5 ms·
just run your own and use vaultwarden so your passwords aren't on someone else's server
by hijinks 3y ago
just run your own and use vaultwarden so your passwords aren't on someone else's server
- 542458 3y agoUnless you own a datacenter I don’t think that’s a full solution to the “passwords on someone else’s server” problem.
- unforeseen9991 3y agoConsidering I just lost power to my house containing my homelab due to a storm, absolutely lol
- ndsipa_pomu 3y agoWell, I run my own vaultwarden instance (it's great), but I host it on a free Oracle (ewww) cloud instance. At least if that goes down, I can just run it from my last backup and host it in my house until I find something more resilient.
- sotix 3y agoWhen I looked into running it locally on my own server, I couldn’t get it to work because it required https. I connect to my local server with WireGuard without exposing it otherwise to the internet, so I don’t have a need for https. There’s probably a way to set up https, but I gave up after a few hours trying various workarounds while the rest of my local services continue to work via http and WireGuard.
- Isthatablackgsd 3y agoI tried to self host for some services in Docker and they requires https as well. I gave up trying to set up my own after few days of trying set up https, it is way out of my league and I don't have experience with it. I remember Caddy provides automatic https right out of the box. Maybe try looking into Caddy?
- coder543 3y agoPlain Wireguard would require more work to replicate this feature, but I remembered hearing that Tailscale offers a beta feature to provision certificates, which I still need to try out sometime. https://tailscale.com/kb/1153/enabling-https/ https://tailscale.com/kb/1153/enabling-https/
- DavideNL 3y agoWell, any server will at some point crash / need a (partial) restore / need an urgent update / have a power outage / etc, including the one your run yourself - which you also need to manage yourself, which can sometimes be an issue when you're busy. - It's great they offer it of course, as for many people it _is_ a good fit.
- Wowfunhappy 3y agoI have more faith in Bitwarden's ability to secure their servers than I do in my ability to secure my own server. Bitwarden has people who work on this full time, and I do not. I do self-host things, but nothing so security-sensitive.
- xoa 3y ago>I have more faith in Bitwarden's ability to secure their servers than I do in my ability to secure my own server. Bitwarden has people who work on this full time, and I do not. First: E2EE. You're thinking in terms of a web gui, not a E2EE client-server where the server itself is untrusted. If done properly (and I've seen no indication Bitwarden's isn't) that would mean that server compromise is irrelevant anyway beyond uptime. But second in general: Bitwarden has people attacking it full time, and necessarily must be on the public internet with untrusted clients. And I do not. One's own server doesn't need to be on the public internet at all, you can have 100% of access exclusively through a Wireguard or other secure VPN. You have completely control of every single client, because they're all yours. Server blocked from internet entirely, update it out of band, or at least restrict what it can talk to to exclusively upstream update servers. This massively reduces attack surface. If only trusted clients can access something, then compromising it means going through a trusted client. But if the trusted client is compromised in this scenario you're hosed regardless. The server is irrelevant. There's lots of good reasons of course not to run your own thing, but the security aspect gets overdone with false equivalences. It's the equivalent of people pointing at what the likes of Amazon or Google or whomever have to do for database work. But while they have far more resources, they also have far more demands and requirements. Stuff that is very challenging at hyperscale can be done far more simply but still effectively at small/medium scale. It's not wrong to think about the tradeoffs, but worth being cautious of apples to watermelons comparisons.
- suddenclarity 3y agoThis is what stopping me from migrating to Bitwarden. Do I trust their servers and hope they are not as bad as Lastpass? Or do I need to host everything myself and accidently leak it? I've had plenty of Wordpress sites through the years that were exploited before they introduced auto update. I've also heard that the autofill is quite bad. I wish password protection was a lot simpler.
- HumblyTossed 3y agoI trust Bitwarden more than my own abilities, but I have been thinking to do this just as a backup and have it offline unless I need it.
- _lvbh 3y agoI do that & make sure it’s only accessible by connecting via my WireGuard VPN. Works amazingly and I would bet probably more secure than just a master password.
- Barrin92 3y ago>so your passwords aren't on someone else's server being able to transmit information across open or even adversarial channels is the literal reason encryption exists This is security theater, if your security method is keeping your data local you can use notepad, you don't need to go through the hassle of setting up a password manager