Skip to content

Comment on OneLogin: Breach Exposed Ability to Decrypt Dataparent

Comments

Sounds a lot like the private key to decrypt this information was stored alongside the data in the database... whoops!

Not necessarily, even if this was done "properly" there is no guarantee that from the internal network there wasnt a separate exploit that the attacker could use to gain access to a different node which had the key in memory. With breakages like these you generally have to assume that anything that is theoretically possible has happened.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.