6 ms·
I 'mirror' my Bitwarden login entries in a KeepassXC database, so I have an offline carbon copy incase Bitwarden's servers are wiped or not accessible, or for w
by sysadm1n 3y ago
I 'mirror' my Bitwarden login entries in a KeepassXC database, so I have an offline carbon copy incase Bitwarden's servers are wiped or not accessible, or for whatever reason, I can't access my Bitwarden vault. I would suggest everyone do the same. The only pain point is remembering to make a carbon copy of each entry you add to Bitwarden, in the KeepassXC database.
I also make copies of my KeepassXC database in several cloud storage services incase of a house eating event which destroys my hard-drives (unlikely but still a possibility). I really don't like the idea of being locked out of my digital life.
Terence Eden has a good article about this potential scenario;
https://shkspr.mobi/blog/2022/06/ive-locked-myself-out-of-my-digital-life/ https://shkspr.mobi/blog/2022/06/ive-locked-myself-out-of-my...
For those wondering why I use Bitwarden as-well as KeepassXC:
1.) Redundancy. Can't get at my KeepassXC?, then I try Bitwarden. Can't get at my Bitwarden? Then I try KeepassXC. Can't get access to both? Then I'm screwed (but this is unlikely).
2.) Browser extension. I like to be able to login easily to sites using their extension.
3.) LOCKSS (Lots of copies keeps stuff safe). Having a cloud-based mirror of my login entries stored in Bitwarden is marginally better than solely relying on KeepassXC.
4.) Logging into KeepassXC is sometimes more complicated than logging into Bitwarden. I have a long seven word passphrase for KeepassXC, and use a keyfile which I have to 'hunt down' in the filesystem each time I go to access KeepassXC (I have disabled the ability to store the last used database & keyfile for security reasons). With Bitwarden I just open the app and if it's unlocked, I get quick access to everything.
- dotnet00 3y agoWhy not just periodically backup your bitwarden vault to external storage?
- lxgr 3y agoFrom GP: > incase of a house eating event which destroys my hard-drives I worry about this as well. Yes, a friend's house is an option, but not everybody has friends or family in the same city, and if they're further away, updating copies is a pain.
- dotnet00 3y agoAh, fair point. I should do something like that for my own setup then. My current setup may also be vulnerable to that failure mode.
- eviks 3y agoHow is Dropbox shared folder is a pain in updating copies across cities?
- lxgr 3y agoSyncing your password safe to Dropbox is a completely different scenario, with a corresponding different threat model. It may work for some people, but on average, I'd say it's worse than relying on a dedicated/"native" password safe cloud syncing service. In any case, it's certainly not an alternative to a physical offline copy.
- eviks 3y agoOn the contrary, it's very similar - you share a keyfile to your friends in a different city and then you encrypt your password safe with that extra keyfile that hasn't touched Dropbox. This solves the threat model issue while also relieving you of the pain of syncing the password safe (in this case syncing is even more convenient than your same-city-physical-visit model)
- havnagiggle 3y agoWhat exactly is Bitwarden getting you if you're doing this copy process? I have only used Keepass and haven't read why Bitwarden would be superior for some scenarios over what I am already doing.
- sysadm1n 3y ago> What exactly is Bitwarden getting you 1.) Redundancy. Can't get at my KeepassXC?, then I try Bitwarden. Can't get at my Bitwarden? Then I try KeepassXC. Can't get access to both? Then I'm screwed (but this is unlikely). 2.) Browser extension. I like to be able to login easily to sites using their extension. 3.) LOCKSS (Lots of copies keeps stuff safe). Having a cloud-based mirror of my login entries stored in Bitwarden is marginally better than solely relying on KeepassXC. 4.) Logging into KeepassXC is sometimes more complicated than logging into Bitwarden. I have a long seven word passphrase for KeepassXC, and use a keyfile which I have to 'hunt down' in the filesystem each time I go to access KeepassXC (I have disabled the ability to store the last used database & keyfile for security reasons). With Bitwarden I just open the app and if it's unlocked, I get quick access to everything.
- havnagiggle 3y agoThanks! I will probably just stick with Keepass but this was a nice write-up to consider. 1) I have my database replicated several places already. Cloud storage, mobile, FTP server, etc. 2) I don't use a browser extension on desktop, but I know there is one. On mobile the accessibility permissions allow it to suggest login information both in third party apps and in the browser. I've found it works fairly well. If you aren't able to open your database quickly it might not be as convenient. 3) This sounds the same as what I was considering for (1). Historical backups would be important for recovering from possible corruption, but I have not run into this yet for Keepass. 4) Understood. Bitwarden doesn't support keyfiles? I have been close to splitting my Keepass DB up into several, but haven't pulled the trigger on that effort.
- noAnswer 3y ago4. is ... interesting :-) You made access to KeePass more obscure for "security reasons." But fear not: "With Bitwarden I just open the app." Okay cool.
- Timber-6539 3y agoWhy not just use KeePassXC ?
