Reset the password. Not the incident.
Every helpdesk knows the shape of it: a temporary password has to reach a user right now, and the channels at hand — email, the ticket, Teams — are all archives. BurnPony gives the credential a link that dies instead of a paper trail that doesn't.
The problem with pasting credentials
A password pasted into a ticket or chat outlives its own rotation: it sits in the thread, the ticket history, the mail store, and every backup of each, searchable long after the account moved on. Even when the credential is temporary, the record of it isn't — and "grep the helpdesk archive for passwords" is a real attacker move precisely because it works.
What BurnPony changes
- The credential never rests in the archive. Send the ticket a BurnPony link instead of the password. The thread keeps a link that burns; the secret itself was encrypted on your iPhone and deleted from the relay on its last view or at expiry.
- Views match the workflow. One view for one user. A handful if the user always fumbles the first attempt. The last allowed view deletes the ciphertext atomically — two simultaneous fetches can't stretch a one-view note.
- Receipts close the loop. Turn on the disclosed read receipt and the ticket can be closed on fact — the note was opened at 14:32 — rather than on silence.
- Expiry enforces your policy. A reset link that must be used today gets a 1-hour or 8-hour expiry, enforced by the server, not by asking nicely.
- No account sprawl. The recipient needs a browser, not an enrollment. Contractors, new hires without mailboxes, and one-off externals all work the same way.
Honest limits
BurnPony moves one artifact — the secret — out of your archives. It is not a PAM system: there's no vaulting, no rotation, no audit trail beyond your own Sent tab, and no admin console. Composing notes requires an iPhone, which may not fit every desk. And no tool prevents a recipient from copying what their screen showed them — pair the note with a forced password change on first login, exactly as you already do.
A sensible pattern
- Generate the temporary credential in your normal tooling, with forced rotation on first use.
- Put the credential — only the credential — in a BurnPony note: 1–2 views, short expiry, receipt on.
- Paste the link into the ticket or chat, with the username travelling in the ticket as usual, so neither channel alone is complete.
- Close the ticket when the receipt lands; burn the note from the Sent tab if the request turns out bogus.
Get BurnPony
Free self-destructing encrypted notes for iPhone. Recipients need only a browser. No accounts, no tracking.