Company
Date Published
Author
Richard Huffaker
Word count
1394
Language
English
Hacker News points
None

Summary

ThisData was an API-first risk engine that provided a score of whether the pattern looked consistent against normal traffic. Rich Chetwynd, Product Manager at OneLogin, joined ThisData as its founder and CEO after it was acquired by OneLogin. The service used various indicators from web transactions to create a risk score for each user, including browser or device information, IP locations, and attributes. The system would merge aliases from multiple profiles online, allowing users to be identified across different sources. However, the alias matching had gotten confused, resulting in false positives about breaches. Rich Chetwynd realized that the issue was due to a bug in the system's handling of alias shifts, particularly when employees left the company and their email addresses were reassigned. The initial fix involved changing the sync with Google from daily to hourly, but ultimately led to shutting down the integration altogether. Despite the setback, the incident helped improve the service, and the customer was able to test their internal processes and respond quickly in case of a potential breach.