From a simple KeePass database to enterprise credential management solutions—what’s your setup at work?

  • @stoy@lemmy.zip
    link
    fedilink
    2
    edit-2
    3 days ago

    Keepass.

    Backed up in the cloud, with a long password with plenty of non english characters in the password.

    For learning new passwords, I write them down on a note in my wallet, without any explanation of where they lead or what username to use.

    • partial_accumen
      link
      fedilink
      186 days ago

      Bottom of keyboard? Are you out of space on your monitor to place additional Post-its with user credentials on them? /s

    • @shalafi@lemmy.world
      link
      fedilink
      English
      45 days ago

      Got a thrift store keyboard. The pink sticky on the bottom said:

      User: admin

      Pass: password

      I wish I was joking. Someone out there was dumb enough to need a reminder on that one.

    • @cron@feddit.orgOP
      link
      fedilink
      36 days ago

      I would need a small book hidden under my keyboard. My work password safe has approximately 100 entries.

  • Refurbished Refurbisher
    link
    fedilink
    18
    edit-2
    6 days ago

    I write it in plaintext then email it to myself. For my email password, I write that down on a sticky note next to my monitor with my webcam pointing towards it with Skype and Zoom always running so I can look at it when I’m not at home. I always make sure to turn 2FA off as well, since that gets annoying and isn’t very convenient.

    I might choose to mirror the webcam stream to a public RTMP stream later, but not sure yet, since I think that might open up some security holes.

  • @rumba@lemmy.zip
    link
    fedilink
    English
    85 days ago

    Bit Warden, one password, whatever float your boat just not last pass.

    For SHTF stuff GPG.

  • @cron@feddit.orgOP
    link
    fedilink
    10
    edit-2
    6 days ago

    We use Netwrix Password Secure at work. They just announced this week they have found a RCE vulnerability in their software…

  • slazer2au
    link
    fedilink
    English
    86 days ago

    We use PasswordState at work and KeePassXC for personal passwords.

  • @skooma_king@lemm.ee
    link
    fedilink
    66 days ago

    Bitwarden/KeePass for MFA (not SMS or email) protected accounts. Pen and paper stored in a fire proof vault for non-MFA and break glass accounts.

  • @jplee@lemmy.world
    link
    fedilink
    66 days ago

    As an admin for a Linux server, I want to institute a ssh pub key expiration policy for all the users and enforce non-reuse of old keys. Does anyone have a best solution for this?

  • @Godort@lemm.ee
    link
    fedilink
    66 days ago

    We use ITGlue because it lets us tie password records to documentation which makes finding things very streamlined.

    Personally, I use Bitwarden

  • @lightnsfw@reddthat.com
    link
    fedilink
    45 days ago

    At work I keep them in onenote (they are encoded) because they won’t let us install an actual password manager and half the shit I log into doesn’t support SSO/doesn’t have it set up and is all on different password schemes. Our service account passwords are in a shared cyberark vault.

  • Astigma
    link
    fedilink
    English
    5
    edit-2
    6 days ago

    We have a KeePass DB as a fallback but mostly use a PAM solution to manage server access.