From a simple KeePass database to enterprise credential management solutions—what’s your setup at work?
correct horse battery staple
Always a relevant xkcd
Not today, Russia.
Scribbled on the whiteboard in the office.
jk
I would never scribble my password on a whiteboard. It’s important to write in large clear letters so I can read it from across the lab.
I don’t understand the extreme love for Bitwarden. I understand it’s useful, but I want as few things with a webui and server instance as possible, especially passwords, the thing that should be most secure.
KeePass, vault saved into the user’s One Drive synced folder is sufficient. It’s secure, offline, and automatically makes backups. And migrates to the new system just by logging into One Drive.
Bitwarden and others worry me because they have a lot of exposed attack surface, comparatively, and require much more maintenance to keep secure imo. I don’t want to expose any of that to a portal or anything.
That said, I don’t hate Bitwarden, the bitwarden/vault warden software is incredibly solid for what it is.
OneDrive
offline
…shoukd we tell them?
The method of champions. Post-it on the bottom of keyboard.
Got a thrift store keyboard. The pink sticky on the bottom said:
User: admin
Pass: password
I wish I was joking. Someone out there was dumb enough to need a reminder on that one.
Bottom of keyboard? Are you out of space on your monitor to place additional Post-its with user credentials on them? /s
Boss, I need a third monitor, I’m out of space for post-its


