Modern Password Management
Jerome Kelly

Modern Password Management

At Thirdbridge, providing peace of mind to our clients is at the heart of our priorities, and we believe it all starts with the reliability of our internal practices and processes.

At Thirdbridge, providing peace of mind to our clients is at the heart of our priorities, and we believe it all starts with the reliability of our internal practices and processes. To kick off the year, we decided to revamp our password management policy. We believe that the best practices of the industry are actually outdated and have chosen to take a different approach.

In general, a traditional password management policy looks like this:

Members of Company XYZ must use passwords that meet the following criteria when using tools or systems required for their work:

  • At least 10 characters;
  • Contain at least one number;
  • Contain at least one lowercase letter and one uppercase letter;
  • Contain at least one special character.

A password must never be reused across different tools or systems. Additionally, passwords must be updated periodically, at least once every six months.

In this article, we will explain how and why Thirdbridge’s policy, centered on the use of a password manager, is much better suited to today’s reality. Specifically, we will address password entropy, uniqueness, breaches on the deep web, phishing protection, and fostering a security culture.

The Thirdbridge Version

Currently, Thirdbridge’s password management policy can be summarized as follows :

Thirdbridge members must install the 1Password application as well as the browser extension of their choice. Each password must be generated by 1Password and achieve a “Fantastic” score.

Although this formulation is very simple and does not contain specific guidelines on password content, the integration of a tool like 1Password makes it much more relevant for a variety of reasons.

Thirdbridge is neither affiliated with nor sponsored by 1Password. While the following text may sound like an advertisement, there are several competitors offering similar products. That being said, at Thirdbridge, we particularly appreciate 1Password.

A “Fantastic“ password

As mentioned in our policy, passwords must achieve the “Fantastic” score when created in 1Password. This score is based on sophisticated criteria that incorporate a multitude of parameters.

Reusing Passwords

Unless you have a photographic memory, it’s practically impossible to remember a different secure password for each digital tool used in your work. Without a password manager, the reality is that most people reuse the same password across multiple accounts, which poses a huge security risk.

By requiring the use of 1Password for creating all passwords, it automatically detects any password reuse and will not assign the Fantastic score in such cases. Problem solved!

Breach Detection

When creating a password in 1Password, an automatic check is performed to confirm that the chosen password has never been compromised in a previous breach and is not available on the deep web.

While it is true that many web browsers now offer this functionality by default, several other interfaces, especially less modern ones, lack this kind of sophisticated verification. With 1Password, this protection is systematically integrated, regardless of the interface being used.

Entropy

In extremely simple terms, entropy can be described as the level of randomness in a password. The higher the entropy, the harder it is to guess or crack the password. 1Password uses this approach to evaluate password strength, instead of relying on the inclusion of a mandatory set of characters. With this approach, it is possible to generate extremely secure passwords even for archaic systems where, for instance, the use of special characters is blocked by an enterprise firewall.

Phishing

The requirement to install the browser extension is not arbitrary. Not only does it offer a much smoother user experience, but it also helps protect against another attack vector.

During our last phishing simulation campaign, we tried to mislead people into entering their credentials on a fake platform that was visually identical to the original. Several colleagues mentioned that the lack of autofill from 1Password tipped them off. While in our case it was only a simulation, phishing remains the most common attack vector to this day! According to the 2023 State of the Phish report, no less than 84% of companies fell victim to a successful attack, sometimes with disastrous consequences.

Thus, although it is not an infallible solution against phishing like Passkeys, using the browser extension still significantly enhances the level of protection.

Security Culture

Another benefit of our approach is its increased visibility. For instance, whether during a screen-sharing session or an in-person work meeting, it’s very easy to notice if a colleague logs into a site without using 1Password. The goal is not to shame anyone or impose consequences. On the contrary, a simple friendly reminder is often enough to effectively instill proper password management hygiene.

In conclusion, we firmly believe that linking our internal password management policy to a tool like 1Password is the best way forward. Templates provided by law firms or consulting companies that merely list fixed criteria are, in our view, sterile documents meant solely to check a box in a legal or compliance process. Instead, we aim to build a company culture where security is a central element guiding our daily actions.

Thirdbridge clients can rest easy: The emphasis placed on creating secure passwords through 1Password ensures a high level of security for access to sensitive client data and their own!


share this article

Other articles

Jan 30, 2025

Game Day

It’s crucial to remember that the primary goal is to uncover the blind spots in the project.

Jan 6, 2025

25 Key Trends to Optimize Your Mobile App in 2025

The Thirdbridge team has compiled this article outlining 25 trends to consider for mobile app development or strategy, or any other type of digital product in 2025.

Oct 24, 2024

Leverage Mobile to Optimize the Online Shopping Experience

The holiday season is a strategic time and a crucial opportunity for businesses to maximize their sales through mobile while enhancing the online shopping experience.

Oct 15, 2024

Enhancing Product Management: Key to Success in Software Development

The distinction between product management and project management is essential for ensuring optimal productivity. It’s not enough to treat them as interchangeable concepts; it’s crucial to adopt a proactive approach to place the right resources in the right places.

Sep 27, 2024

Thirdbridge in La Presse: Vision and Growth

Our President and Co-Founder, Pierre-Étienne Bousquet, was recently the guest of Camille Dauphinais-Pelletier of La Presse, where he shared his thoughts on Thirdbridge's journey.

