|
|
|
|
|
by sbarre
3304 days ago
|
|
From reading many articles, it seems that OneLogin does have a service called "Password Cache", which sounds to me like a cache for passwords, perhaps for storing credentials to sites that do not have SSO.. See here: https://support.onelogin.com/hc/en-us/articles/201175264-Pas... If they are storing the password and pushing it to the connected service on the user's behalf, then they have to be able to decrypt it somehow, and if the bad actor was able to intercept and decrypt data within the platform, then that may have included passwords stored using this mechanism perhaps |
|
By storing so many passwords in one system, they made that system a high value target, all while not having the security chops they thought they had.
Password vaults should be distributed. This prevents the conglomeration of password secrets that creates a high value target. They would've been wise to have a series of password vault apps that are integrated with their system. They could have done this by leveraging Password Safe.