I have an #infosec question: is there any good reason for co-workers to share login information, e.g. to access a supplier website? If yes, what’s the reasonable way to share such information nowadays?

My current customer is doing this, and I’m freaking out a bit. :-/

@fabi1cazenave keepassxc with a shared db.
Text file pgp encrypted
@usul Thanks for the suggestion. That was my first idea, sharing the db on their NAS, but I was afraid it would be too weak.
@fabi1cazenave db was shared in a private git repo to deal with password changes
@fabi1cazenave it's always too weak anyway. The other way is a physical safe but not nice for remote workers