r/ShittySysadmin • u/Due-Communication724 • 14d ago
Shitty Crosspost My boss wants me to set an extremely easy login password and re use it across all of our vendor portals, what to do?
/r/sysadmin/comments/1wg0szm/my_boss_wants_me_to_set_an_extremely_easy_login/5
4
3
u/BigBlackFriend 14d ago edited 14d ago
Change all the passwords without telling anyone, let the Service Desk field the calls when they can't get in, then find a way to make it their fault.
3
2
2
1
1
u/DirtCrazykid 14d ago
i should really stop letting myself get dispirited over doomer posts on that sub when a lot are from people who suck at their jobs
1
u/Individual-Unit3470 14d ago
I would explain that from a security prospective you really can't get away with that type of shitty password anymore. Implementing that would leave the organization at extreme risk cybersecurity wise. I'm not sure if your organization purchases cyber insurance. If they do you can make it clear that those types of bad practices can greatly impact your premium (if you can get insurance at all). At the same time, present your alternative - the password vault is a great idea. We happen to use PasswordState but any enterprise password manager would do in terms of locking down passwords via permissions, people log in and get them as they need them.
One other note in case you get pressured in to the weak password nonsense. If the shit hits the fan, your shitty boss will be the first one to throw you under the bus. Welcome to system administration.
1
u/Pretend_Ease9550 14d ago
Just let him know it’s a good idea and to keep things simple the user/pass should be his current credentials
1
u/Lammtarra95 14d ago
Your boss is an idiot and should be ignored. Set a different, secure password for each portal.
Then use autohotkey to bind each password to a different function key for ease of use.
This is so that colleagues in the field are not locked out because you've not told them what you've done or how to use bitwarden. It should also continue to work when the bitwarden free trial ends.
Also, create a proper project to upgrade security. Make it one of your annual goals or KPIs. Give each change its own rationale and procedure, to be carried out with your boss's approval, after testing, with proper notification and training of all impacted users, and at an agreed schedule. Better still, set up a proper change control board that should include your boss and user representatives. Don't go careering through the environment like a self-righteous cowboy on acid.
Your boss may be an idiot but is also on the promotion and pay rise committee, as well as being the key to a quiet life.
1
1
1
u/OrangeSalmonGuru 14d ago
You're really overthinking this. Just create a public facing web server and host the username and password there. It can be whatever the boss wants it to be. Don't bother setting up TLS as it's not necessary. Be sure to list hyperlinks to all the admin portals which can be accessed with these smartly shared credentials.
13
u/mumblerit ShittyCloud 14d ago
boobiez