Live data from Hacker News

Ask HN: Does your org use a password keeper?

news.ycombinator.com

51–60 of 74 posts

Re: Ask HN: Does your org use a password keeper?

#51
post #5

> gets very pricey with 10k users With that many users you don't pay the advertised prices. You schedule a call and they make sure you get an affordable offer. > The average employee likely has 10-20 (hopefully) different sets of credentials that they must maintain and update as necessary Time for azure, auth0, okta, or some other sso provider to just get rid of the passwords?

I'm really not cut out to work for a big corporation. Even if they charged $0.50/per user, that would be $5k/month. I could go as a consultant and charge half of that to setup vaultwarden integrated with their AD for maybe 2 lazy days, and offer a support contract for $500/month. It's not even that much of rare skill. I'd guess you can randomly selected /r/selfhosted users and I'd give 10% of odds to find someone who…

(Most) managers hate meetings just as much as you, and they're not wasting money for the fun of it. Every technical manager has inherited problems because someone at some point tried to save money by hiring a random dude on the cheap who just half assed it.

You go with companies that can demonstrate scalability because they provide project governance, proper change management, and layers of redundancy and support in the event of an emergency.

Re: Ask HN: Does your org use a password keeper?

#52
post #51

Earlier quoted context omitted.

I'm really not cut out to work for a big corporation. Even if they charged $0.50/per user, that would be $5k/month. I could go as a consultant and charge half of that to setup vaultwarden integrated with their AD for maybe 2 lazy days, and offer a support contract for $500/month. It's not even that much of rare skill. I'd guess you can randomly selected /r/selfhosted users and I'd give 10% of odds to find someone who…

(Most) managers hate meetings just as much as you, and they're not wasting money for the fun of it. Every technical manager has inherited problems because someone at some point tried to save money by hiring a random dude on the cheap who just half assed it. You go with companies that can demonstrate scalability because they provide project governance, proper change management, and layers of redundancy and support in…

When I was working at Deutsche Telekom, I actually heard the CIO from a German Bank say they "were not interested in our (Chromebook-like) solution, because if adopted it will be a lot cheaper than their current windows licenses and that would mean he would lose his budget in 2 years".

Also, the idea that someone charging $2k for two days of work is considered "doing it on the cheap" is almost offensive.

Re: Ask HN: Does your org use a password keeper?

#53
post #51

Earlier quoted context omitted.

(Most) managers hate meetings just as much as you, and they're not wasting money for the fun of it. Every technical manager has inherited problems because someone at some point tried to save money by hiring a random dude on the cheap who just half assed it. You go with companies that can demonstrate scalability because they provide project governance, proper change management, and layers of redundancy and support in…

When I was working at Deutsche Telekom, I actually heard the CIO from a German Bank say they "were not interested in our (Chromebook-like) solution, because if adopted it will be a lot cheaper than their current windows licenses and that would mean he would lose his budget in 2 years". Also, the idea that someone charging $2k for two days of work is considered "doing it on the cheap" is almost offensive.

Relative to the enterprise vendor, that is very much on the cheap. I wasn't placing any value on your work, I was referring to the ubiquitous "I know a guy" cost cutting solutions that end up somehow being very, very expensive in the end.

Re: Ask HN: Does your org use a password keeper?

#54
post #53

Earlier quoted context omitted.

When I was working at Deutsche Telekom, I actually heard the CIO from a German Bank say they "were not interested in our (Chromebook-like) solution, because if adopted it will be a lot cheaper than their current windows licenses and that would mean he would lose his budget in 2 years". Also, the idea that someone charging $2k for two days of work is considered "doing it on the cheap" is almost offensive.

Relative to the enterprise vendor, that is very much on the cheap. I wasn't placing any value on your work, I was referring to the ubiquitous "I know a guy" cost cutting solutions that end up somehow being very, very expensive in the end.

I didn't mean offensive to me, the offensive part is to think as a shareholder or a taxpayer hearing that this kind of problem actually warrants so much money.

I know that people can come up with many perfectly reasonable justifications to spend this much on a service, but to someone like me who grew up in a poor country dealing with recession and austerity policies, it's hard to see these things and not thing "surely we can achieve the same results spending less?"

