don't use on important sites like this one.

  4. #4
    Splays for the Bidet CS1983's Avatar
    Join Date
    Jan 2011
    Location
    St. Augustine, FL
    Posts
    6,260

    Default

    I use a host based password program which requires me to login to it w/ a master password to access individual passwords.

    It's not as convenient, but it's also, hopefully, safer.
    Feedback

    It is terrible to contemplate how few politicians are hanged. - The Cleveland Press, March 1, 1921, GK Chesterton

  5. #5
    Possesses Antidote for "Cool" Gman's Avatar
    Join Date
    Oct 2005
    Location
    Puyallup, WA
    Posts
    17,848

    Default

    From the articles I was reading, the passwords were being stored in plain text. I'm not a fan of these 'put all of my eggs in one basket in the cloud' strategies.

    I do use Password Safe on my NAS at home to keep some of my info.
    Last edited by Gman; 06-02-2017 at 21:16.
    Liberals never met a slippery slope they didn't grease.
    -Me

    I wish technology solved people issues. It seems to just reveal them.
    -Also Me


  6. #6
    Zombie Slayer Aloha_Shooter's Avatar
    Join Date
    Feb 2007
    Location
    Colorado Springs, CO
    Posts
    6,564

    Default

    My passwords are all in one place -- my head. If someone cracks that, they deserve to post on Disqus or here as me. If they want to access my bank account, they'll need more than just the password ...

    BTW, even sites that claim they're secure because they store hashes instead of the password in plain text are really vulnerable. https://blog.codinghorror.com/hacker-hack-thyself/

    Length is better than plain "complexity". Fixed rules suck.
    Last edited by Aloha_Shooter; 06-02-2017 at 21:51.

  7. #7
    A FUN TITLE asmo's Avatar
    Join Date
    May 2012
    Location
    Douglas County (Parker)
    Posts
    3,446

    Default

    Repeat after me: Do not use cloud based password managers. All cloud based password managers are evil. If you must use a password manager, it needs to be locally resident and not on someone else's computer.
    What is my joy if all hands, even the unclean, can reach into it? What is my wisdom, if even the fools can dictate to me? What is my freedom, if all creatures, even the botched and impotent, are my masters? What is my life, if I am but to bow, to agree and to obey?
    -- Ayn Rand, Anthem (Chapter 11)

  8. #8
    "Beef Bacon" Commie Grant H.'s Avatar
    Join Date
    Jul 2007
    Location
    Longmont
    Posts
    2,443

    Default

    Quote Originally Posted by asmo View Post
    Repeat after me: Do not use cloud based password managers. All cloud based password managers are evil. If you must use a password manager, it needs to be locally resident and not on someone else's computer.
    This.

    I have a text file on an encrypted NAS that I can access from anywhere that I use to keep obscure passwords written down. Even then, I don't write the password out, I just give myself a text based hint/clue as to what the password is.

    Example:

    Site: XYZ.com
    Username: abc123
    Password: Password 1, first Cap, Last cap, + SC1 and SC2

    I have used the same 3 passwords, with dozens of variations for years. I've never had a password get "hacked".

    Works great, and the security level is fantastic. Someone manages to breach my personal network (highly unlikely), then crack the 256-bit AES encryption on the NAS (extremely unlikely), and then guess my passwords anyway...
    Living the fall of an empire sucks!
    For your convenience, a link to my Feedback

  9. #9
    Glock Armorer for sexual favors Jer's Avatar
    Join Date
    Jul 2009
    Location
    Loveland, CO
    Posts
    6,256

    Default

    Quote Originally Posted by asmo View Post
    Repeat after me: Do not use cloud based password managers. All cloud based password managers are evil. If you must use a password manager, it needs to be locally resident and not on someone else's computer.
    I couldn't agree more. The admins that think they're making the world safer by forcing frequent password changes and specific characters that require users to then use a 3rd party host to track all of their passwords are actually creating more problems. All my passwords are in my dome and I sleep tight at night knowing that nobody has them but me.
    I'm not fat, I'm tactically padded.
    Tactical Commander - Fast Action Response Team (F.A.R.T.)
    For my feedback Click Here.
    Click: For anyone with a dog or pets, please read

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •