When AI Operates with User Credentials: Accountability Gaps at N-able and Beyond

When AI Operates with User Credentials: Accountability Gaps at N-able and Beyond

A persistent governance gap is evident in current IT operations, as credential management and authorization checks fail to keep pace with increased automation and AI integration. This is visible in incidents involving major vendors such as N-able (through Passportal), Anthropic’s Claude, AI-based retail management at Andon Labs, and legacy industrial controllers monitored by agencies like the NSA, CISA, and FBI. The episode highlights how systems are increasingly reliant on automated actors and credentialed assistants, while foundational questions of access rights and accountability remain unresolved.

The most consequential case centers on a vulnerability in N-able's Passportal browser extension, disclosed by security researcher James Arnott. The flaw allowed any website—or embedded ad—to request and obtain session tokens, enabling decryption of entire password vaults. This affected approximately 2,500 MSPs and 165,000 SMBs, with each stolen token remaining valid for 100 days. N-able patched the issue quickly, but Dave Sobel emphasizes that the responsibility for checking permitted actions within such systems is often misattributed or left unaddressed.

Supporting developments reinforce this governance gap. An AI assistant exploited poor authorization in an Australian gym reservation system, canceling another user’s booking without hacking or unauthorized login. Similar risks persist in industrial environments, where controllers for energy, water, and agriculture often lack basic authentication—exposing them to AI-generated exploitation scripts, according to joint agency warnings. Additionally, retail automation at Andon Labs revealed AI-driven policy lapses, where systems cannot reliably document or enforce their own rules, highlighting operational weaknesses.

Operationally, MSPs face increased risk from both their own service infrastructure and client environments. The practical recommendation is to issue discrete, revocable credentials tailored to each system agent, limiting their scope and ensuring traceable accountability. Providers are advised to formally define and document their responsibility boundaries regarding access and permissions in third-party applications. These steps shift the focus from attempting to control every client-side variable to clear documentation and compartmentalization, reducing dispute risk and speeding incident investigations.

00:00 The Gym Class and the Vault

03:39 The Check Was Always a Person 

06:37 Your Tools Ask the Wrong Question

10:27 Why Do We Care? 

 

Supported by: 

GoTo(LogMeIn)
Proofpoint 

💼 All Our Sponsors

MSP Radio is supported by our partners:

ABC Solutions · CometBackup · Guardz · HaloPSA · LogMeIn · OpenText · Pax8 · Proofpoint · Rythmz · ScalePad · TimeZest · Transit AI · USecure

Supporting the IT services community through insights, analysis, and transparency.

🚀 Join Business of Tech Plus

Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.

👉 https://businessof.tech/plus

🎧 Subscribe to the Business of Tech

Want the show on your favorite podcast app or prefer the written versions of each story?

📲 https://www.businessof.tech/subscribe

📰 Story Links & Sources

Looking for the links from today’s stories?

Every episode script — with full source links — is posted at:

🌐 https://www.businessof.tech

🎙 Want to Be a Guest?

Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:

💬 https://www.podmatch.com/hostdetailpreview/businessoftech

🔗 Follow Business of Tech

LinkedIn: https://www.linkedin.com/company/28908079

YouTube: https://youtube.com/mspradio

Bluesky: https://bsky.app/profile/businessof.tech

Instagram: https://www.instagram.com/mspradio

TikTok: https://www.tiktok.com/@businessoftech

Facebook: https://www.facebook.com/mspradionews


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.