The Danger of Chat Logs
Sending a password via email, Slack, Teams, or SMS leaves a permanent record. These platforms often retain chat histories indefinitely. This means that if an account is compromised years later, attackers can search the chat history for "password" and find sensitive credentials.
Even if you delete a message, you cannot guarantee it was purged from backups, or that the recipient didn't already copy it somewhere insecure.
3 Ways to Share Passwords
- Password Managers: Tools like 1Password or Bitwarden are excellent for sharing within a family or company. However, they require both parties to use the same software, which isn't always possible when working with contractors or clients.
- In-Person or Verbal: Sharing a password over a secure phone call leaves no digital trace, but it is prone to typos and miscommunication.
- One-Time Encrypted Links: Using a service like Hush allows you to send a password that can only be viewed exactly once.
Pre-Share Checklist
Before sharing any password, run through this checklist: - Do you trust the recipient? (No tool prevents screenshots). - Can you share a scoped, limited-permission account instead of a root password? - Does the recipient know to save it in their own password manager immediately?
How Hush Works
- Client-side Encryption: The password is encrypted in your browser before it ever reaches the server.
- Atomic Destruction: The moment the recipient opens the link, the encrypted payload is destroyed in the database.
- No Central Logs: Even if Hush servers are compromised, the plaintext password is never there to be stolen.
Remember: Hush encrypts content in the browser before upload. However, one-time links do not prevent malware on the recipient's computer from stealing the password, nor do they prevent screenshots.