Live data from Hacker News

Ask HN: Does your org use a password keeper?

news.ycombinator.com

31–40 of 74 posts

Re: Ask HN: Does your org use a password keeper?

#31
I think what you should be looking for is a Single Sign-on solution that integrates with your different systems and applications. It's a necessity when trying to have audit logs and proper and secure onboarding and offboarding solutions.

Things like Okta, OneLogin, GCP, AWS, Auth0 or Keycloak (self-hosted). A lot of products nowaday offers SSO integrations but often unfortunately at the highest tiers - see https://sso.tax/

Re: Ask HN: Does your org use a password keeper?

#32
Passbolt is a great open source option: https://www.passbolt.com/ It has the team collaboration functionality and is free & OSS. We run it on Digital Ocean via Docker. Once you get it working it's pretty fantastic- it has a Chrome/Brave extension that works just like 1Password and LastPass for auto-filling credentials. Highly recommend.

Re: Ask HN: Does your org use a password keeper?

#33
post #5

> gets very pricey with 10k users With that many users you don't pay the advertised prices. You schedule a call and they make sure you get an affordable offer. > The average employee likely has 10-20 (hopefully) different sets of credentials that they must maintain and update as necessary Time for azure, auth0, okta, or some other sso provider to just get rid of the passwords?

I'm really not cut out to work for a big corporation.

Even if they charged $0.50/per user, that would be $5k/month. I could go as a consultant and charge half of that to setup vaultwarden integrated with their AD for maybe 2 lazy days, and offer a support contract for $500/month. It's not even that much of rare skill. I'd guess you can randomly selected /r/selfhosted users and I'd give 10% of odds to find someone who has done it already and would even offer to do for less.

Yet, I think that most managers would simply prefer to go through all the negotiation meetings, all the internal procurement process just so they can justify the big boy expenses.

Re: Ask HN: Does your org use a password keeper?

#34

> The average employee likely has 10-20 (hopefully) different sets of credentials that they must maintain and update as necessary That's your red flag right there. All identities that are tied to individual people should be connected to SSO in some way, then there will be no juggling of passwords at all on the individual-person level. Then you only need some 2FA solution on top in your identity provider, for instance…

This is nice until you consider the network effects. People can often get away with the $5/user/month plan, until they need SSO, in which case it always becomes $30k a year.

SSO seems like the only way SaaS companies can make money, and what this HN post tells me is that even enterprises with 10k employees (!) still find that to be a little out of their price range. The state of the industry is kind of crazy, but that's why people are looking for an enterprise 1password account. Cheaper to pay them once than to pay 1000% markup on every SaaS you use.

Re: Ask HN: Does your org use a password keeper?

#35
post #6

LastPass is great. We can share credentials and secrets through it. There's a feature where you can even share the login to a site on it, but they can't view the password - only lastpass can fill it up.

We use LastPass and I hate it.

Specifically - the constant and inability to disable install the safari extension and hideous use of space / user layout.

Re: Ask HN: Does your org use a password keeper?

#36
post #18
post #6

LastPass is great. We can share credentials and secrets through it. There's a feature where you can even share the login to a site on it, but they can't view the password - only lastpass can fill it up.

Can't really agree with that. For me, LastPass is a huge annoyance (it wants to fill in passwords on pages that these passwords definitely don't belong to, and it prompts you to save passwords over and over again with no "don't save passwords on this page" checkbox), and its UI is not really good either (e.g. the floating "+" icon in the vault - if you want to create a new folder you have to hover over it , for other…

It's as much as a pain as you make it. For me if I keep it well organized I basically just forget that I have to login to things at work, I just click them and I'm in or I navigate and it's filled.

I can see how it might not be the solution you want for home but at work I'm just trying to get things done and that unfortunately involves a large number of passwords that can't easily be federated into an SSO like okta because they span businesses clients and companies. I don't understand the hate for LastPass, for me it just works (tm)

Re: Ask HN: Does your org use a password keeper?

#37
post #5

> gets very pricey with 10k users With that many users you don't pay the advertised prices. You schedule a call and they make sure you get an affordable offer. > The average employee likely has 10-20 (hopefully) different sets of credentials that they must maintain and update as necessary Time for azure, auth0, okta, or some other sso provider to just get rid of the passwords?

I'm really not cut out to work for a big corporation. Even if they charged $0.50/per user, that would be $5k/month. I could go as a consultant and charge half of that to setup vaultwarden integrated with their AD for maybe 2 lazy days, and offer a support contract for $500/month. It's not even that much of rare skill. I'd guess you can randomly selected /r/selfhosted users and I'd give 10% of odds to find someone who…

IMO, 1Password has much much better UX than Vaultwarden has. So you definitely get something for the money.

Re: Ask HN: Does your org use a password keeper?

#39
we have a corporate 1pass account and I have a personal lastpass account. we use okta for SSO but 1pass is still absolutely essential IMO. I need to keep track of lots of secrets that aren't in okta (eg gitlab tokens and stuff like that).

Re: Ask HN: Does your org use a password keeper?

#40
post #5

> gets very pricey with 10k users With that many users you don't pay the advertised prices. You schedule a call and they make sure you get an affordable offer. > The average employee likely has 10-20 (hopefully) different sets of credentials that they must maintain and update as necessary Time for azure, auth0, okta, or some other sso provider to just get rid of the passwords?

Even with bulk pricing, the current enterprise providers are quite expensive. I'm a YC founder working with some others on a solution to this that brings the cost way down. If you're interested, send me a quick email and I'm happy to share what we've learned.
Post reply on HN