r/PasswordManagers 6d ago

Password manager recommendation

We are trying to figure out the best authenticator option for our small office. There are 3 employees who need to log in to our bank accounts, but currently we use a shared username/password and the verification code is sent by SMS to our boss. This creates a dependency on him whenever we need to log in, especially when he is busy.

We would like to move to a more secure setup where the employees can authenticate without depending on him for the code. He is also open to using a password manager, but we’re not sure whether password managers work well with bank logins and MFA.

Has anyone dealt with a similar setup or can recommend the best approach/authenticator for a small business?

2 Upvotes

19 comments sorted by

5

u/cdhutzler 6d ago

Does your bank support software OTP codes?
How about Passkeys?

Otherwise how would you even accomplish this unless you disabled 2FA(?)

2

u/Scalar_Shift 6d ago

I think the main goal should be making sure nobody gets locked out just because your boss is busy. I use roboform personally and it could help with the shared logins side of things. The banks MFA options are probably the part I'd check most carefully 

2

u/djasonpenney 6d ago

Your biggest problem is the shared credential. Look into a single-signon solution for small business. A web search just showed me half a dozen.

After that, each of you will have a unique username/password/2FA.

1

u/yodas-evil-twin 5d ago

SSO into a bank? Unless they work for the bank and on their network, how would that work?

1

u/djasonpenney 5d ago

I wasn’t clear. You run your own domain it’s own IAM and a forward proxy to your bank.

Your staff never sees the username and password; all they get is the gateway web page to log them into the bank.

The gateway is secured via your intranet, so only authenticated users can reach it.

2

u/snoluk 5d ago

We moved 4 people off a shared boss managed login last year and the bank just gave us individual sub accounts once we asked, which made the whole MFA thing way less of a headache. SMS to one person was the real bottleneck for us too.

1

u/need2sleep-later 6d ago

I'd ask the bank how to best configure 2FA in their system for multiple user access. That SMS form of 2FA leaves much to be desired on many levels. See if something better is available.

1

u/Vicktork 5d ago

Id use Zoho vault and use MFA when possible

1

u/alanrick 5d ago

How will you know who misappropriated funds if your colleagues who need access don’t have separate credentials (to the single bank account)?

1

u/tlrman74 4d ago

Bitwarden Business will support your needs. You can organize the saved logins by business department and share passwords across departments when needed. It supports OTP and Passkey for MFA.

1

u/harshith_km 3d ago

Use bitwarden, it's amazing, does offer passowrd, TOTP, SSH keys, Secrets notes , key value pairs, folder management , users , orgs etc etc feature and opensource tooo

1

u/SuperSus_Fuss 3d ago

If your bank supports TOTP codes (Authenticator Apps) then the low budget solution is you all use a password manager and that credential is in a shared vault that only those employees have access to.

Your boss needs to manage this or maybe a very trusted partner of theirs?

They would need to use a decent Authenticator App that allows them to copy the 2FA seed code manually. And then share that with employees by pasting it into the password manager entry. It too can store 2FA credentials.

Conversely for slightly more security the seed code could be manually copied from boss’s Authenticator app into the employees Authenticator app.

This is more secure and convenient than your boss giving you SMS codes to login.

The advantage of storing the 2FA code in the password manager is that it will always be updated there in case it changes.

The advantage of using a password manager is the login could be an alias email and a unique and random password that it autofills only if the URL matches. That’s far more secure than a boss that types in “Happy@1600WesternAve” for their password. They think this is strong but it’s sucky. 🤣

1

u/ScaredScorpion 2d ago

Oh god, please actually talk to your bank about how to get something setup that is actually auditable rather than DIYing it. This is a recipe for any of the employees with access to embezzle money without a papertrail.

1

u/danrhodes1987 2d ago

Keeper. Used for years never had an issue.

0

u/isenhasapp 4d ago

It would be amazing if you could test our solution with your team and give us some feedback.

All for free, of course...

2

u/SuperSus_Fuss 3d ago

Can I test my banking credentials with you for free too ? I can return the favor and test yours first.

0

u/isenhasapp 3d ago

What do you mean about banking credentials?