Password Sharing Solution
I need a solution for sharing passwords. Current solution that everyone loves: You go to a website. You can enter a password, or have one generated for you. It gives you a public URL. You can choose it to be valid once or for up to 7 days. You give the link…
I need a solution for sharing passwords. Current solution that everyone loves: You go to a website. You can enter a password, or have one generated for you. It gives you a public URL. You can choose it to be valid once or for up to 7 days. You give the link to a user, customer, client, whoever. They click it, they get the password in plain text in their browser window. Done. Problem: it's running on an EOL OS, the original programmer is long gone. Need something you get a link, you click it, you get the password. No auth required, can work publicly with no VPN. SaaS solution preferred.
Collected discussion
https://onetimesecret.com
This is what we run
Yeah most of the time I see bitwarden including the MFA codes and stuff aswell
This is the answer. Nobody should be putting secrets into some rando third party website, period. Use an approved password vault tool.
Funnily enough I'm trying to get this self-hosted. Last week I spent a good couple hours trying to get SSO working but couldn't. Might keep on it.
If you get this working let me know, I'm def boomarking this project but going through Entra is a must.
Perhaps I'm misunderstanding the question, but like this? https://oss.pwpush.com/ or you can selfhost https://docs.pwpush.com/docs/self-hosted/
The best answer.
It's annoying that you can't share a bitwarden item, temporarily, with a colleague...
1Password has this feature
Bitwarden. For external password sharing, you can use Bitwarden Send You can set up groups for sharing accounts among groups internally as well
Bitwarden, keeper or 1password.
https://privatebin.info/ works pretty good.
Snappass or Yopass. 1Password is also a great option if it is an already a deployed secrets manager to your endpoints. I'd e talking to my CISO before using any of the public endpoints suggested.
Keeper does this, password shares can only be opened on one device using the one link, so you send it to someone via email, they open it and then after they've opened it for the remainder no one else can because it's specific to that device they opened it with. With time limits it really limits issues but still allows sharing easily without the password being plaintext.
My team uses Keeper password manager. We have licenses for all of our sysadmins and developers. It has a built in password generator in which you can specify the complexity requirement for any passwords it creates. That's on top of storing credentials for all the services, websites, and servers we use and administer. It also has the ability to do granular sharing/ownership of credentials. It's a great tool, but I'm afraid i don't know what it costs us - I know it's NEVER under consideration for not renewing the licensing annually.
Devolutions send, pwpush, there are probably others
Traceless.io
Privnote
We use traceless.io for this, it also lets you request data securely and lets you send and receive large files too.
We use passwordstate for our main vault. It has a feature to send a password via link. I don’t understand why people use third party tools, surely you have software already for storing company passwords?
Passwordstate by Click Studios
Wait... This isn't r/shittysysadmin?
If you use Hudu for documentation, it can do exactly what you're currently doing. If not, Keeper is also great.
Another vote for pwpush pwpush.com/