Live data from Hacker News

Passbolt: Self hostable, open source, password manager for teams

passbolt.com

51–60 of 101 posts

Re: Passbolt: Self hostable, open source, password manager for teams

#51
post #46
post #36

Earlier quoted context omitted.

Password sharing is not a good idea, but sometimes or even often unavoidable.

I have the feeling that password sharing is only unavoidable in a company that doesn't care much about security. Any company that takes security seriously would, I suppose, have personal passwords as a strict requirement. They wouldn't use services that can't comply with this requirement.

Not necessarily true.

In the health insurance industry, for example, many insurance portals offer one account that has to be used by a team. And, in a team scenario where all staff need access to all third party vendor accounts, it can be simpler to share the one password rather than manage 10.

For on site systems under a company's control, they can enforce the policies. But third party resources are where the limitations are. It's not the company that's minimal on security hygiene, it's the non-tech vendor in many cases.

Re: Passbolt: Self hostable, open source, password manager for teams

#52
post #22

pass[0] has been the best of everything so far. gpg based and easy to use with keyboard shortcuts. i like alternatives like htis, but pass is super barebones and highly available. [0]: https://www.passwordstore.org/

Pass has got to be one of my favorite CLI tools and is descent third-party browser plugins and mobile apps. Gopass works well too, especially for Windows and is compatible. I wish someone would build a bookmark manager using a similar concept.

Re: Passbolt: Self hostable, open source, password manager for teams

#53
post #32
post #20

Earlier quoted context omitted.

More like "fauxpensource". All the useful features are part of the expensive looking Business plan. I don't mind people charging money for software, but I really wish they wouldn't pretend to be open source when they're not.

The paid version is also distributed under Open Source license, but is not free (as in free beer).

How does that work? If it's open source, I can get the source and run it for free, hell, I could even redistribute it for free. What's stopping me from doing this? I assumed it was that the non-free features were distributed under a proprietary license which comes with an invoice attached?

Re: Passbolt: Self hostable, open source, password manager for teams

#54
post #51
post #46

Earlier quoted context omitted.

I have the feeling that password sharing is only unavoidable in a company that doesn't care much about security. Any company that takes security seriously would, I suppose, have personal passwords as a strict requirement. They wouldn't use services that can't comply with this requirement.

Not necessarily true. In the health insurance industry, for example, many insurance portals offer one account that has to be used by a team. And, in a team scenario where all staff need access to all third party vendor accounts, it can be simpler to share the one password rather than manage 10. For on site systems under a company's control, they can enforce the policies. But third party resources are where the limita…

> In the health insurance industry, for example, many insurance portals offer one account that has to be used by a team.

Sorry, but are you kidding me? Do these companies pass security audits?

This only shows that security is near the bottom of the priority list for these companies, probably right above privacy.

Re: Passbolt: Self hostable, open source, password manager for teams

#56
post #53
post #32

Earlier quoted context omitted.

The paid version is also distributed under Open Source license, but is not free (as in free beer).

How does that work? If it's open source, I can get the source and run it for free, hell, I could even redistribute it for free. What's stopping me from doing this? I assumed it was that the non-free features were distributed under a proprietary license which comes with an invoice attached?

It's the same model than redhat, you buy a subscription, and the software checks if you have a valid subscription. Nothing is stopping you from modifying the source to remove that check, re-build and re-distribute for free (or for a fee) under another name. This allows community-driven projects like Centos or Fedora to exist. It's an ambitious business model, which doesn't prevent other to compete. The bet is companies that rely on the service will want to pay and will prefer getting professional services / hosting from the original maintainers.

Re: Passbolt: Self hostable, open source, password manager for teams

#57
post #22

pass[0] has been the best of everything so far. gpg based and easy to use with keyboard shortcuts. i like alternatives like htis, but pass is super barebones and highly available. [0]: https://www.passwordstore.org/

Although I always appreciate alternatives being given on HN, I don't see how this competes with Passbolt. There's no password sharing between groups of an organization, which is exactly what Passbuilt is built for.

Personal password managers are great unless you want to share a list of passwords in a group within an organization.

Re: Passbolt: Self hostable, open source, password manager for teams

#58
post #2

I feel like this is becoming a very crowded market. What sort of differentiation separates this service from the pack? For my purchasing decision, I’d lean heavily on the probability the service will be there in 5 years (it’s obvious I’m getting older I guess), as the market seems pretty mature.

I did a pretty thorough review of PassBolt a couple of years back when I was trying really hard to get a company to adopt it and give up their "we store our all of our passwords on a spreadsheet" approach. I don't have my notes any more, but off the top of my head, the big points in favor were: - Self-hostable. The tech guy in charge just resolutely would not use any hosted service, period. In his evaluation, trustin…

> - Built with PHP. Same guy was uncomfortable with Python, Node, and all that, and insisted that he be able to maintain and troubleshoot the codebase himself if necessary, so it had to be PHP.

Now that's an interesting perspective, I don't think I've heard anyone consider PHP to be more secure than Python before.

Re: Passbolt: Self hostable, open source, password manager for teams

#59
post #53
post #32

Earlier quoted context omitted.

The paid version is also distributed under Open Source license, but is not free (as in free beer).

How does that work? If it's open source, I can get the source and run it for free, hell, I could even redistribute it for free. What's stopping me from doing this? I assumed it was that the non-free features were distributed under a proprietary license which comes with an invoice attached?

Well, the law and moral basically. What stops you from torrenting all your games and apps and not distributing them forward?
Post reply on HN