4 ms·
Better security for sure. Bitwarden is a massive target while I am not. The chance that bitwarden has a databreach is way bigger than the chance that my server
by Yujf 4y ago
Better security for sure. Bitwarden is a massive target while I am not. The chance that bitwarden has a databreach is way bigger than the chance that my server gets hacked. No one cares about my server, I am nobody not worth attacking. As long as I don't leave any big holes that can be found by an untargeted attack (which I won't, I run everything behind a personal VPN) it is safer.
- 542458 4y ago> I am nobody not worth attacking. You’re probably not worth individually attacking, but a brief look at the failed ssh login logs of any insignificant server shows that you probably are worth automated attacks… so I suppose the question is “Are you more vulnerable due to a) the risk of getting pwnt by an automated attack (due to a misconfiguration or being even a little slow to install a critical patch) or b) due to the risk of bitwarden getting pwnt by a sophisticated targeted actor?” Further complicating this math is the E2EE nature of it, so it’s not just enough to pwn a server, you’d need to also compromise the client application. Actually, now that I think about it, if you can compromise the client you don’t even need to compromise the server. I’m not really sure under what scenarios running your own server would protect you in in that case.
- dvzk 4y ago> Further complicating this math is the E2EE nature of it, so it’s not just enough to pwn a server, you’d need to also compromise the client application. The webvault is both a server and a client, and you can't not use it. As soon as you sign into it once (which you must, with the official apps) you have allowed unsigned ephemeral javascript code to run against your decrypted vault.
- hackerman123469 4y agoI can contest to this, I am by no mean important and none of my servers that I own have any importance, BUT I have thousands of people trying to remote into the servers every day and also thousands of requests into some of my webservers with things like /admin /phpmyadmin or whatever, you name it. So yeah even if you aren't a big target then you are still a target for automated attacks as they just pick whatever IPs they can find and try to breach.
- phpisthebest 4y agoThe entire purpose of bitwarden is they do not have your unencrypted data in the first place, so what is the fear there?
- dvzk 4y agoThe Bitwarden webvault infrastructure is a doomsday target. If it's compromised, no evidence of a client backdoor will exist except in the server logs. You can't avoid using it, because you need to sign into the webvault to configure 2FA. Want to change the encryption passphrase? Guess what, you need to use the webvault. Bitwarden's vault encryption is essentially reduced to the security model of TLS.
- jmcnulty 4y agoAnd? If you don't trust TLS then I assume you don't trust web banking, or purchasing anything over the internet for that matter. Might as well give up on technology and go find yourself a nice quiet pastoral life.
- dvzk 4y agoI trust the cryptography behind TLS. I don’t trust every website using TLS. The difference between end-to-end encryption and transport-layer encryption is the website operator can recover the plaintext. And the point of the comment I responded to was that Bitwarden data is not recoverable. I’m glad that you think E2EE is a waste of effort though.
- dvzk 4y agoFollowing up, I find it funny that this old meme comment thought orders and banking are our most trusted activities, and not our communications and data storage.
- hackerman123469 4y agoFor me personally, I don't actually trust any of that. Any purchase I do online is done with a virtual card that links to a bank account that only ever has the amount I need to pay for whatever it is I am currently purchasing. That way it doesn't matter if the information is stolen etc. because there is no more money to use and I can cancel the card as easily as I can create a new. For banking I also only use my banks official app, I don't know how exactly it works and I assume it does use some form of http and whatnot, but I wouldn't trust using a bank through the browser as you never know what kind of thing an extension or something have in there.