• doubleaught@lemmy.today
        link
        fedilink
        arrow-up
        2
        ·
        20 hours ago

        Exactly, massive IT failure. Unique passwords are required and should be used everywhere. Yet without a way to generate or access them, you end up with this dude, and I don’t blame them one bit!

        Passkeys are actually better for situations like this. (And others, I’m just not a universal fan for every possible use case.)

        • wonderingwanderer@sopuli.xyz
          link
          fedilink
          arrow-up
          1
          ·
          19 hours ago

          Passkeys are actually better for situations like this

          Is that like when you have a really long unique string of random characters stored on a flash drive and you use it to unlock your computer instead of a password?

          I think those can be beneficial cause if there’s a data breach and all your passwords are compromised, they wouldn’t get your passkey, right? It would require physical access to the USB.

          But the downside is then you have your passkey on a USB, and if someone gets their hands on it they can copy it and use it.

          So I think a hybrid approach is best (when it’s not overkill), and have your passkey on an encrypted, password-protected flash drive so that it requires both physical access and knowledge of the password.

          But unless you’re in government, healthcare, or deep in some industry where absolute confidentiality is supremely critical, it’s probably overkill

    • Zarobi@aussie.zone
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 days ago

      Yeah, some company I.T. policies ban password managers, which is extremely dumb… But also like, what’s there to do about it? Not my decision and we still gotta work.

      I think I remember at some point putting my passwords inside an encrypted 7zip archive that itself had a password. No idea how secure that truly was, but it made me feel better.

      • helpImTrappedOnline@lemmy.world
        link
        fedilink
        arrow-up
        3
        ·
        2 days ago

        They might allow the browser’s built in manager. Good chance if they’re a Microsoft shill, edge’s built in would be better than nothing…although it’s Microsoft so a text file might be better.

        IT probably bans them because they can’t access the data. Keepass files are some kind of container, you can store any file with in it. Great when you want save a txt doc with 2fa recovery codes or something and also not a bad way to send a payload that’s impossible to scan. “I’m going on vacation, please use this keypass file for vendor XYZ, open the file within for the vendors contact info”.