- sysadm1n 3y ago1.) Redundancy. Can't get at my KeepassXC?, then I try Bitwarden. Can't get at my Bitwarden? Then I try KeepassXC. Can't get access to both? Then I'm screwed (but this is unlikely!). 2.) Browser extension. I like to be able to login easily to sites using their extension. 3.) LOCKSS (Lots of copies keeps stuff safe). Having a cloud-based mirror of my login entries stored in Bitwarden is marginally better than solely relying on KeepassXC. 4.) Logging into KeepassXC is sometimes more complicated than logging into Bitwarden. I have a long seven word passphrase for KeepassXC, and use a keyfile which I have to 'hunt down' in the filesystem each time I go to access KeepassXC (I have disabled the ability to store the last used database & keyfile for security reasons). With Bitwarden I just open the app and if it's unlocked, I get quick access to everything.
- Timber-6539 3y ago1. You can store your encrypted KeepassXC kdbx file anywhere you wish. 2. KeepassXC has a browser extension. 3. Refer to point 1. 4. Using a keyfile is optional and IMO don't see how it adds any security benefits to the master passphrase. The only reason Bitwarden "just opens" from the last session is because of the very features you have disabled in KeepassXC (remember last used kdbx). Launching KeepassXC for me has exactly the same steps as Bitwarden has. Open program, put correct passphrase (or insecure PIN on Bitwarden for the lazy folks) and the password database unlocks.
- eurg 3y agoKeePassXC even had the advantage that I only have to unlock once for both desktop app and browser extension. BitWarden requires separate unlocks.
- mdaniel 3y ago> 4. Using a keyfile is optional and IMO don't see how it adds any security benefits to the master passphrase. I believe it fulfills the same 2FA role as does the Secret Key in 1Password <https://support.1password.com/secret-key-security/ https://support.1password.com/secret-key-security/>: combining something you know (passphrase) with something you have (keyfile/Secret Key), thus making a potential Dropbox breach (or wherever you store your .kdbx) not subject to offline dictionary attacks -- err, unless you also stored your keyfile in Dropbox in which case, yes, it wouldn't add any security benefits
- ronnier 3y agoI just host my own Bitwarden. I try to self host as much as possible and be anti cloud
- seanthemon 3y agoUsing something like vaultwarden? I'm curious how do you keep it secure from intrusion? I'm looking to do the same
- donutshop 3y ago> Using something like vaultwarden? I'm curious how do you keep it secure from intrusion? I'm looking to do the same The official bitwarden self hosted setup works flawlessly. Hosting it at home and access it through tailscale.
- RyeCombinator 3y agoAnti public cloud here as well
- CommanderData 3y agoWhen Bitwardens servers are inaccessible mobile and windows app continue to work just fine using a cached version. In my case even sync new passwords once the seever/Internet comes back up.
- BiteCode_dev 3y agoIndeed, it worls online fine. Also there is a stand alone desktop version, no need for keypass. I do use keypass to save things I don't want to expose in an online service, no matter how secure it is.
- 54ty45hg 3y agowhy not just self host at this point? this seems like security theater.
- lxgr 3y agoI've been considering this, but to be honest, I don't trust myself to keep up with updates and other aspects of opsec for something that I only use for myself and would have to do consistently and reliably at nights and weekends. That would probably be balanced out with my self-hosted instance hopefully being less of a target, but the downside there is that I might not even know that my database was compromised and it's down to my passphrase strength now. With Bitwarden's SaaS, I'd hope that I would hear about such a compromise before too long, giving me time to rotate passwords while GPUs gnaw at my (and everybody else's) passphrase. Additionally, there are certain opportunities for account access recovery that are much harder or impossible when self-hosting, e.g. things like a cool-down period and a warning e-mail before allowing a less-secure 2FA method.
- noam_compsci 3y agoGenuine question: why all the hassle when it’s so easy to reset passwords?
- miketery 3y agoPassword reset assumes two things: A - the service doesn't encrypt your data (or has access to your private keys), and B - that you have access to the second factor which is used to reset your password (e.g. a backup email address). Secure password managers do not have access to your private key (i.e. the encryption key), as such if you lose the seed there is no recovery. In the case with other services (i.e. they can reset your password) there is a chance you could lose access to your backup email or phone number used for resetting. Edit: some services do allow reset by proving your "identity" (e.g. bank), in which case you have to go through customer service and provide requested information. (I put "identity" in quotes, because nefarious actors can sometimes prove this too).
- thefz 3y ago> I 'mirror' my Bitwarden login entries in a KeepassXC database I do this manually and I want to know if you automate it and how.
- miketery 3y agoI'm working on a product to solve this problem (i.e. where do you backup your seed, high value keys / secrets, 2FA codes). The approach is social recovery (threshold cryptography) for the root seed, and a digital agent component (i.e. DWN - distributed web noted) SaaS or self hosted. The digital agent is used for encrypted backups and to communicate with other parties (contacts). Does this sound interesting to you?