1 / 3
Inside the safe
Russ moved every company password into the new safe and had Pip generate a forty-character master password. Then he saved the master password in the safe.
The mistake
The team stores the safe's own master password as a record inside that same safe, so the one secret needed to unlock the vault is only retrievable by first unlocking the vault. This is a circular dependency: there's no out-of-band store (a separate secrets manager, a physical backup, split-knowledge shares) holding the credential that guards everything else, so a session lockout has no recovery path. Deleting every other copy of the passwords beforehand removes the fallback too, turning a single expired session into a full outage.
- security
- passwords
- ops
- process
- access-management