Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
communism bitch
Apr 24, 2009
no what you do is make a new gmail account called "passwords" and put all the passwords in a draft email that you save, and then give everybody the login for that account so they can ctrl+f thei pasword they need. hth

Adbot
ADBOT LOVES YOU

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
just make all of them the exact same and make sure it's easy to remember

flakeloaf
Feb 26, 2003

Still better than android clock

TheManFromFOXHOUND posted:

I've been assigned to create a centralized password manager for the IT/Development department and I need to figure out what to do. Right now I'm leaning towards using KeepAss on a shared network drive with a key file.

four seconds later someone copies the keyfile to anywhere on the network

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
1p assword for teams. next question

geonetix
Mar 6, 2011


normally you just do "<company>123" and that's always safe

gonadic io
Feb 16, 2011

>>=

RISCy Business posted:

Lastpass for teams. next question

TheManFromFOXHOUND
Nov 5, 2011
all good suggestions
I'm looking into 1password for teams now, thanks

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


geonetix posted:

normally you just do "<company>123" and that's always safe

use the company street address instead of 123, that's more safe

Shame Boy
Mar 2, 2010

yeah there's several "for teams" programs out there that would work fine if you have nonzero budget

actually now that i'm thinking about keep rear end and keyfiles how come it doesn't work with like, SSL certs, so you could use hardware tokens? is that even possible? has someone made that?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

PKI LOL IMHO

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

TheManFromFOXHOUND posted:

For reference we will be storing passwords to our task servers and AWS in the manager.

make individual accounts for the task servers, use IAM on AWS to make individual accounts or there's probably some way to scoop them out of ldap or w/e

sadus
Apr 5, 2004

Secret Server is good and fancier than I realized

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

sadus posted:

Secret Server is good and fancier than I realized
it has lots of neat features

gonadic io
Feb 16, 2011

>>=

ate all the Oreos posted:

yeah there's several "for teams" programs out there that would work fine if you have nonzero budget

actually now that i'm thinking about keep rear end and keyfiles how come it doesn't work with like, SSL certs, so you could use hardware tokens? is that even possible? has someone made that?

keep rear end lets you specify a file as a key out of the box, but you need to use one of the plugins to do rsa/ssh/user account/whatever

Shame Boy
Mar 2, 2010

gonadic io posted:

keep rear end lets you specify a file as a key out of the box, but you need to use one of the plugins to do rsa/ssh/user account/whatever

yeah i know about keyfiles, i mean hardware token/smart card/PKI-based auth, though it sounds like there's plugins for that is what you're saying? neat, i'll check em' out later

spankmeister
Jun 15, 2008






I think it allows you to use a yubikey as well?

freeasinbeer
Mar 26, 2015

by Fluffdaddy
hashicorp vault.

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug
Spent the day in blechley park and it's really neato. They have a redic "cyber security" section presented by mcafee with an entire wall of Facebook people "keeping you safe" that was pretty lol though

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
lol https://twitter.com/ericgeller/status/871842516458496001

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

Bhodi posted:

Spent the day in blechley park and it's really neato. They have a redic "cyber security" section presented by mcafee with an entire wall of Facebook people "keeping you safe" that was pretty lol though

bletchley is amazing. i legit cried at the plaques describing how he was treated after the way, even though i already new it all. seeing it next to all his papers and essays it was just too much.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


CHICKEN DINNER was exonerated after a thorough investigation.

DumbWhiteGuy
Jul 4, 2007

You need haters. Fellas if you got 20 haters, you need 40 of them motherfuckers. If there's any haters in here that don't have nobody to hate on, feel free to hate on me

good poo poo all around

spankmeister
Jun 15, 2008






Subjunctive posted:

CHICKEN DINNER was exonerated after a thorough investigation.

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Bhodi posted:

Spent the day in blechley park and it's really neato. They have a redic "cyber security" section presented by mcafee with an entire wall of Facebook people "keeping you safe" that was pretty lol though

I need to go back because I didn't have enough time to see everything

duTrieux.
Oct 9, 2003

i'm pretty sure that keepass supports opening files with ssl?

spankmeister
Jun 15, 2008






Bhodi posted:

Spent the day in blechley park and it's really neato. They have a redic "cyber security" section presented by mcafee with an entire wall of Facebook people "keeping you safe" that was pretty lol though

Did you go to the nearby computer museum? They have a working rebuild of the Colossus, the first electronic computer.

Imo the story and technical details about cracking the Lorentz cioher is as interesting or even more so than Enigma.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

duTrieux. posted:

i'm pretty sure that keepass supports opening files with ssl?

what does it mean to open a file with ssl (tls)?

duTrieux.
Oct 9, 2003

Subjunctive posted:

what does it mean to open a file with ssl (tls)?

i think just that it can retrieve a database from https, there's something in the options about allowing self-signed certs to do so

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

duTrieux. posted:

i think just that it can retrieve a database from https, there's something in the options about allowing self-signed certs to do so

oh, ok. I thought you meant a local file

duTrieux.
Oct 9, 2003

Subjunctive posted:

oh, ok. I thought you meant a local file

i'm not that much of an idiot, although yes what i posted was extremely poorly phrased

Midjack
Dec 24, 2007




reality winner

like, that's the leaker's name

it's no CARL MARK FORCE IV but still pretty good

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
For each server, tattoo the password on one butt cheek each of two distinct employees, taking care not to have any two employees have the same two servers between them. keep a department spreadsheet of server names to tattooed employees. Do not inform the employee which server their tattoo is for. In the event of an employee departure where that employee has a password, tattoo the 1-2 passwords onto different employees as previously. Enforce key rotation via frequent layoffs and hirings.

this is what you all mean when you're suggesting a team keep rear end, right?

haveblue
Aug 15, 2005



Toilet Rascal
made a point to visit bletchley when I went to london, it was awesome

I did see the colossus, they also have a bombe

haveblue fucked around with this message at 01:27 on Jun 6, 2017

duTrieux.
Oct 9, 2003

Volmarias posted:

For each server, tattoo the password on one butt cheek each of two distinct employees, taking care not to have any two employees have the same two servers between them. keep a department spreadsheet of server names to tattooed employees. Do not inform the employee which server their tattoo is for. In the event of an employee departure where that employee has a password, tattoo the 1-2 passwords onto different employees as previously. Enforce key rotation via frequent layoffs and hirings.

this is what you all mean when you're suggesting a team keep rear end, right?

this was tortured but so is naming a password manager "keepass" so i'll give it an A-

OJ MIST 2 THE DICK
Sep 11, 2008

Anytime I need to see your face I just close my eyes
And I am taken to a place
Where your crystal minds and magenta feelings
Take up shelter in the base of my spine
Sweet like a chica cherry cola

-Cheap Trick

Nap Ghost
https://twitter.com/quinnnorton/status/871883733032415236

gj intercept

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
they're kinda hard to see on that image

Only registered members can see post attachments!

Peachfart
Jan 21, 2017


My company makes copiers that do this and it's pretty cool. Though all copiers made since copiers went digital do this in some fashion.
There are ways to trick it or to hide them, but it's not easy.

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

Peachfart posted:

There are ways to trick it or to hide them, but it's not easy.

Scan, OCR, don't share the originals

Peachfart
Jan 21, 2017

Jabor posted:

Scan, OCR, don't share the originals

None of these will work. At the bare minimum, older MFP's leave their serial number almost invisibly on any copy, print, or scan. Newer copiers, and certainly anything the government is using(we are their main supplier), have much more information especially since you are required to use PIV to log into each machine.

Adbot
ADBOT LOVES YOU

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

Peachfart posted:

you are required to use PIV to log into each machine.

seems kind of discriminatory against gay people

  • Locked thread