3 ms·
I’ve used Vaultwarden for at lesst 7 years, I’m sure for longer but I’m not sure how long. Never had an issue with Vaultwarden itself. Restored from backups se
by JimBlackwood 5mo ago
I’ve used Vaultwarden for at lesst 7 years, I’m sure for longer but I’m not sure how long.
Never had an issue with Vaultwarden itself. Restored from backups several times for a variety of reasons (migrating host, corrupt hard disk, re-installs) and that always worked first try.
In regards to hardering, the wiki has a good guide: https://github.com/dani-garcia/vaultwarden/wiki/Hardening-Guide https://github.com/dani-garcia/vaultwarden/wiki/Hardening-Gu....
- EvanAnderson 5mo agoPretty similar experience for me, albeit I've only been managing it for about a year. Restore from backup testing was straightforward. We haven't had any problems w/ the application itself. I used that that hardening guide for my setup. The one I manage is exposed to the Internet and I'm bringing traffic into it via a reverse proxy.
- akerl_ 5mo agoThat guide is wild. By default it allows public registration, shows password hints, requires a reverse proxy for robust TLS but then passes tokens via GET params, runs in the container as root. Recommends fail2ban because it doesn't have any coverage against brute force. Recommends using a custom path for security. This feels less like a guide on hardening Vaultwarden than a guide on why I should be skeptical about it.
- zx8080 5mo agoSince it's authored by the vaultwarden collaborators, I would not trust the project any bit of my passwords.
- tacticalturtle 5mo agoI’m not an expert with web sockets or web development - but re: Get Params, Vaultwarden has to follow the API of the upstream Bitwarden implementation: https://github.com/dani-garcia/vaultwarden/discussions/1549#discussioncomment-539972 https://github.com/dani-garcia/vaultwarden/discussions/1549#... The upstream also had this issue, which appeared to be closed without a PR: https://github.com/bitwarden/server/issues/3650 https://github.com/bitwarden/server/issues/3650
- drzaiusx11 5mo agoRequiring a reverse proxy for TLS is pretty standard, but the rest of those findings are egregious (if they haven't been addressed yet.)
- akerl_ 5mo agoThe part I found jarring was that it will totally do TLS for you but using a TLS stack they don’t recommend, and if you put it behind a reverse proxy you also need to know to do custom log redaction to avoid logging tokens.
- harrall 5mo agoThose problems are endemic to all web apps. e.g. You can’t just provide software to people that obtains TLS certs on their behalf: you have no idea how their infra is setup. Hosting any app on your own infra is a serious skill set.
- akerl_ 5mo ago> Those problems are endemic to all web apps. No, they’re not. They’re design choices where the default that has been chosen is dangerous for somebody deploying the software. Plenty of web apps do not have those pitfalls.