Use of 3rd party password trackers has been a periodic concern for our organization. We do B2B business with banks , so the temperature is increased somewhat. There are kinds of credentials we have access to that genuinely terrify me. I've been debating building an in-house solution for managing secrets, if for no other reason than to get all of this information off of 3rd party computers. No serious proposals have b…
If I were a bank customer, I would not want to hear your second paragraph…
At this small scale, everything is vendored out. Many times, 2+ different vendors will need to directly exchange something like a password for the bank's core system. Email is the preferred technique, typically with some theatrical secure email crap on top - involving yet another 3rd party in the secret exchange mess.
As you get into the scale of an organization like Capital One or BofA, you start to see more of that Hollywood-style credential exchange & control with multiple consenting parties, Iron Mountain trash cans, biometric doors and one-time passwords.
If you are concerned about the IT/security of your financial institution, you may prefer larger ones. These have more employees running just IT compliance than many of our clients have in total.
If you are concerned about bad customer service or losing access to funds, you may prefer smaller ones. Being able to realistically talk to a board member of the bank about a dispute makes a lot of people feel better about where their money is.