paint-brush
Uber & Thycotic: Are Password Vaults a Huge Security Vulnerability?by@jamesbores
41,489 reads
41,489 reads

Uber & Thycotic: Are Password Vaults a Huge Security Vulnerability?

by James Bore4mOctober 3rd, 2022
Read on Terminal Reader
Read this story w/o Javascript

Too Long; Didn't Read

Security is complicated and managing credentials is tough. A 17 year old hacker, TeaPot, got hold of the credentials of an Uber contractor and began sending multi factor authentication requests to them repeatedly. Once the contractor got annoyed and hit accept, their account was used to access a script with admin credentials to Uber's password vault, Thycotic, giving them access to almost everything else.

Companies Mentioned

Mention Thumbnail
Mention Thumbnail
featured image - Uber & Thycotic: Are Password Vaults a Huge Security Vulnerability?
James Bore HackerNoon profile picture
James Bore

James Bore

@jamesbores

Security professional, homebrewer, amateur butcher, techie, board gamer, and beekeeper.

About @jamesbores
LEARN MORE ABOUT @JAMESBORES'S
EXPERTISE AND PLACE ON THE INTERNET.
L O A D I N G
. . . comments & more!

About Author

James Bore HackerNoon profile picture
James Bore@jamesbores
Security professional, homebrewer, amateur butcher, techie, board gamer, and beekeeper.

TOPICS

Languages

THIS ARTICLE WAS FEATURED IN...

Permanent on Arweave
Read on Terminal Reader
Read this story in a terminal
 Terminal
Read this story w/o Javascript
Read this story w/o Javascript
 Lite