Sep 12, 2024

Maximizing Engagement with User-Generated Content

The emergence of user-generated content (UGC) is revolutionizing co-creation. As a key tool in brands' marketing strategies, UGC is changing the way content is created and consumed.

Aug 9, 2024

PWAs: Test the Potential of Mobile Apps

With the advent of mobile applications, our daily lives have been transformed: these simple tools have become essential facilitators of daily tasks and catalysts for professional and personal interactions.

Jun 26, 2024

Thirdbridge in La Presse

As a business leader, one must ask themselves, "What am I trying to accomplish with my project?" and answer with a vision that extends beyond one's own interests.

Jun 14, 2024

Recruiting an In-House Team or Hiring an Agency for Developing Your Application?

When embarking on a project as significant and important as developing an application, a crucial dilemma quickly arises: choosing between a specialized agency or recruiting your own in-house team to accomplish the work. One thing is certain, both options present distinct advantages and constraints.

Jun 14, 2024

Mastering App Development: A 5-Step Guide to Success

Developing an application isn't something you can just wing. To succeed in this coveted domain, being well-prepared is essential. Unfortunately, a vast majority of large-scale digital projects fail due to inadequate preparation.

May 30, 2024

Do You Really Need an Application?

Don't furrow your brows! This is a genuinely good question. Just observe people on the subway, for example, or in a waiting room: almost everyone has a phone in hand, whether to read, text, play, get information, meet a soulmate, order food, or shop...

May 22, 2024

Optimizing Synergy with Your Software Development Partner

The digital realm, especially that of custom digital solution development, is constantly evolving—between fast technological advancements and changing consumer needs, it's quite challenging to predict what the future holds for web players.

May 14, 2024

Succeeding in Your Updates in 5 Steps

Did you know that at least 20% of the development time of an application should be allocated to testing and quality assurance?

May 3, 2024

Simplified Infrastructures for Enhanced Agility

At Thirdbridge, we believe that project-oriented teams deliver superior quality results, and do so more quickly. Given that they are responsible for the entire value creation flow, these teams can increase their velocity by eliminating bottlenecks themselves. Moreover, entrusting end-to-end flow responsibility to our developer teams makes their work even more engaging and motivating.

Apr 12, 2024

The Thirdbridge Entrepreneurial Scholarship

Thirdbridge is more than proud to be able to support a project and individuals full of promise.

Jan 20, 2025

Thirdbridge in the spotlight: L'Arrière-Scène's digital partner

Thirdbridge is proud to announce that it is the official digital partner of JA Hypothèques and their latest project: L'Arrière-scène.

Oct 29, 2024

AI driving innovation: A new Era for Mobile Apps and User Experience

Artificial intelligence (AI) represents a digital transformation that impacts us all. This rapidly advancing technology, fueled by data analysis, not only enables informed decision-making and reliable forecasting but also allows for the completion of many tasks at a faster pace.

Oct 17, 2024

How to Gauge your Mobile App's performance?

A mobile application is the extension of a brand's customer experience.

Oct 15, 2024

Pierre-Étienne Bousquet guest of "Les Affaires"

Our president and co-founder, Pierre-Étienne Bousquet, discussed with Jean-François Venne from Les Affaires the significant growth of digital technology in the retail industry and its impact on online sales, which are becoming increasingly crucial for revenue.

Sep 24, 2024

Cybersecurity and Mobile Applications: Choosing the Right Authentication Method

Mobile applications are essential tools that handle personal data, access sensitive information, and are part of our daily lives. However, in an age where the term cybersecurity is on everyone's lips, ensuring the security of these applications and the information they contain is crucial.

Sep 4, 2024

The impact of UX research

Integrating user experience (UX) principles and practices into the software or application development process has become crucial.

Jul 15, 2024

The Phygital: Rethinking the Retail

Businesses have always had to innovate and rethink their approaches to remain relevant, and this is even more true in the digital age.

Jun 18, 2024

Hybrid vs. Native: Making the Right Choice

At Thirdbridge, the preferred development approach is hybrid. But let's delve deeper by comparing hybrid and native development across key stages of application development: costs, performance, security, and maintenance.

Jun 14, 2024

Funding Your Digital Project

It's no secret that realizing your wildest dreams regarding digital innovation within your company brings many benefits.

Jun 13, 2024

Launching Your Application: The Key to a Well-Planned Budget

Very few digital projects end within their initial budgets and timelines.

May 23, 2024

Tips and Tricks for Sustainable Software Design

When we think about reducing our ecological footprint, our first instinct is to consider the means of transportation we use or our recycling and consumption habits.

May 17, 2024

Maximizing Your App's Profitability: Our Advice

Whether you're looking to save time for your users, retain them, or enhance their shopping experience, we're sharing here the three key elements to consider to maximize your return on investment (ROI).

May 6, 2024

Couche-Tard Connecté: The Cashierless Convenience Store

Congratulations to our mobile development team, who gave their all in recent weeks to ensure a smooth launch of the Couche-Tard Connecté project.

Apr 25, 2024

Beyond Launch: Ensuring the Longevity of Your Application

You've diligently followed the development stages of your application and are about to launch it: congratulations! But even though this is a great accomplishment, your job is far from over...

Mar 22, 2024

Our 12 tips for succeeding in a software project after 12 years in the industry

Thirdbridge celebrates its 12th anniversary!