3 ms·
Personal k8s cluster >Pretty uncomfortable with the idea of hosting it on digitalocean or similar Everything is encrypted. Use strong master password and 2fa,
by rlex 5y ago
Personal k8s cluster
>Pretty uncomfortable with the idea of hosting it on digitalocean or similar
Everything is encrypted. Use strong master password and 2fa, even if your VM gets dumped and your password gets stolen there's no data they can recover.
Alot of people host it on raspberry at home, if you have VPN to home it can be more secure.
Also clients are synced, so you can sync while at home network - your in-browser or in-app vault will be available even if server is not reachable at the moment.
- klyrs 5y agoIf your VM gets dumped and your password gets stolen, are you not vulnerable to a SIM swap? Asking out of paranoia.
- rlex 5y agoNobody forces you to use sms for 2fa. I'm not even sure vaultwarden supports SMS. I use https://getaegis.app https://getaegis.app with usual 2FA TOTP, also protected by password. So for someone to gain access to your vault will need: * access to your server with bitwarden/vaultwarden (this one is tricky, someone might inject something in webui JS if it's open to public internet, so keeping it VPNed might be good idea indeed) * access to your master password * access to your mobile device / totp storage and password for it I'd say it's pretty safe from random hackers, but if someone is dead set on getting your data, well https://xkcd.com/538/ https://xkcd.com/538/