The Danger of Forwarding OTPs
One-Time Passwords (OTPs) are sensitive authentication credentials. Although they expire quickly, sending them via Slack, Microsoft Teams, or email normalizes incredibly weak access practices.
When a team gets used to pasting 2FA codes in shared chat channels, they stop questioning the authenticity of access requests, opening the door for social engineering and phishing attacks. Furthermore, retaining authentication codes in chat history creates unnecessary permanent records.
Shared Accounts Are Not Recommended
Shared accounts and forwarded OTPs are insecure workarounds, not a recommended authentication model. They eliminate accountability and break the fundamental security principle of attributing actions to individual users.
Safer Long-Term Alternatives
Organizations should transition away from shared credentials and implement proper access controls: - Individual User Accounts: Every employee should have their own distinct login. - Role-Based Access Control (RBAC): Assign permissions based on an employee's role, not by handing them root passwords. - Single Sign-On (SSO): Centralize authentication to manage offboarding safely. - Shared Authenticators: If a shared account is absolutely unavoidable (e.g., legacy software), use a secure password manager that supports shared OTP generation or an admin-approved workflow, rather than forwarding SMS codes.
Harm Reduction, Not a Solution
If temporary transmission of an authentication code is strictly necessary for an authorized team member during an emergency, tools like Hush can act as a short-term harm-reduction measure. By using a one-time encrypted link, the credential is not permanently recorded in a chat log.
However, Hush does not magically make shared-account access "safe." It is a transmission tool, not a substitute for proper identity verification or access controls.