3 ms·
> I need to make sure to properly secure the server I'm running it on myself I think, for practically everyone, it is far more likely that shared infrastructur
by gcommer 8y ago
> I need to make sure to properly secure the server I'm running it on myself
I think, for practically everyone, it is far more likely that shared infrastructure (like LP or hosted bitwarden) would be centrally compromised. For example, this post mentioned compromising a safety check for all lastpass users by finding a single vulnerability on a single lastpass domain.
Unless you go to extreme lengths with your personal opsec, a targeted attack by a skilled attacker is pretty much sure to be able to compromise you.
(In fairness, I don't actually know if self hosted bitwarden is enough for all classes of attacks or if I should also compile the clients myself in order to remove any references to the main bitwarden domain)
- tatersolid 8y ago> I think, for practically everyone, it is far more likely that shared infrastructure (like LP or hosted bitwarden) would be centrally compromised. I believe the opposite to be true. Any use of Shodan or any vulnerability scan of the public internet provides strong evidence that centralized, funded and focused services do security better than 99% of orgs and individuals. You can’t run infrastructure and app security better than a specialist SaaS company. You don’t have the same time and money. Yes, the blast radius is smaller for self-hosting, but that’s small comfort when you are still inside the blast radius.
- Faark 8y agoAttackers will spend resources proportional to the expected reward. Alone I am a low value target, but using a standardized solution makes me part of a huge reward pool. As such my strategy is to require manual work by the attacker to compromise me. Combining a few of the shelf components (dropbox + keepass in my case) should be easy enough to not screw up so badly it isn't worth putting your eggs in a different basket as everyone else.