Which password manager(s) would you guys suggest for a team of 10-15?
If you do need to have shared passwords (dev/stage/prod servers and services) why not Bitwarden for Business? https://bitwarden.com/#organizations
81–90 of 118 posts
Which password manager(s) would you guys suggest for a team of 10-15?
If you do need to have shared passwords (dev/stage/prod servers and services) why not Bitwarden for Business? https://bitwarden.com/#organizations
Earlier quoted context omitted.
Bitwarden. Works well and the integration with 2FA/TOTP is amazing. I highly recommend to not rely on a single (mobile) device for 2FA. Loosing or breaking it might shut you out of certain accounts forever.
> Loosing or breaking it might shut you out of certain accounts forever. But isn't this what the backup codes are for?
I use the notes for each entry in Bitwarden to indicate what kind of 2FA I have enabled and whether I have a backup code already stored in the other vault.
Good to see. Aside from the Apple ecosystem's password management, Bitwarden is what I've been using.
Same. They are one of the few open source products with decent support across multiple platforms.
Tangential question: What password manager do you guys use?
I also use it at my company, and personally with my wife. Also got my mum to use it!
At my company, we also use it for server secrets, using envwarden: a simple wrapper we created and open-sourced[0] for managing server secrets with Bitwarden.
Earlier quoted context omitted.
Appsec pentester for 6 or so years: The 1-1.2k a day figure (GBP) is relatively low for 2020. I know you mentioned that i's been a while; just trying to shed some light. Boutique Firm X billed at 285/hr with an average of 60 hours for a small application. That comes out to $2,280 USD a day. Standard Small Consulting Firm Y billed at 250/hr. In the past 6 years I have yet to see anything below 235/hr, which is still $…
Worth noting that (IME) US day rates are a lot higher for pentest work :) your US rates sound similar to what I've seen but Morrbo's UK rates sound ballpark right for the UK (I'd have said a little higher but it does depend on the company and work)
More bespoke services like proper red teaming, DDoS simulation IOT/connected cars/hardware were about double that.
£800 a day is the very bottom of the price scale in the UK for general SME public sector companies.
What does it cost to hire somebody reputable to perform an audit like this? Its something I want to look into for one of my own projects, but I have no frame of reference for what is a reasonable price for a simple full stack app (way simpler than bitwarden for sure)
$8k - $12k for a "platform" that hires 100% outsourced pentesters of highly variable skill and quality, and takes no liability themselves, and whose pentesters are located in developing countries and good luck getting damages out of them, ever, regardless of their platform "reputation" pretend points. also communication tends to be difficult as the norm is ESL.
$25k for a US-based boutique firm with in-house pentesters of vetted high quality, who accept liability and against whom you can actually expect to enforce an NDA and/or extract other damages. source code and design audit starts at about this price.
then, you can run your own program on top of the bounty platforms, however scope and focused work is not going to happen (a lot of the work is boring), and it will cost you a lot of your own time. the money you save DIY is not worth your own time investment.
if you actually want a good pentest, go with a boutique, quality firm. if you want something to give to an auditor or to meet a VSA, go with cheap.
Earlier quoted context omitted.
Same. They are one of the few open source products with decent support across multiple platforms.
And finally pretty usable on mobile, too! I have waited for this and just migrated from 1password (which was very easy, despite I lost my structure... I wish there were an open password database standard which password managers would use)
Tangential question: What password manager do you guys use?
I'm currently using MacPass on macOS and KeePaasium on iOS, and syncing both through Dropbox. But that means I need my Dropbox credentials, in addition to the KeePass file secrets, if I lose both the Mac and the iPhone (after a fire or a robbery for example). Not sure I'm comfortable with that. I'm considering switching to 1Password or Bitwarden. But I'm not sure about BitWarden using the same password both for encry…
It all depends on the risk you’re trying to mitigate. A MITTM or a server attack won’t be able to gain access to your passwords, even if they intercept the data. A user with knowledge of your password or a key logged on your client could. However in either of those cases, you’re not protected all that much by having two passwords as opposed to one long one.
Tangential question: What password manager do you guys use?
It's good to see companies making reports public to provide some confidence that they're having reviews done, but in this case the scoping of this job seems a little odd, not sure if that's a bad reporting template or something else. Last page of the PDF indicates that they just did an external VA and pentest, but looking at their product set , I'd have expected (at least) a review of the web, desktop and mobile apps…
When I was a pentester, I once ran the numbers and concluded that each pen test must have cost some absurd amount of money for us to be profitable. And they do, because it’s effective. But I wanted to point out a likely possibility: they wanted to do what you were saying, and concluded a million dollars spent on a pentest was beyond reach.
a review of the web, desktop and mobile apps and the browser plugins
If a million dollars sounds like an overestimate, you’re right to be skeptical. But $270k seems entirely reasonable; that’s $30k per app, for 9 apps.
So it might be tempting to feel like “it’s just a browser plugin though. How can the cost be anywhere comparable?”
Because pentests are billed in days, and a day on a plugin is a day on an app.