HomeSecurityOneLogin: Security Breach That Exposed Secure Notes

OneLogin: Security breach that exposed Secure Notes

OneLogin announced a server security breach that allowed an attacker to gain access to customers' Secure Notes thanks to a bug in the company's logging processes.

The San Francisco-based startup, which provides a relatively popular SSO (Single-Sign-On) service, detailed a series of unfortunate events that led to a serious and disturbing security breach.

OneLogin: Security breach that exposed "Secure Notes"

OneLogin says the data breach began when an attacker managed to gain access to one of its employees' credentials for a server used to store logs and analytics information.

The attacker had access to the system in question between July 2, 2016, and August 25, 2016, when the company discovered the breach.

While under normal circumstances the attacker would have been faced with a few boring and useless lines of logging, OneLogin says a bug in the logging system exposed the data from Secure Notes in plain text.

OneLogin offers Secure Notes to its customers as a notepad utility that stores text information on the company's servers in encrypted form. On its website, the company also recommends that customers use Secure Notes to store passwords and license keys.

According to Alvaro Hoyos, Chief Information Security Officer at OneLogin, its Secure Notes system that encrypts data using multiple layers of AES-256 encryption had a bug that made notes visible in log files in plain text.

The attacker had access to all Secure Notes created and edited between July 25 and August 25, a period during which the bug was present in the system and the attacker had access to the server.

OneLogin says that, aside from the content of some Secure Notes, customers' personal information was never compromised, similar to the rest of OneLogin systems.

Meanwhile, Hoyos says OneLogin has strengthened server security with authentication and has whitelisted access to internal systems to only a limited set of internal IP addresses.

Additionally, OneLogin says it has reset all passwords for all systems that do not support SAML authentication, as a precautionary measure, in case the attacker manages to escalate their access to other parts of their infrastructure.

The company notified users of the incident and advised them that some of their Secure Notes may have been exposed, so they could take appropriate precautions. A copy of that email can be read below:

secure-notes

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS