Remix.run Logo
mrj 2 days ago

This is why my self-hosted Vaultwarden is my one password that I have to remember and requires no 2fa, which is the only important account that doesn't have 2fa.

If I wake up in a bathtub missing a kidney I can still get to my passwords and 2fa sources stored with it. Some accounts require SMS (annoyingly) so I'd have to buy a phone but the auth and credit card numbers I need to do that are in Vaultwarden, too.

I don't have good solutions now for OP (other than buy a new phone through your carrier and transfer the number). But everyone else do think through your personal DRP. Generate backup codes and put them somewhere safe, too.

bazmattaz 2 days ago | parent [-]

Welll yeh until a Hargrove fails on your self hosted server

nyx 2 days ago | parent [-]

One of my favorite things about self-hosted Vaultwarden is that you get distributed backups for free. Every client keeps an offline copy of your entire password vault, kept in sync when the client is online.

So for me to lose my vault, not only would my server have to get hit by a bus, but also my phone, my desktop, my HTPC, both laptops...

627467 2 days ago | parent [-]

True.. but now you have more devices to have to secure against attacks...

Edit: this "feature" did save me when my home hosted vaultwarden died due to hdd failure.