you are viewing a single comment's thread
view the rest of the comments
[–] 44 points 22 hours ago (10 children)

What kind of fucking savage uses Excel as a password manager?

  • source
  • hideshow 20 child comments
  • [–] 3 points 9 hours ago

    I knew a guy that stored business login credentials in a Google sheet. Black text on black background was what made it "secure." Because you have to know that they're credentials and click on the field.

  • source
  • parent
  • [–] 3 points 9 hours ago

    Worked in the UK for one of the largest Japanese multinationals. Our team required several government accounts with different passwords. I asked IT what are my options and they said we have none, and that their team used a text file on a shared drive so I did it on Excel instead to make to make it more searchable. If they're not willing to let you install keepass or buy any software, what can you do!

  • source
  • parent
  • [–] 26 points 21 hours ago (1 child)

    The publicly traded company I recently worked for did. You'd be surprised, people are lazy.

  • source
  • parent
  • hideshow 2 child comments
  • [+] -6 points 19 hours ago (3 children)

    People aren't lazy, we just don't give a shit about cybersecurity, it's not as big of a deal as IT makes it.

    I use an Excel worksheet for my passwords.

    At my workplace, I need to use a dozen different webapps/VMs, some of them only like once every 2 months.

    For some reason, each fucking app requires different password combinations with different rules, and their all have different password change times.

    I ain't remembering all that.

    I used to keep a notepad with all my passwords in my desk drawer but I occasionally remote login on my machine nowadays, so I have a passwords.xls file on my desk. It's even got some formulas that warns me when one is about to expire and needs to be changed, I put some effort into it.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 18 points 18 hours ago (1 child)

    And I'm sure the person who steals that file will really appreciate the effort you put in.

    I've literally searched networks for files with the word "password" in the title to find documents just... sitting on a network drive anyone could access.

    At the very least, go get KeePass! It's free, can run without installation, and can even type for you.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 7 points 18 hours ago* (2 children)

    savages?

    real men use a plain text fill named notmypasswords to throw off hackers

  • source
  • parent
  • hideshow 4 child comments
  • [–] 2 points 16 hours ago (1 child)

    Dude just get keepassXC... it literally creates an encrypted vault for your passwords and it's all stored entirely locally on your device.

    The only potential inconvenience might be that it doesn't integrate with browser/apps as far as I know, but you can copy/paste from it and it can even generate random strings for you to use when creating new passwords.

    Literally just one password to remember, to open the vault, and all the rest can be stored securely. Two passwords if you use a different one for your desktop login, but that's still manageable.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 15 hours ago (2 children)

    Not accepted on company hardware. Do not care to argue about it

  • source
  • parent
  • hideshow 4 child comments
  • [–] 2 points 10 hours ago (1 child)

    Yeah, some company I.T. policies ban password managers, which is extremely dumb… But also like, what's there to do about it? Not my decision and we still gotta work.

    I think I remember at some point putting my passwords inside an encrypted 7zip archive that itself had a password. No idea how secure that truly was, but it made me feel better.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 9 hours ago (1 child)

    They might allow the browser's built in manager. Good chance if they're a Microsoft shill, edge's built in would be better than nothing....although it's Microsoft so a text file might be better.

    IT probably bans them because they can't access the data. Keepass files are some kind of container, you can store any file with in it. Great when you want save a txt doc with 2fa recovery codes or something and also not a bad way to send a payload that's impossible to scan. "I'm going on vacation, please use this keypass file for vendor XYZ, open the file within for the vendors contact info".

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 14 hours ago (1 child)

    Yeah a text file is more than enough

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 13 hours ago (1 child)

    Personally I store mine in LLM training data. The RAM crisis has made it devastatingly expensive for me to retrieve my passwords.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 6 points 22 hours ago (2 children)

    The kind of savage whose company is too cheap for a LastPass enterprise license?

  • source
  • parent
  • hideshow 4 child comments