Hacker News new | past | comments | ask | show | jobs | submit login

Don't you have external services which use a password? DNS provider, VPS admin console for example?



Not really, we have our own datacenter and DNS servers. We have HSMs for somethings (like CA certs) and yubikey/similar for things that require passwords but those are all protected by user-specific certificates.


Do you have a company Twitter account?


Yes/no, one exists but its unrelated to my job. Its probably worth noting that we also have sets of accounts that while password protected are essentially considered public. Those accounts are accessible to anyone who knows the well-known standard passphrase


It kind of negates your first point.

"Passwords? No. We don't. Everything is a certificate or key."

...

"We have sets of accounts ... accessible to anyone who knows the well-known standard passphrase."


As a company "we" don't have passwords for our company infrastructure, individual users may have passwords for their accounts but those aren't secret/ as important. Its not practical to deploy PKI to and expect ~100K users to use it. As for communal accounts they're almost all for paying for services offered in-house by a group other than yours.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: