Hacker News new | ask | show | jobs
by vectorEQ 2785 days ago
sso+2fa all the things. easy for users as they only need 1 token and set of credentials. so no need to manage databases full of passwords.

okta is useful service for it which is popular because it's good / useful, but it needs to be set up properly and securely by people with experience in it. since messing it up can be BAD as any compromise is obviously going to be more of impact. might be a bit of an investment at first, but it will save in administrator's time / maintenance etc. later.

do it carefully though. really carefully :) only need to do it once, so it's worth to take the time and investment and do it right.

1 comments

there's also products like 'secret server' , but i tend to dislike password management solutions ,as they are not a solution to the root cause and if compromised, it's a major issue instead of 1 limited user being owned.