3 ms·
why not just self host at this point? this seems like security theater.
by 54ty45hg 3y ago
why not just self host at this point? this seems like security theater.
- lxgr 3y agoI've been considering this, but to be honest, I don't trust myself to keep up with updates and other aspects of opsec for something that I only use for myself and would have to do consistently and reliably at nights and weekends. That would probably be balanced out with my self-hosted instance hopefully being less of a target, but the downside there is that I might not even know that my database was compromised and it's down to my passphrase strength now. With Bitwarden's SaaS, I'd hope that I would hear about such a compromise before too long, giving me time to rotate passwords while GPUs gnaw at my (and everybody else's) passphrase. Additionally, there are certain opportunities for account access recovery that are much harder or impossible when self-hosting, e.g. things like a cool-down period and a warning e-mail before allowing a less-secure 2FA method.