6 ms·
First paragraph on their page disqualifies it completely. I do not want my passwords on anybody’s servers. Our secure cloud syncing features allow you to acces
by albertop 8y ago
First paragraph on their page disqualifies it completely. I do not want my passwords on anybody’s servers.
Our secure cloud syncing features allow you to access your data from anywhere, on any device! Your vault is conveniently optimized for use on desktop, laptop, tablet, and phone devices.
- ReverseCold 8y ago> I do not want my passwords on anybody’s servers. What about your own server? https://help.bitwarden.com/article/install-on-premise/ https://help.bitwarden.com/article/install-on-premise/
- slenk 8y agoI run my own server; it works great and is incredibly easy to set up. I would highly recommend people check this software out. It's maybe not as feature rich as other password managers, but it is being actively developed and the few times I had questions I got a quick response from Kyle (the creator).
- DavideNL 8y ago> I run my own server If you think it matters where the data is stored (which shouldn't matter because it should be client side encrypted), running your own server would also be a risk. Because you cannot possibly have the same resources to monitor your server/router for suspicious activity...
- SteveGoob 8y agoThat's true, but at the same time, there's something to be said for not storing my eggs in the huge basket with everyone else's eggs in it too. By separating the storage of passwords, we drive down the economic interest in breaking into any one of the individual baskets.
- slenk 8y agoI still think it matters where data is stored because I don't trust most companies to not have back doors. Since its all my own equipment and I have a background in this sort of stuff, I know what I am looking for when it comes to intrusions.
- unethical_ban 8y agoMaybe I do, maybe I don't want my passwords to be at the same target as others, maybe I don't trust the hosting provider or Bitwarden the company (which you could argue, then I shouldn't trust the software, but I can monitor its behavior).
- techsupporter 8y agoTo me, this disqualifies it: > Each Bitwarden installation requires a unique installation id and installation key. If I’m self hosting, I want it to be independent of the code provider. It is bad enough, to me, that I have to pay a subscription fee to self-host “advanced” features like Yubikey auth. That’s the same kind of annoying that my own install still must link to their server that can die at any moment. Let me buy the software to self-host with all of the features. The “subscription” and “integrated” mindset has no place in “I’m doing it myself” installs.
- jchw 8y ago>That’s the same kind of annoying that my own install still must link to their server that can die at any moment. With software like a password manager, if it's not actively maintained you're not going to want it anyway. So the same risk of the developers either discontinuing the product OR changing the pricing model applies just about evenly. Being open source, at least the community can fork and maintain the software if the developers ever did throw in the towel, similar to TrueCrypt's forks.
- bad_user 8y agoIt’s expensive to setup, if you need to rent a VPS it’s going to cost $5 per month which is probably the most expensive option and if you can’t trust somebody else’s server, you definitely CANNOT trust your own VPS ;-)
- unethical_ban 8y agoI had considered setting it up until I saw that SQL Server won't start unless the container has 2G of RAM. That quadruples the price of a VM on hosting providers from the usual minimum. What is essentially a small CRUD app with encryption requirements shouldn't need 2G just for a database app.
- yyx 8y agohttps://github.com/vvondra/bitwarden-serverless https://github.com/vvondra/bitwarden-serverless
- illuminati1911 8y agoMaybe you should have read a bit more than just the homepage title. "HOST IT YOURSELF Don't want to use the Bitwarden cloud? You don't have to. With Docker you can easily host Bitwarden's entire infrastructure stack on the platform of your choice."
- albertop 8y agoThanks to the comments there I finally did. First I was excited with the possibility of setting up my home server. But after reading more, the complexity of the setup and required resources are way to much for my use case. I think this is great for a small business, but it is huge overkill for me (home use). I just want my laptop to sync with my iDevices. Peer to peer vault sync built into the app would be much easier and does not require server running all the time. Plus it does not put man in the middle for simple sync. Nothing wrong with Bitwarden for small business or even enterprise it is just not for personal use if you want your secrets secret.
- woah 8y agoIt's encrypted on the client.
- cjh_ 8y agoThe 'point' of solutions in this space is that they allow password access across devices. They use end-to-end encryption and support self hosting, what else could they do?
- albertop 8y ago1Pasword for ages had ability to sync your computer and iDevices on the same WiFi network by opening direct connections. A bit more inconvenient than cloud base sync, but convenience was always death to security :-) Self hosting may be the answer.