From a simple KeePass database to enterprise credential management solutions—what’s your setup at work?

  • Refurbished Refurbisher
    link
    fedilink
    22
    edit-2
    3 months ago

    I write it in plaintext then email it to myself. For my email password, I write that down on a sticky note next to my monitor with my webcam pointing towards it with Skype and Zoom always running so I can look at it when I’m not at home. I always make sure to turn 2FA off as well, since that gets annoying and isn’t very convenient.

    I might choose to mirror the webcam stream to a public RTMP stream later, but not sure yet, since I think that might open up some security holes.

    • @phanto@lemmy.ca
      cake
      link
      fedilink
      33 months ago

      Also, if you use a really easy to remember password… I like P@ssw0rd! Easy to remember, and nobody will ever guess it because, get this… The ‘o’ is actually a zero!

  • @stoy@lemmy.zip
    link
    fedilink
    2
    edit-2
    3 months ago

    Keepass.

    Backed up in the cloud, with a long password with plenty of non english characters in the password.

    For learning new passwords, I write them down on a note in my wallet, without any explanation of where they lead or what username to use.

  • @rumba@lemmy.zip
    link
    fedilink
    English
    93 months ago

    Bit Warden, one password, whatever float your boat just not last pass.

    For SHTF stuff GPG.

  • @cron@feddit.orgOP
    link
    fedilink
    11
    edit-2
    3 months ago

    We use Netwrix Password Secure at work. They just announced this week they have found a RCE vulnerability in their software…

  • Lena
    link
    fedilink
    English
    33 months ago

    Bitwarden self-hosted with vaultwarden on my Hetzner VPS

  • @jplee@lemmy.world
    link
    fedilink
    63 months ago

    As an admin for a Linux server, I want to institute a ssh pub key expiration policy for all the users and enforce non-reuse of old keys. Does anyone have a best solution for this?

  • @skooma_king@lemm.ee
    link
    fedilink
    63 months ago

    Bitwarden/KeePass for MFA (not SMS or email) protected accounts. Pen and paper stored in a fire proof vault for non-MFA and break glass accounts.

    • partial_accumen
      link
      fedilink
      183 months ago

      Bottom of keyboard? Are you out of space on your monitor to place additional Post-its with user credentials on them? /s

    • @cron@feddit.orgOP
      link
      fedilink
      33 months ago

      I would need a small book hidden under my keyboard. My work password safe has approximately 100 entries.

    • @shalafi@lemmy.world
      link
      fedilink
      English
      53 months ago

      Got a thrift store keyboard. The pink sticky on the bottom said:

      User: admin

      Pass: password

      I wish I was joking. Someone out there was dumb enough to need a reminder on that one.

  • BoofStroke
    link
    fedilink
    English
    23 months ago

    For actual sysadmin stuff? Ansible vaults. Things that are managed otherwise either in ssh blowfish encrypted files or the company 1password thing (not my choice)

    • @pinball_wizard@lemmy.zip
      link
      fedilink
      23 months ago

      I would never scribble my password on a whiteboard. It’s important to write in large clear letters so I can read it from across the lab.

  • @catloaf@lemm.ee
    link
    fedilink
    English
    23 months ago

    KeePassXC. We have an enterprise secret management product, but I don’t think we’re using this functionality yet.

  • slazer2au
    link
    fedilink
    English
    83 months ago

    We use PasswordState at work and KeePassXC for personal passwords.