Password Managers at Organisational Scale: The Recovery Problem Returns

Password Managers at Organisational Scale: The Recovery Problem Returns

组织规模下的密码管理器:恢复难题的回归

What a password manager is actually for 密码管理器的真正用途

An enterprise password manager exists to remove two habits: reusing a password across services and storing credentials in places a colleague can read. It does this by holding secrets in an encrypted store that a server administers but cannot decrypt, and by generating unique values. The security value depends on the master credential that unlocks the store, so the interesting failure modes concern that credential and what happens when the user loses it. 企业密码管理器的存在是为了消除两种习惯:在不同服务间重复使用密码,以及将凭据存储在同事可以读取的地方。它通过将机密保存在一个由服务器管理但无法解密的加密存储库中,并生成唯一值来实现这一目标。其安全性取决于解锁存储库的主凭据,因此,值得关注的故障模式主要围绕该凭据,以及当用户丢失该凭据时会发生什么。

The failure modes that matter 关键的故障模式

Vault recovery performed by an administrator. If an administrator can reset a user’s master password, the administrator can read or take over the vault. Products differ here: some support administrative reset, some support organisational recovery with the user’s cooperation, and some deliberately cannot recover at all. The choice has to be made deliberately, because the default is whatever the vendor found easiest to build. 由管理员执行的存储库恢复。如果管理员可以重置用户的主密码,那么管理员就可以读取或接管该存储库。不同产品在此处有所不同:有些支持管理员重置,有些支持在用户配合下进行组织级恢复,还有些则刻意设计为完全无法恢复。这种选择必须经过深思熟虑,因为默认设置通常是供应商认为最容易构建的方案。

Weak or reused master passwords. The vault is only as strong as the credential protecting it, and this is where an organisation-wide rollout can make things worse if the master password is a memorable phrase that users also use elsewhere. 弱密码或重复使用的主密码。存储库的安全性取决于保护它的凭据,如果主密码是用户在其他地方也使用的易记短语,那么在全组织范围内推广可能会使情况变得更糟。

Offline or emergency access. Some products keep a locally cached copy of the vault on each device. The cache is an encrypted file that outlives the user’s employment, and it sits on a laptop that may be resold. 离线或紧急访问。一些产品会在每台设备上保留一份存储库的本地缓存副本。该缓存是一个加密文件,即使在用户离职后依然存在,并且它存储在可能被转售的笔记本电脑上。

Sharing. Shared vaults and shared items are the feature that makes a manager useful to a team and the feature that makes access review hard, because access to an item often outlives the project it was created for. 共享。共享存储库和共享项目是使密码管理器对团队有用的功能,但也是使访问审查变得困难的功能,因为对某个项目的访问权限往往会超出该项目本身的生命周期。

Deployment decisions that reduce the risk 降低风险的部署决策

Require a strong, unique master password and verify it against the organisation’s breach corpus rather than against a generic strength meter. 要求使用强且唯一的主密码,并将其与组织的泄露数据库进行比对验证,而不是仅依赖通用的强度评估工具。

Choose the recovery model on purpose. If the requirement is that no administrator can access user secrets, say so explicitly and accept that a lost master password means a lost vault. If recovery is required, constrain it with multi-party approval and log it as a privileged action. 有目的地选择恢复模型。如果要求是任何管理员都不能访问用户机密,请明确说明,并接受丢失主密码意味着丢失存储库的后果。如果必须进行恢复,请通过多方审批进行限制,并将其记录为特权操作。

Disable or shorten the offline cache where the product allows it, and include the cache in device decommissioning. 在产品允许的情况下,禁用或缩短离线缓存,并将缓存清理纳入设备退役流程中。

Review shared items on the same cycle as accounts, with an owner per item rather than per vault. 与账户审查周期同步审查共享项目,并为每个项目指定所有者,而不是按存储库指定。

Prefer passkey or hardware-token unlock for the vault itself where supported, so the master credential is not a value that can be phished. 在支持的情况下,优先使用通行密钥(Passkey)或硬件令牌解锁存储库,这样主凭据就不会成为可被钓鱼攻击的目标。

Defensive implications and limits 防御意义与局限性

A password manager concentrates risk. One well-chosen credential protects a large number of secrets, and the same property means that credential is a high-value target. This is acceptable, because the alternative is a large number of credentials protected by memory. 密码管理器集中了风险。一个精心选择的凭据保护着大量机密,而这一特性也意味着该凭据是一个高价值目标。这是可以接受的,因为另一种选择是依靠记忆来保护大量凭据。

The limits are real. A manager does not help with credentials that machines use, and it does not stop a user pasting a password into a chat window. It reduces the population of credentials a human must remember and makes the remainder auditable, which is a narrower claim than marketing material usually makes. 其局限性是客观存在的。密码管理器无法处理机器使用的凭据,也无法阻止用户将密码粘贴到聊天窗口中。它减少了人类必须记忆的凭据数量,并使剩余的凭据可审计,这比营销材料通常宣称的范围要窄得多。