Avatar of Yashy
Yashy
Flag for United Kingdom of Great Britain and Northern Ireland asked on

Password managers?

HI guys

In our IT department, we would like to better be able to store our network passwords somewhere? At the moment, they're in a password protected document.

Is this how you guys do it? Are there password managers that are much better to use and something you guys have come across?

Cheers
Yashy
Network SecurityWindows Server 2012IT Administration

Avatar of undefined
Last Comment
Mathias Altensleben

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
Member_2_6492660_1

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
SOLUTION
Seth Simmons

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Firstcom

We use Password Safe. Which is open source as well. It can be found here... http://pwsafe.org/
Bryant Schaper

We use lastpass. Phone app is nice too
Thomas Zucker-Scharff

I use and recommend roboform2go. But a business may want to look into cyberark.

The reason I like roboform2go, is that it stays with me on my stick.  I have a subscription to roboform everywhere (where it stores passwords on the web with double encryption), but  only use it to sync my passwords with my phone and ipad, then I delete all passwords stored on the cloud.
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
dbrunton

Another vote for Keepass.
David Piniella

lastpass, lets you share logins without sharing passwords, lets you do groups and revocation and prestage shared passwords and notes (for things like procedures instead of just pain passwords)
Thomas Zucker-Scharff

I've used Dashlane and Passwwordbox as well.  Both have their pros/cons.  Forinstance the reason I have passwordbox at all is becasuse they bought out Legacy Locker which is now incorporated into the manager as "Legacy".  It is a way to share passwords in case of your death.  What happens to your passwords (especially if you are like me and have literally hundreds) and identities and online profiles?  Legacy lets you designate someone who will receive that information when they can produce a death certificate (among other things).  The biggest problem for me is that it seems like it is storing the passwords in the cloud (since it is basically a browser plugin.  But it has passwords, wallet, safe notes, sharing, legacy, a a generator.

Dashlane is another option.  I was an original beta tester for this one and do like it, one of the biggest pros is that it will notify you if there are breaches well in advance of anyplace else.  It also has a great security manager which rates your passwords and helps you make them better.  It will tell you which ones are used more than once and how many times as well as telling you which passwords are bad/poor/okay/good/better/best (I may not have gotten the categories exactly correct, but you get the idea).

While Passwordbox's import facility for roboform passwords and safenotes worked fairly well, Dashlane has a few problems with the same import.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Dr. Klahn

Slightly off topic:  Do be aware that using a password manager doesn't remove the threats of keystroke loggers, scree captures or RAM sniffers stealing passwords.
Carlos Ijalba

My vote goes for Keepass:

It plugs in with PuTTY, so you can open a putty session directly from keepass, as well as websites, and RDP sessions, very handy.

It's portable, so good for out of hours support personnel.

We use it at work as our main systems DB as well (kindda CMDB), not just to keep passwords,
David Johnson, CD

I use lastpass with yubikey this way I have 2 factor authentication.
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
Natty Greg

If I was to trust any password keeper it would be keepass
David Johnson, CD

Security Expert Steve Gibson has evaluated many password managers and so did the USENIX security team and lastpass is the one he uses.  LastPass fixed the vulnerabilities that the security researchers found.. Keeppass wasn't even mentioned.

https://www.grc.com/sn/sn-467.pdf
https://www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-li-zhiwei.pdf
dbrunton

The USENIX evaluation was on web based password managers.  Keepass isn't web based.  The Keepass application is local while the database can be anywhere else that the app can access.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Carlos Ijalba

Keepass has certificate and password security,therefore 2 factor authentication.
Thierry Hulsebosch

Here's another vote for keepass.
Yashy

ASKER
Hey guys,

Thanks for your input and help on this. Sounds like Keepass is getting the vote here.

Thank you Thomas Zucker-Scharfff for your input regarding Dashlane and Passwwordbox and David Johnson also, I greatly appreciate the feedback also.
Your help has saved me hundreds of hours of internet surfing.
fblack61
Thomas Zucker-Scharff

sure
Mathias Altensleben

We also use keepass. It's very simple to use. Just place the kdbx-file on a Share, where everyone of the IT-Department has access.