Password manager OneLogin hit by data breach


Open padlock surrounded by keys on circuit boardImage copyright Getty Images

Encrypted information has been accessed during a data breach at the password management service, OneLogin.

It affects “all customers served by our US data centre” and perpetrators had “the ability to decrypt encrypted data”, according to The Register.

Those affected have been advised to visit a registration-only support page, outlining the steps they need to take.

Security experts said the breach was “embarrassing” and showed every company was open to attack.

OneLogin is a single sign-on service, allowing users to access multiple apps and sites with just one password.

In 2013, the company had 700 business customers and passed 12 million licensed users.

Apps and sites integrated into the service include Amazon Web Services, Microsoft Office 365, Slack, Cisco Webex, Google Analytics and LinkedIn.

“We have since blocked this unauthorized access, reported the matter to law enforcement, and are working with an independent security firm to determine how the unauthorized access happened,” chief information security officer Alvaro Hoyos said on the company’s blog.

“We are actively working to determine how best to prevent such an incident from occurring in the future.”

Users who log in to the site have been given a list of steps designed to minimise the risk to their data. These include:

  • forcing a password reset for all users
  • generating new security credentials and certificates for apps and sites
  • recycling secrets stored in OneLogin’s secure notes

Some customers have criticised OneLogin for requiring users to log in to see the list.

Image copyright Twitter / Trevor Scott Mays
Image copyright Twitter / Erik Gomez

The company has not yet responded to a BBC request for comment.

In its email to customers, OneLogin told them that “because this is still an active investigation involving law enforcement, there are certain details we can’t comment on at this time.

“We understand how frustrating this might be and thank you for your patience while we continue the investigation.”

‘Strong passwords’

“Companies need to understand the risks of using cloud-based systems,” Professor Bill Buchanan of Edinburgh Napier University told the BBC.

“Increasingly they need to encrypt sensitive information before they put it within cloud systems, and watch that their encryption keys are not distributed to malicious agents.

“It is almost impossible to decrypt data that uses strong encryption, unless the encryption key has been generated from a simple password,” he said.

IT security consultant Ben Schlabs told the BBC it was likely the compromised data included passwords protected using “hashing” – converting the data into fixed-length strings of characters or numbers.

“The security of data would then depend on the strength of the passwords, and of the password hashes,” he said.

“I would happily store my properly encrypted password safe in any cloud service, because you don’t know my password for that safe and I trust encryption.”

View the original article: http://www.bbc.co.uk/news/technology-40118699

The strongest encryption system “hasn’t been broken yet, and there’s no sign that it should be,” he said.

In the same category are

Church to discuss same-sex blessing Image copyright PA Image caption Priests and churches would not be forced to bless same-sex marriages or civil partnerships The Church of England ...
Home Office u-turn over stroke survivor’s wife’s visa Image caption Leah Waterman cares for her husband Simon who can barely speak and needs 24-hour help The wife of a stroke survivor who was told she...
What it’s like being black and working class at Cambridge Chelsea Kwakye is not your typical Cambridge University student. Her mum is a nurse, her dad works in a post office depot, she went to a state school ...
Apple hit with trademark lawsuit over iPhone X ‘animoji’ feature NEW YORK (Reuters) - A Japanese software company is suing Apple Inc (AAPL.O) in a U.S. court over the trademark for the term “animoji”, alleging the U...
Brexit: UK will struggle to change UK borders in time, says watchdog Image copyright Getty Images The government will struggle to deliver the "huge changes" required to the UK's borders in time for Brexit, Meg Hillier...
Middlesbrough modified Kodi box trader gets suspended jail term Image caption Brian Thompson had previously said he wanted to know whether he was doing anything illegal A trader who sold TV boxes which allowed ...

Dont forget to “Like” us on Facebook


Need something to share, visit our sister site for the

‘News in the last 30 days”

in a clear concise package ….

 

If you are an artist or interested in art, visit our art website and read about todays artscene and browse some of our artist profiles

 

Comment on this story