Security Basics mailing list archives

Re: third-party password managers in the enterprise


From: "Saqib Ali" <docbook.xml () gmail com>
Date: Tue, 12 Dec 2006 10:23:12 -0500

A lot of computer manufacturers are including password managers with
their laptops/desktops. For e.g. HP ships Credential Manager which is
password manager as well as a Single Sign On utility. Similarly Dell
includes Wavesys Basic Security Center, and IBM/Lenovo has Utimaco.

Check with your computer manufacturer if they already have credential
manager utility.

If not, Password Safe is recommended by Bruce Schneier. :)

saqib
http://www.full-disk-encryption.net


On 11 Dec 2006 21:10:23 -0000, krymson () gmail com <krymson () gmail com> wrote:
Does anyone have any experience on rolling out or using (or banning) use of third-party "secure" password managers in an 
enterprise 200-1000 users)? I'm just looking for ideas or feedback as this question has been raised in our organization. Examples 
of such apps could be PasswordSafe and KeePass.

These applications are simply encrypted databases which require a user-supplied password in order to open them. The 
user can then populate the database with their logins and passwords. This allows the user a secure storage for multiple 
logins and they only really have to remember the one password to unlock the database.

---------------------------------------------------------------------------
This list is sponsored by: ByteCrusher

Detect Malicious Web Content and Exploits in Real-Time.
Anti-Virus engines can't detect unknown or new threats.
LinkScanner can. Web surfing just became a whole lot safer.

http://www.explabs.com/staging/promotions/xern_lspro.asp?loc=sfmaildetect
---------------------------------------------------------------------------




--
Saqib Ali, CISSP, ISSAP
http://www.full-disk-encryption.net

---------------------------------------------------------------------------
This list is sponsored by: ByteCrusher

Detect Malicious Web Content and Exploits in Real-Time.
Anti-Virus engines can't detect unknown or new threats.
LinkScanner can. Web surfing just became a whole lot safer.

http://www.explabs.com/staging/promotions/xern_lspro.asp?loc=sfmaildetect
---------------------------------------------------------------------------


Current thread: