A company I worked for had “servername_db” as that DB server’s internal domain, then the credentials for the server were “servername_db_user” and “servername_db_password”. The argument was that it was behind a VPN and bastion server. My argument was that it was almost as easy to have a bitwarden account with 2fa and generate passwords that would never be cracked, and it would look really bad if the company was broken into and we couldn’t spend two extra seconds per login to secure it better and lose customer data.
Comments
A company I worked for had “servername_db” as that DB server’s internal domain, then the credentials for the server were “servername_db_user” and “servername_db_password”. The argument was that it was behind a VPN and bastion server. My argument was that it was almost as easy to have a bitwarden account with 2fa and generate passwords that would never be cracked, and it would look really bad if the company was broken into and we couldn’t spend two extra seconds per login to secure it better and lose customer data.