TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

OneLogin data breach, all users in US datacenter affected

14 pointsby Goopplesoftalmost 8 years ago

1 comment

jtchangalmost 8 years ago
This is a huge deal. Depending on how deep the attackers got it could be considered a giant compromise of data at multiple companies. Imagine you had a single password that could let you into any app a company is using internally. Not only that but that single password could be used for any account. That&#x27;s basically what it means when your identity provider is compromised. Not only that but it is really hard to tell if it was a legitimate login because the assertions are perfectly valid.<p>If I was a company I&#x27;d seriously reconsider outsourcing my identity provider.