How about AWS KMS?
Ask HN: Does your org use a password keeper?
71–74 of 74 posts
Re: Ask HN: Does your org use a password keeper?
#72Earlier quoted context omitted.
this is somewhat a pipedream orgs should support what people do
I'll try that reasoning with my PCI/DSS auditors next time. Let's see what they think about that. If you think I'm being hyperbolic, I'm not. Our org has recently gone through a PCI/DSS audit, and there was a lot of frustration about the amount of required changes with regards to locking down access policies, tracking suspicious activity, enforcing 2FA and such, but most of the stuff that I saw change was stuff that…
it's already a part of secret management for machines in secure cloud environments
Re: Ask HN: Does your org use a password keeper?
#73We don't have use a password manager for most users, but for those with access to many and varied accounts (like IT and anyone dealing with social media) we use VaultWarden, which is a FOSS re-implementation of BitWarden. We don't do any browser or AD integration though.
This is great! I didn't know this existed, but it looks like for self-hosting this is a much better solution than BitWarden proper (as it is lighter). This shall go on my synology.
Re: Ask HN: Does your org use a password keeper?
#74Earlier quoted context omitted.
Not all SaaS apps support SSO. We use 1password for those that don't.
Then don't give your business to them. Let them very clearly know "we will not purchase your services until you support SSO at a reasonable price". Otherwise they'll never learn.