Ask HN: Does your org use a password keeper?
21–30 of 74 posts
Re: Ask HN: Does your org use a password keeper?
#22Of course, the UX of the free solution will never compete with the commercial solutions. If you want that, you have to pay.
Re: Ask HN: Does your org use a password keeper?
#23LastPass is great. We can share credentials and secrets through it. There's a feature where you can even share the login to a site on it, but they can't view the password - only lastpass can fill it up.
Prime example of Lastpass security theater - what exact problem did they think this feature solved?
Re: Ask HN: Does your org use a password keeper?
#24LastPass is great. We can share credentials and secrets through it. There's a feature where you can even share the login to a site on it, but they can't view the password - only lastpass can fill it up.
> There's a feature where you can even share the login to a site on it, but they can't view the password - only lastpass can fill it up. Prime example of Lastpass security theater - what exact problem did they think this feature solved?
Re: Ask HN: Does your org use a password keeper?
#25I don't face any annoyances sharing passwords with 1pass like I used to with lastpass, secretserver, etc. It's a smooth experience all the way.
Re: Ask HN: Does your org use a password keeper?
#26LastPass is great. We can share credentials and secrets through it. There's a feature where you can even share the login to a site on it, but they can't view the password - only lastpass can fill it up.
> There's a feature where you can even share the login to a site on it, but they can't view the password - only lastpass can fill it up. Prime example of Lastpass security theater - what exact problem did they think this feature solved?
Sure, its not too hard to get around that feature, you could just inject your own javascript on the page to dump the contents of the password field. But it does block the low hanging fruit of the millions of users who don't know how to do that who might abuse having access to the password because they don't really know better.
In essence, it helps to prevent those users who don't know better from leaking the password to places it shouldn't be. Obviously it doesn't prevent people who know how to get around it from getting around that protection, but in those circumstances you shouldn't really be sharing your password with someone who will abuse your trust.
Re: Ask HN: Does your org use a password keeper?
#27Re: Ask HN: Does your org use a password keeper?
#28> The average employee likely has 10-20 (hopefully) different sets of credentials that they must maintain and update as necessary That's your red flag right there. All identities that are tied to individual people should be connected to SSO in some way, then there will be no juggling of passwords at all on the individual-person level. Then you only need some 2FA solution on top in your identity provider, for instance…
orgs should support what people do
Re: Ask HN: Does your org use a password keeper?
#29Earlier quoted context omitted.
> There's a feature where you can even share the login to a site on it, but they can't view the password - only lastpass can fill it up. Prime example of Lastpass security theater - what exact problem did they think this feature solved?
Not having to rotate shared passwords after an employee leaves I suppose?
Re: Ask HN: Does your org use a password keeper?
#30My personal benefit was that the convenience of using password managers finally pushed me to use Bitwarden+2FA on all my personal devices.