Re: Ask HN: Does your org use a password keeper?

#55

Earlier quoted context omitted.

> There's a feature where you can even share the login to a site on it, but they can't view the password - only lastpass can fill it up. Prime example of Lastpass security theater - what exact problem did they think this feature solved?

People easily copying and pasting the password into a chat app to quickly share it with Greg from finance asking if he could just quickly log into the app even though he's not really supposed to? Sure, its not too hard to get around that feature, you could just inject your own javascript on the page to dump the contents of the password field. But it does block the low hanging fruit of the millions of users who don't…

The people likely to do such things counter to security are going to click phishing links, install malware and misuse their company devices anyway. Their problem is not technological in nature to solve - it is personal and behavioral. I call it theater because it doesn't significantly improve the security posture and maturity, while making both the user and administrator feel tough and hardened.

Re: Ask HN: Does your org use a password keeper?

#56
post #37

Earlier quoted context omitted.

IMO, 1Password has much much better UX than Vaultwarden has. So you definitely get something for the money.

That's the other part that breaks my lizard brain. We are talking about $5k/month vs $500. If the UX of the FOSS version is lacking, pay for the closed version BUT throw $1000/month on the direction of the FOSS developers until the issues are mitigated and they satisfy your requirements. I can bet that in less than a year you'd be able to make a switch and the investment would pay itself.

> BUT throw $1000/month on the direction of the FOSS developers until the issues are mitigated and they satisfy your requirements

This is not at all an easy thing to guarantee even if you’re willing to spend the money. The FOSS developers might not be interested in doing this work (even for pay) nor have UX staff.

Re: Ask HN: Does your org use a password keeper?

#58

Earlier quoted context omitted.

That's the other part that breaks my lizard brain. We are talking about $5k/month vs $500. If the UX of the FOSS version is lacking, pay for the closed version BUT throw $1000/month on the direction of the FOSS developers until the issues are mitigated and they satisfy your requirements. I can bet that in less than a year you'd be able to make a switch and the investment would pay itself.

> BUT throw $1000/month on the direction of the FOSS developers until the issues are mitigated and they satisfy your requirements This is not at all an easy thing to guarantee even if you’re willing to spend the money. The FOSS developers might not be interested in doing this work (even for pay) nor have UX staff.

Do you have any idea how much "developer power" you can buy with $1000/month, if you just look in the right places?

So many talented people working for that money or less in São Paulo, Buenos Aires or Hanoi, it would be worth it to give it a shot even if they just worked part-time.

Re: Ask HN: Does your org use a password keeper?

#59

Earlier quoted context omitted.

People easily copying and pasting the password into a chat app to quickly share it with Greg from finance asking if he could just quickly log into the app even though he's not really supposed to? Sure, its not too hard to get around that feature, you could just inject your own javascript on the page to dump the contents of the password field. But it does block the low hanging fruit of the millions of users who don't…

The people likely to do such things counter to security are going to click phishing links, install malware and misuse their company devices anyway. Their problem is not technological in nature to solve - it is personal and behavioral. I call it theater because it doesn't significantly improve the security posture and maturity, while making both the user and administrator feel tough and hardened.

> The people likely to do such things counter to security are going to click phishing links, install malware and misuse their company devices anyway.

Are you arguing that because they might make mistakes elsewhere we shouldn't bother putting any barriers up to them breaking policy, and that the only thing we should do is more training? I'd argue both things should be done. I do agree preventing LastPass from directly exposing the password isn't a very strong protection, but lets not act like it doesn't prevent any kind of password abuse. Sure, users should be more trained, but we should also create more barriers to prevent them from shooting off their toes.

It almost sounds like an argument to get rid of barriers on highways. Drivers should just know to not drive off the cliff; if people are driving off the highway clearly all we need to do is train them more. Barriers are just safety theater, people might still end up driving off the cliff if they try hard enough!

You asked for a use case for this feature and I gave you a use case that happens all the time and which such a feature prevents a large percentage of those users. You'd need someone determined to break the policy to dump the password and share it someplace they shouldn't, as opposed to someone doing it without thinking "is this against policy? shrug"

Post reply on HN