Tangential question: What password manager do you guys use?
Work is switching to Bitwarden due to easier ability to integrate into our environment than 1Password.
111–118 of 118 posts
Tangential question: What password manager do you guys use?
Work is switching to Bitwarden due to easier ability to integrate into our environment than 1Password.
Tangential question: What password manager do you guys use?
Now I'm testing waters with bitwarden. I like the cross platform functionality so far and the self hosting option. I also like that I just need a master password and don't have to worry about keeping any extra keys safe. I'm not a security expert so I'm not sure whether encrypting before syncing with bitwarden servers is actually safe (this is what bitwarden does afaik). I'm yet to try out their cli option. I also wonder what would happen to my passwords if it shuts down abrubtly. Do I have a backup/copy of the passwords somewhere? This is something that concerns me, where I feel pass is superior. Maybe if there was an option for pass, to use passphrase for encryption rather than gpg, that'd be really cool (maybe not good security wise? I'm unsure on this aspect)
I also liked that when I add the URI of the website login, it gives the icon for it too. Bitwarden's user experience is top notch. I recommended my parents to try it out, except for a few basic questions they were up and running within a few minutes. That's something I really appreciate.
If anyone has self hosted bitwarden, how do you make sure that it is safe from attacks? I'm still exploring this option. Bitwarden uses azure and lets the MS team take care of managing the infra (I'm guessing this includes taking care of attacks).
Which password manager(s) would you guys suggest for a team of 10-15?
Depends on what you need. Do all people need access to all passwords? Do you need to know which passwords a certain person accessed so you don't have to rotate everything when they leave?
Which password manager(s) would you guys suggest for a team of 10-15?
If you don't need to share passwords: KeePassXC. If you do need to have shared passwords (dev/stage/prod servers and services) why not Bitwarden for Business? https://bitwarden.com/#organizations
Earlier quoted context omitted.
I think that was the point of the previous comment. That, despite the software being open-source and therefore more likely to have bugs spotted, and despite having a bug bounty program, the auditing company found a moderate, therefore they must be thorough.
> ...therefore they must be thorough. I wonder if that's the case here. I don't work in that space but the issues they found seem like they might be low hanging fruit. I've pasted them below for anyone that's curious. > The Cross Origin Resource Sharing (CORS) configuration on Bitwarden server APIs allows for any clientorigin to access its endpoints. > The Content Security Policy (CSP) configuration on the Bitwarden…
If they were appropriately thorough and all they found were low-hanging fruit, then that is a good thing.
Of course a detailed report is no absolute guarantee: we once had a test done that I think was more than shoddy: there was not nearly enough activity on the web server over the testing period for the amount of automated work they claimed to have done, and I spotted an issue a couple of weeks later that at least one of their documented processes really should have picked up on. That company is no longer in business thankfully.
Earlier quoted context omitted.
When I did pentesting for a consulting firm the daily rate was £2000-2500 (depending if we had to pay reverse VAT for non UK/SM clients, and some other factors) we worked with financial firms and software companies primarily, there for remote on-site would be the same + expenses. More bespoke services like proper red teaming, DDoS simulation IOT/connected cars/hardware were about double that. £800 a day is the very b…
Let me guess, Big-4? boutiques in the UK don't usually charge that kind of day-rate and the big banks all use their purchasing power to get day rates down. £800/day is low, but not unheard of especially if you use freelancers/small boutiques, but £2k/days is more than I've seen for most things in the UK.
We didn’t really deal with retail banks the banking clients would be investment and asset management banks like RaboBank.
Earlier quoted context omitted.
When I did pentesting for a consulting firm the daily rate was £2000-2500 (depending if we had to pay reverse VAT for non UK/SM clients, and some other factors) we worked with financial firms and software companies primarily, there for remote on-site would be the same + expenses. More bespoke services like proper red teaming, DDoS simulation IOT/connected cars/hardware were about double that. £800 a day is the very b…
Sounds a bit much. Could you have names of firms running this sort of service? and are they recruiting? When I was working in financial firms, there were internal red teams running vulnerability scanners or manual pentest (manual requires much more planning and coordination) . No point in paying external firms £10k per app to run an automated test. I am gonna have to consider changing side if audit firms are really b…
Tangential question: What password manager do you guys use?
For more important things I use KeePass and keep it all offline.