Meldium (YC W13) Controls Your Team’s Shared App Passwords For You
techcrunch.com
techcrunch.com
Can't I just sniff what my browser sends to the server?
I'm suspicious.
This is a real problem though.
PS: You might want to reconsider that name. Meldium, to me at least, just looks like someone typoed when trying to type Medium.
http://cl.ly/image/3f3x3R0N0y2W
If I had actually logged in you would see my password in the space that currently says NotActuallyMyPassword.
I don't see how Meldium could prevent that.
It is also possible to run the proxy server on the end user machine and use a mechanism called SSL tunneling to securely replace the password. Its hard to explain it here but it can be done. The benefit of running the proxy on the end user machine is that you don't have to route your traffic through a remote proxy.
I have a system which has this thing working - will open-source it under github soon.
Regardless of your answer I think these questions make it clear that you should definitely consider adding some more detailed explanations to your website about how exactly your product works. Especially for a security related product this is pretty important.
I say this as someone who is very interested in paying someone to solve this problem for me.
It's probably a reasonable trade for a lot of services -- I'd probably use it for an analytics dashboard, etc., but probably not for admin interfaces to do stuff to customer data (which you presumably could set up with individual user accounts and group/role management, anyway). This seems to be aimed at the ~bunch of low security passwords which are either the same across your whole business, or stored in a google docs spreadsheet now, not the most important credentials for your users.
I don't mean this to criticize you, one of the first scripts I ever sold was a better UI to a service that basically used Cross Site Request Forgery to do the work.
The solution I'm going with now is a native client that creates the cookies locally which the browser extension then accesses. Mine's also not immediately marketed towards teams but rather individuals.
Best of luck.
You might be able to view the password using something like https://addons.mozilla.org/en-us/firefox/addon/tamper-data/ provided that runs after their extension.
One thing that groupware password things never remember is that folks like to use their personal services, too, and requiring multiple-accounts for personal stuff is not workable.
Is there support for personal (e.g. private only to my login) accounts? That way, I could store all my stuff with a single browser plugin...
For services that do support many users, we have deep integration that actually creates individual accounts for every new employee you hire. We have almost 20 of these services integrated now and we're always looking to add more.
We've had the opportunity to talk to many service vendors in the process of building Meldium and the response has been overwhelmingly positive. With provisioning integrated, Meldium removes one of the barriers to service adoption - it makes it easy for a company to add more accounts when the hire more people, and service vendors love this. We're always looking for tighter and higher-quality integrations with vendors - if you run a SaaS app and you'd like to see it supported on Meldium, ping me at brad@meldium.com and we'll find a way to make it happen.
Who's the customer here?
I need a solution like this, but allows the storage and potential sharing of other types of passwords not associated with a specific website or service (server passwords, door codes, etc)
That being said, it looks like a great start!
I wish they would have compared this to other existing products such as LastPass instead of comparing it to an excel spreadsheet.
Typically we work with many small clients and one of our issues is managing access to admin sites etc for these clients across our team. We have relatively few 'users', perhaps 5 - 10, but a large amount of shared apps. I currently have around 100 sets of login details on file in 1Password.
We think of Meldium as a tool for sharing accounts,
not for just sharing passwords.
Meldium seems to be a tool for sharing web app accounts. Some of the accounts my team shares aren't for web apps. While there are a lot of password managers out there,
none of them are built for teams first.
What about Passpack, which is what my team uses? Passpack has worked well for us, but I'm interested in alternatives because Passpack doesn't seem to be actively developed (bugs I reported months ago haven't been fixed and Passpack's blog is rarely updated).It would be interesting to see what they offer if someone exposed their database and caused your financial ruin?
But I fundamentally agree, you need to consider that in many cases you are not just subject to your own risks and threats (internal and external) but each of your suppliers (and their suppliers such as Heroku and AWS) and their internal and external risks added to yours.
Github, Salesforce, Box, Google Apps, WordPress. These all support using multiple accounts right?
On the other hand, I'm terrified of giving my account info to a 3rd party. Seems like the sweetest hacker target ever.
They've really left themselves open to competition. Good luck to Meldium taking them on.