How to share a password with a colleague without leaving it in the chat

Updated

A colleague needs the password to a shared account, and the quickest way to get it to them is the chat window that is already open. It works, and that is the problem: the password arrives, and then it stays. This guide is about getting a password to one person without leaving a copy of it behind.

Why the chat is the wrong place

A message in Slack, Teams or a messenger is not a conversation that ends. It is a record, and it is built to be kept and found again:

  • It is searchable. Anyone who later gets into either account can type "password" and find it.
  • It is synced to every device both of you are signed in on, including the old phone in a drawer, and it shows up in notification previews on a locked screen.
  • It is retained. Workspaces keep history for years, export it, and back it up. Integrations and bots in the channel may be able to read it too.
  • It outlives the reason it was sent. Six months later, nobody remembers that the message is there, and it still works if the password was never changed.

Deleting the message afterwards helps less than it seems. It may already have been read on another device, backed up, or quoted in a reply, and you are relying on remembering to do it.

What you actually want

Handing over a password well comes down to four properties:

  1. Only the person you meant can read it. Not the chat provider, not the server in the middle.
  2. It can be read once, or for a short time, and then it is gone.
  3. You can tell whether it arrived, and whether someone else got there first.
  4. Nothing readable is left in the conversation afterwards.

If you both use the same password manager, use that

When your team already has a password manager with shared vaults, sharing the entry there is the best option. The password stays in one place, it can be changed without telling anyone the new value, and access can be taken away later. A one-time link is for everything else: the colleague in another team, the account that lives outside the vault, the moment when setting up sharing would take longer than the task itself.

How to do it with a one-time link

A one-time link carries the password encrypted, and the key to decrypt it sits in the part of the link after the #, which browsers never send to a server. The link itself can go through the chat, because once it has been opened there is nothing left behind it.

  1. Open PassAlong and paste the password. If it is for a specific account, add the username, and the sign-in address if your colleague might not know it. All three are encrypted together in your browser.
  2. Choose how long the link should live: an hour if they are waiting for it, a day if they are not, a week at most.
  3. Leave "Destroy after it is opened" switched on. The first time the link is revealed, the encrypted text is deleted.
  4. Create the link and send it to your colleague in the chat as usual.
  5. Keep the second link you are given for yourself. It shows whether the secret has been opened, and lets you revoke it if it has not been.

When your colleague opens the link, they see a button, not the password. Nothing is revealed until they press it, so a chat app generating a link preview does not use the link up. After they have revealed it, the message in the chat is a dead link.

When the link says it was already opened

The one-time property doubles as an alarm. If your colleague opens the link and is told it is no longer available, and they did not open it before, someone else did. Your own link will show when that happened. Treat the password as seen by someone else: change it, and send the new one in a fresh link.

For something more sensitive, you can also split the channels: send the link in the chat, and tell your colleague on a call that it is coming. Someone who reads the chat then has a link that has either been used or is about to be.

What a one-time link does not do

It protects the password on the way. It does not protect it after it arrives. If your colleague's computer is compromised, or they paste the password into a note, the link cannot help with that. It also does not decide who should have access in the first place: sharing a personal account's password is worth avoiding even when it is done carefully. How the encryption works, and what the server can and cannot see, is set out in How it works.

Afterwards

  • If the account is shared, ask your colleague to save the password in their password manager, not a note.
  • When someone who knew the password leaves the team, change it. A strong replacement takes a second in the password generator, which runs entirely in your browser.
  • If the password was ever posted in the chat before, change it now: that copy is still there.