This is certainly a compromise of note, though according to the article, if you were affected, you have have already received notice from OneLogin. In the comments/discussion section of Mr. Krebs blog, there is also an interesting conversation surrounding 2FA and how that could have mitigated the risk. If multi-factor was in place for the individual sites a person accessed through OneLogin, then yes, it would have been beneficial. Otherwise, decrypted credentials are the straw that breaks this particular camel’s back.
top of page
Recent Posts
See AllI recently spoke about the FTC’s lawsuit against Chegg, a major education tech firm, in one of the weekly tech tips interviews I provide...
Multiple sources have reported the breach of Cisco’s own network, purportedly via a Cisco employee’s personal Google account. According...
I very much enjoyed this article from Pieter Danhieux via Dark Reading and this creative approach to the management of applications and...
bottom of page