4 ms·
>We shared a google account with passwords that everyone needed. I am speechless.
by throwmeback 8y ago
>We shared a google account with passwords that everyone needed.
I am speechless.
- deleted 8y ago[deleted]
- berkes 8y agoI'm intrigued by the `needed` in there. Why would that ever be a necessity?
- deadbunny 8y agoThere isn't, the only excuse is lazyness and a complete disregard for any kind of security.
- AnIdiotOnTheNet 8y agoLets say your company has a profile on a platform that uses a Google account login. How many Google accounts do you want to wager can be permitted to administer that profile?
- deadbunny 8y agoOn a properly written platform? As many as needed, RBAC exists for a reason. On a shitty platform? Zero, that shit isn't production ready.
- tyingq 8y agoThere's mundane stuff, like letting a small group of people log into Gmail for support@mysmallbiz.com There's ways around that, but for some orgs, it would be unneeded overkill, and not protecting anything notable.
- berkes 8y ago> but for some orgs, it would be unneeded overkill, and not protecting anything notable. I can honenstly not think of a single venture where "support@" is not one of the most critical resources wrt privacy and security. On top of that, "support@" is typically the account that has a high churn rate. Where people move on and new people are hired. Of all the cases, I'd say that "support@" ranks amongst the top for need of proper account management. That said, it's dead simple to grant jane@ and john@ access to an inbox in Google. Researching how to do this may take 30+ minutes. But getting it configured afterwards is really a two minute job. The only reason I've came across why people shared Google accounts was "we have a business domain and we need to pay for every extra seat". Which is a valid excuse. I'd argue that its not a good enough excuse to lower your security for, but valid nontheless. For one, 2fa is almost impossible when sharing accounts. Which is why having a "pay per seat" model for any SAAS is perpendicular to having proper security practices. You are not rewarding good security, but rather punishing it by letting organisations with proper separation of accounts pay more then the ones that choose to have as few as possible.
- tyingq 8y agoI've seen functionality where one gmail account can send an email so that it appears to be from another email address. I haven't seen anything that allows a seamless view of the inbox/outbox, and a way of sending that doesn't accidentally use their normal email address if they forget to click a drop down.
- kerng 8y agoSupport emails fall into the "interesting" GDPR bucket often overlooked. I see only few companies actually share/keep track of that data bucket when doing a data request, or deletion request.
- marcosdumay 8y agoAnd I'd bet you never worked in any OPS task. Not every password identifies a user.
- deadbunny 8y agoI've worked in ops for a decade. There is no legitimate excuse for sharing accounts/credentials. Ignoring the myriad security issues with shared credentials auditing alone is completely ruined with shared creds.
- deleted 8y ago[deleted]