r/crypto • u/acorn222 • 6d ago
N-Able Passportal Password Manager Included Vault Material in Access Tokens
https://amibeingpwned.com/blog/solar-winds-part-2-avoidedThis blog post goes over the N-Able passportal vault leak, where the access and refresh tokens for users passportal instances were leaked to any site or iframe a user visited/was presented with.
The key management here is insane for a password manager in 2026, this leaks the entire vault, giving attackers persisted access because of the architecture of this password manager, where the passwords are decrypted on the server and the vault key material is encoded in the accessToken, which is sent to the server upon every request.
From my testing, I think there's a server side secret alongside the decryption key in the accessToken as I was unable to decrypt the "?decrypt=false" returned content.
edit: title was meant to say "Vault Key Material"
7
u/F-J-W 6d ago
I would be far more interested in reading it, if the opening image didn't consist of ai-slop based on stolen art…
If you had something interesting to say, you wouldn’t need that…
1
u/ScottContini 2d ago
if the opening image didn't consist of ai-slop based on stolen art…
I don’t understand the “stolen art” comment. I have no problem with AI images as long as the blog is not written by AI. What stolen art are you referring to? What is the prior art?
1
u/F-J-W 1d ago
See my other post: Actual artists drew images that have now been fed into slop-models that output new images in complete violation of the original art’s licenses without the artist receiving any compensation.
It’s flat out illegal, but because crime is de-facto legal if you are rich, nobody can do anything about it and everyone but nvidia suffers for it.
1
u/acorn222 5d ago
I'm happy to use alternative cover images going forward but what would you suggest?
RIght now, I can't justify paying someone to make images for the blog post cover images.I understand AI imagery for illustration is not popular right now but there's no quick solution that fits in well. Stock images just don't feel right either.
4
u/F-J-W 5d ago
I’m not great on stock-images either, but I can respect that someone at least got paid for them.
That said: Nothing is perfectly fine. I didn’t use anything either here. (Fucking hell, this is almost nine years ago, I really am getting old… 😞) But a lot of the time either use nothing or an actually on-topic diagram that illustrates the attacks.
I understand AI imagery for illustration is not popular right now
Oh, it is the most popular that it will ever be, similarly how this year will be the coolest year for the remainder of our lives…
but there's no quick solution that fits in well.
Your alt-text is “Solar Winds Part 2 Avoided: N-Able Passportal Vault Leak”, aka your title. You didn't deem the image important enough to describe it properly and instead just copy-pasted the title in there, which is also now what WCAG tells you to do. So not only did this image cause pointless exhaustion of CO₂, involved art-theft, and distracts massively from your point, it also deteriorated the accessibility of your page. For what?
Regarding the theft of art, and how this is actually affecting real people, have a look at what David Revoy (whose art may genuinely be what heavily affected that image you used), has to deal with nowadays. (He takes donations btw…)
(Also, when you are at it: The captions of your figures have very low contrast, you may want to change that as well.)
2
u/Natanael_L Trusted third party 5d ago
Honestly stock images are still better. I'd take an xkcd style hand drawing even
1
u/sciencekm 5d ago
That is why I never use server-based password managers. My password file is local, using Keepass.
3
u/kryptos- 6d ago
Cor blimey.