4 ms·
With Bitwarden (which is better, cheaper and more open) I honestly don't see any good reason to use LastPass now given their poor track record of security incid
by Croftengea 5y ago
With Bitwarden (which is better, cheaper and more open) I honestly don't see any good reason to use LastPass now given their poor track record of security incidents and naive (not to say stupid) business decisions.
- registeredcorn 5y ago
- Closi 5y agoI subscribe to 1Password which has a similar security model - it's a bit more expensive but I've been very happy with it and it's very polished. (Plus their support is excellent and saved my butt once - I upgraded my personal account to a family account and made my father an admin, after which he decided to 'cancel' his account by deleting the full family account, despite a warning saying everyone's passwords would be permanently erased for the full family. I lost access to all my accounts, however thankfully the 1Password team were incredibly helpful and managed to recover our vault from a backup).
- rlex 5y agoI selfhost bitwarden with rust implementation called vaultwarden, it uses little to no resources and works flawlessly. Compatible with original clients, too. Never looked back.
- kennywinker 5y agoWhere do you host it? I was thinking I’d host it on my NAS and only sync when i’m on my local network. Not sure if that’ll work with the clients? My nas is also it’s too old to have a supported docker package, so that’s a bit of a hurdle there. Pretty uncomfortable with the idea of hosting it on digitalocean or similar… wondering what others do?
- flandish 5y agoI do that but also allow sync when not on local network - via traefik and such as a reverse proxy. However ... I may still turn that off as I have wireguard on everything anyway, so it's super simple to turn wireguard on, sync "locally" and then turn wireguard off.
- rlex 5y agoPersonal k8s cluster >Pretty uncomfortable with the idea of hosting it on digitalocean or similar Everything is encrypted. Use strong master password and 2fa, even if your VM gets dumped and your password gets stolen there's no data they can recover. Alot of people host it on raspberry at home, if you have VPN to home it can be more secure. Also clients are synced, so you can sync while at home network - your in-browser or in-app vault will be available even if server is not reachable at the moment.
- klyrs 5y agoIf your VM gets dumped and your password gets stolen, are you not vulnerable to a SIM swap? Asking out of paranoia.
- rlex 5y agoNobody forces you to use sms for 2fa. I'm not even sure vaultwarden supports SMS. I use https://getaegis.app https://getaegis.app with usual 2FA TOTP, also protected by password. So for someone to gain access to your vault will need: * access to your server with bitwarden/vaultwarden (this one is tricky, someone might inject something in webui JS if it's open to public internet, so keeping it VPNed might be good idea indeed) * access to your master password * access to your mobile device / totp storage and password for it I'd say it's pretty safe from random hackers, but if someone is dead set on getting your data, well https://xkcd.com/538/ https://xkcd.com/538/