Jump to content

Recommended Posts

Posted

In all fairness, there is no such thing as a 100% secure product. It's just not possible. LastPass is probably the largest product in this segment, so people are going to attack it more than the others. That last breach, however, was just ridiculous.

 

I don't want you to think that I'm attacking your choices, btw! It's a good idea to review what products you're using periodically no matter how much you may or may not like them.

Posted
I'll look into it. There is an argument that a recently-hacked company might be more secure than another, as they would have had a thorough review of everything and beefed things up. You always buy a better bike lock for your second bike than you had for the first one which got stolen!
  • Thanks 1
Posted
I'll look into it. There is an argument that a recently-hacked company might be more secure than another, as they would have had a thorough review of everything and beefed things up. You always buy a better bike lock for your second bike than you had for the first one which got stolen!

 

I think in LastPass's case, they'd sellotaped their bike to a lamp post, so you can't be sure that 'better' in their case doesn't just mean duct tape.

Posted (edited)

@gshaw

 

I had a demo of BitWarden yesterday and also @jslate1980 uses BitWarden who gave me a quick deep dive into BitWarden's collections.

 

It would seem that you can give granular access to folders (ie, shared folders can contain shared folders) but not give granular access to items (logins, etc) in folders as these follow the permission from the folder they reside in. This is different to how Keeper works as Keeper does not allow you put a shared folder in a shared folder.

 

Collections

Top Level Folder

>Folder1

>Item1

>>Folder2

>>Item2

Edited by timbo343
  • Thanks 1
  • 10 months later...
Posted
On 09/12/2024 at 10:18, mraerosmith said:

self hosted passbolt instance here

Are you happy with it? I came across it last week and if it does what it claims I think it could be what we're looking for. It can't find many reviews - looks like a bit of a niche product.

Posted
17 hours ago, Netwacky87 said:

Just wanted to revisit this thread, i'm looking at password managers at the moment...anybody have a strong recommendation? Keeper looks good for us so far.

We've been using 1 Password for a few years now and really happy with it.

Posted

Yep we are very happy with it, it does what it says on the Tin, and as it is internally hosted, we are the masters of our own destiny, when it comes to the security piece for it

  • Thanks 1
Posted

Bitwarden is what we use. 

 

Good option as it can be segregated via groups (collections). 

Cloud based.

Good user management

Different types of fields are configurable to hide username/passwords etc. 

  • 2 weeks later...
Posted

You could buy something like an IronKey storage drive which will be encrypted and password protected, plug that into the back of a server or protected workstation that is locked away. Put KeePass portable on it which will then store your password database, KeePass also encrypts the database. Then you need to logon to the correct server to unlock the IronKey to unlock the KeePass database - just make sure you keep some kind of emergency access sheet as well! 

 

That said, this only really works well for IT admins for the keys to the IT kingdom given its obscure access requirements! 

Posted

Only just seen this so probably of no use to you now @timbo343

I used KeePassXC at the Trust for years. Stick the database file in Teams and your IT staff can access it anywhere. Recently rolled it out here to the IT team. With it being KeePass based there's plenty of options for how to open it so I've used KeePass2Android and Strongbox for iOS as well. I have two databases in place, one for just me and a shared one for the IT staff. The browser plugin can read from both when they are open.

Set it up for the finance team as well when I found out they were basically storing all their passwords in plaintext in an Excel file.

Many years ago I had used LastPass but binned them off when they got taken over. Quite happy that I have control of which cloud I stick my password data in and encrypt it myself. The only issue I've had is that occasionally OneDrive will freak out on the sync and create a duplicate database. However, KeePassXC has a merge database option in it so I just run that and delete the duplicate every so often.

Posted
On 05/12/2024 at 00:11, timbo343 said:

I'm looking at password managers for our teams and at the moment I've whittled it down to either Keeper or 1Password though I've not looked at Dashlane.

 

I've looked at BitWarden but I feel it doesn't quite match Keeper or 1Password. To test BitWarden business I'd need complete a payment sign up to test it.

 

Keeper looks more granular and feels like it has a lot more features but I'm not sure about the Shared Folders aspect given that the Shared Folder resides with the person who created the shared folder, where 1Password gives you the ability to create vaults. It would be good if 1Password could give granular control on each of the vaults or have the ability to create folders within the vaults. If we created vaults for each site, I'd want to limit individuals / groups to what they could see in each of the vaults.

 

As we currently oversee about 12 different physical sites, it then comes down to management / organisation of how the stored credentials are stored. Would it be best to have it organised as School > System or System > School.  Using saviynt could actually help a lot — especially for a setup with many sites. Its identity-governance features make managing access and credentials across different systems more streamlined and secure. With Saviynt, you can better control who sees what, and easily adjust permissions if team members change or leave.

If it helps, we went through the exact same comparison a few months ago. Keeper definitely has more granular controls, but the shared-folder ownership model confused our team too — especially when someone leaves and you have to reassign things.

1Password’s vault system felt cleaner day-to-day, even if it’s a bit less flexible. For multi-site setups like yours, we found System > School easier to maintain, since most credentials were reused across locations. It reduced duplication and made permissioning simpler.

Posted (edited)

LastPass is the bottom of my list and I would not recommend due to the security breach which showed bad practice. I am aware there are many breaches but I am sure this could of been prevented in numerous ways.

 

Moved to Bitwarden which can be self hosted for the cost of a pro licence. Would always suggest a hardware key for MFA too especially to valuable resources.

 

 

Edited by Davit2005
Posted
2 hours ago, Davit2005 said:

LastPass is the bottom of my list and I would not recommend due to the security breach which showed bad practice. I am aware there are many breaches but I am sure this could of been prevented in numerous ways.

 

Moved to Bitwarden which can be self hosted for the cost of a pro licence. Would always suggest a hardware key for MFA too especially to valuable resources.

 

 

It can be self hosted for free with vaultwarden

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...