In brief
Passing on a password safely
The password does not belong in the same mail. And ideally nowhere it stays.
Never pass a password over the same channel as the access it belongs to. Best is a link that works exactly once and then expires – that way you also learn whether someone else got there first. Chat and email are poor choices because both keep the password forever.
Why chat and mail fail here
Not because they transmit insecurely – mostly they do that well. Because they keep things. The Wi-Fi password you typed into the family chat in 2021 is still there today. The initial password for a new employee sits in their mailbox until they leave the company, and in the archive afterwards.
On top of that: you never learn whether someone read along. A password in a chat is like a key under the mat – you do not know who has already looked.
What is better
Separate channels. Access by mail, password by phone or text. Simple and effective, because an attacker would need both.
A password manager with sharing. If both sides use the same one, this is the cleanest route for lasting team access.
A one-time link. For anything handed over once and then changed. The link works exactly once; if someone opens it before the recipient, the recipient notices immediately because nothing arrives. That is the real advantage: you learn about an access instead of never noticing it.
And change it afterwards
An initial password stays an initial password. Whoever hands one over should say that it is to be changed at first sign-in – otherwise it is still on the same account five years later.
And with tunnl.
With tunnl. you set a message to “readable once”: it is shown when opened and gone afterwards, for us too. Add a short pickup window – a few minutes is enough if you have the person on the phone. Your account shows whether and when it was collected.
What tunnl. cannot do here: Whoever intercepts the link and opens it first gets the password. The difference from a chat is that nobody else gets it afterwards – and you notice.
What else tunnl. is for · How this works technically · Common questions

