Hi All,

Just a quick one, where do you guys tend to store passwords or how do you store them, i know the question itself is insecure so dont be specific lol

Just trying to see if there are better/safer way of doing it for sys admins

31 Spice ups

Password safe or you could use a spreadsheet with a password to prevent access to it.

1 Spice up

On a post-it under my keyboard of course!

34 Spice ups

In all seriousness… have it documented hard-copy, and locked in a safe, just in case.

Electronic versions of password lists, IMHO, are never safe.

3 Spice ups

We use an on-premise install of PasswordState. It has full auditing and 2FA.

4 Spice ups

+1 for Lastpass !

9 Spice ups

Shared Keypass database on a file share.

15 Spice ups

I use LastPass and have a copy printed in my firebox.

2 Spice ups

Have used keepass at my last place and it worked well.

4 Spice ups

True Key by Mcafee. Also use a spreadsheet encrypted with a password, and archived with an additional password. As excel only is cracked too easily…

Password safe

Encrypted off network

Idk man, spreadsheet passwords are pretty darn easy to crack. We use an enterprise account with LastPass to share that kind of data between IT admins. I’m not saying that in itself doesn’t come with it’s own host of risks, but I just know someone asked me to crack a spreadsheet password once and there was no shortage of tutorials online showing me how. ¯_(ツ)_/¯

5 Spice ups

Used sysPass at my old job and it worked great.

Might be going with that here or Password Vault Manager by Devolutions or whatever is included with their Remote Desktop Manager app.

1 Spice up

LastPass Enterprise with MFA.

4 Spice ups

KeePass.

6 Spice ups

Password Safe (Mateso) for Enterprise and KeePass for personal use

We use Bitwarden and 1Password.

Team Password Manager. Free for 2 people

1 Spice up

Tryin’ ta get me to give up me treasure?!?

We use an application called PWsafe. Well… some of us do. I was told not to install it because we were going to be getting a new solution, I installed it anyways… That was like 4 months ago and no new solution yet. It seems to be reasonably secure from what I can tell, as long as you use a proper passphrase with it. It also has support for my Yubikey, so that’s a nice bonus.

I haven’t really done any testing against it, but for what I’m using it for, I believe it’s good enough. My important passwords are all locked up in my brain.

1 Spice up