Posted on 06-06-2015 12:53 PM
We are starting to talk about password managers for our end users so I am asking the Casper folks what they think. Is the basic built in Keychain an ok choice? Should we look around for a better solution. Thanks.
Posted on 06-06-2015 02:31 PM
Not if you want to sync across your iOS/Mac and PC. 1Password is my favorite, but we've never deployed it at work. Heard good things about LastPass but never used it. KeyPassX is OK and free.
Posted on 06-07-2015 08:13 AM
The Keychain isn't a great UI, it can do it but it's not designed to be super easy to pull passwords out, generate passwords, or warn you when two services have the same password.
I recommend LastPass over 1Password because 1Password requires manual work to setup a Dropbox sync, making sure to not use the same password for Dropbox as you use for your actual password vault and etc. Also, until you roll something out company-wide, a co-worker can go and sign up for a free LastPass account on their own.
I also like the new user setup LastPass uses, very easy but also teaches and encourages about passphrases.
Posted on 06-07-2015 11:23 AM
I actually use a combination of Keychain and 1Password. Keychain is great for convenience - especially if you happen to use Safari. As mentioned previously, Keychain isn't really designed to be a user-facing password archive though. That's where I use 1Password - it's more of a "vault" and a replacement for that encrypted Excel sheet of passwords and sensitive info that everyone used to keep somewhere. It's also nice you can throw documents and other miscellaneous files into it if you need to.
Posted on 06-07-2015 02:29 PM
I'm a 1password and keychain user. 1passwords Dropbox integration is good, although I just do an occasional wifi sync and leave automated syncing options off as I'm a bit paranoid given the data stored in the 1password vault. Both solutions are personal though.
If you want something that can share passwords with colleagues, LastPass might be a better option. If you need a company store of passwords you might need to look at some enterprise options. We have a bespoke internal system for security reasons. We're not keen on putting our clients server credentials into Dropbox!
Posted on 06-07-2015 11:41 PM
Keychain really isn't the most secure choice, and while I also use 1Password for historical reasons the best bet for enterprise at this point appears to be LastPass, especially that, as @adamcodega said, there are free accounts that people can sign up for before you get Enterprise.
Posted on 06-08-2015 07:58 AM
What is the intended purpose? You can't get around (that I know of) using the Mac Keychain for certain things like account passwords (login).
If you're on Active Directory, it's more of a challenge on the Macs - especially if user's have more than one Mac/PC as you have to manually change things on the Macs.
A day doesn't go by where a user at my main account doesn't forget their AD password, which means it has to be reset and their keychains deleted. In spite of telling clients to keep track of their passwords, they don't.
The company has a work-around for them. They allow them a crazy long passphrase that doesn't expire, so they don't need to change every 90 days. It seems to help, but that's a bad solution IMO.
I use 1Password on all my devices. Not only does it manage passwords, but Credit Cards, software licenses, etc. and I get instant access to all my data by simply syncing with either Dropbox or iCloud. One password to manage, and well, it works amazingly well. If my Mac Keychain ever gets hose, I lose basically nothing.
I've never thought about using 1P as a company-wide solution, and I've never even looked at other options. But Apple's iCould Keychain is getting better and does a decent job, but it of course requires 10.9+ and iOS7+ and an AppleID, etc.
I guess it comes down to what you're trying to provide to your clients...
Posted on 06-15-2015 11:45 AM
+1 for 1Password. KeyPass and the others can be great solutions but nothing beats 1Password for user experience in my opinion.
Posted on 06-15-2015 12:29 PM
+1 for 1Password love it for personal use, but for our department we use Secret Server
Posted on 06-15-2015 04:24 PM
http://lifehacker.com/lastpass-hacked-time-to-change-your-master-password-1711463571
Posted on 06-15-2015 06:29 PM
+1 for 1Password. The Dropbox sync is especially nice, and it works across Win/OSX/Android/iPhone.
Posted on 06-18-2015 05:23 AM
Ahh heck. Apparently it's all moot, at least temporarily!
http://www.macnn.com/articles/15/06/17/flaw.in.how.apple.handles.secure.app.data.storage.keychain.websocket.disclosed.129099/
Posted on 06-18-2015 05:45 AM
This is why I only use banks that offer dual-factor authentication. ;)
Posted on 06-18-2015 06:10 AM
Agile posted this on their blog. info here