Not a full fledge solution but useful for quick one time sharing. Curious if people here find it helpful.
Ask HN: How to store and share passwords in a company?
121–130 of 297 posts
Re: Ask HN: How to store and share passwords in a company?
#122Rippling's Rpass is a good example of effective implementation.
You can deploy passwords on day 1 based on roles, dept etc.
You can also set passwords to be hidden , not shared etc.
SSO is best practice but this is by far the most effective way for vendor account management.
Oh if you are doing this make sure you have set up group-based SSO.
Re: Ask HN: How to store and share passwords in a company?
#123Earlier quoted context omitted.
> Yes, but they should be unique to your account. I.e. via SSO. This is a great best practice, but user-based value metrics for many SaaS platforms make this untenable for some IT departments. If folks have to log in seldomly, it's very hard to make the business case to pay per user. Similarly, there's many SaaS platforms that charge A LOT extra for SSO because you have to upgrade to their Enterprise-pricing model. I…
Is sharing accounts not against the TOS of any user priced saas company?
Re: Ask HN: How to store and share passwords in a company?
#124- Use 1Password or similar password vault to deliver account passwords on day one; the password manager also promotes good personal password management practices - only share passwords for personal accounts; those accounts you terminate when the employee separates. For shared resources, use SSO and SCIM group management via the SSO provider to add and remove accounts from groups with different roles. Rippling seems l…
OOI do you ever use SCIM for something really granular? I have a service where people can be one of 5 roles and then have access to 1..30 named 'workspaces' - all that we'd like to control with policy on our side not vendor side I think it's unsuitable for SCIM because I'd have to create 5*30 AD groups?
Re: Ask HN: How to store and share passwords in a company?
#125Re: Ask HN: How to store and share passwords in a company?
#126Don't. Give them access to all systems they need with their own user/password. That way you can revoke them (if/when necessary) without disrupting everyone else. Also automate as much as is reasonable, e.g. github access to push code to a dev branch, then enqueue merging of it. But a CI/CD pipeline does the actual deploy, the employee doesn't need to access any of the production systems. A very small number still wil…
Unfortunately, some services don’t allow this.
Re: Ask HN: How to store and share passwords in a company?
#127You generally want to minimize the number of passwords you manage; for instance, you should generally be paying the SSO tax and getting as many services as you can onto OIDC. After that, just do the cloud version of 1Password, which is easy to audit and manage access for, which you'll thank yourself for when it comes time to SOC2. Remember, as you give people access to passwords, that those passwords will need to be…
Re: Ask HN: How to store and share passwords in a company?
#128Use Okta for SSO.
Re: Ask HN: How to store and share passwords in a company?
#1291Password for Teams for individual and group passwords. It’s great. Use Okta for SSO.
Re: Ask HN: How to store and share passwords in a company?
#130We always used 1Password[0]. We still use it in the open-source projects that I work with. I have heard that LastPass is about as good, but have no experience using it. The latest version of 1Password isn't so good, but it works fine. [0] https://1password.com