This story was originally published on HackerNoon at: https://hackernoon.com/uber-and-thycotic-are-password-vaults-a-huge-security-vulnerability.
The Uber hack showed that password vaults come with a security risk. Still, if set up correctly they improve security for companies.
Check more stories related to cybersecurity at: https://hackernoon.com/c/cybersecurity.
You can also check exclusive content about #cybersecurity, #password-security, #password-manager, #uber, #security, #hack, #hackernoon-top-story, #blogging-fellowship, #hackernoon-es, #hackernoon-hi, #hackernoon-zh, #hackernoon-vi, #hackernoon-fr, #hackernoon-pt, #hackernoon-ja, and more.
This story was written by: @jamesbores. Learn more about this writer by checking @jamesbores's about page,
and for more stories, please visit hackernoon.com.
Security is complicated and managing credentials is tough. A 17 year old hacker, TeaPot, got hold of the credentials of an Uber contractor and began sending multi factor authentication requests to them repeatedly. Once the contractor got annoyed and hit accept, their account was used to access a script with admin credentials to Uber's password vault, Thycotic, giving them access to almost everything else.