| ▲ | lstodd 2 hours ago |
| Hosted password manager is equivalent to publishing all your passwords outright. Now, given the general ignorance on infosec I'm suprised that people actually refused to pay to upload their passwords. The world has some hope after all. |
|
| ▲ | ricericerice 2 hours ago | parent | next [-] |
| you have no idea how bitwarden works, do you... by that logic, every time you send a password over a TLS connection, you're publishing it outright too |
|
| ▲ | techjamie 2 hours ago | parent | prev | next [-] |
| People are going to try much harder to break into the main Bitwarden servers than they are my little Vaultwarden instance. Plus, I have the ability to lock it behind a VPN so it isn't even publicly exposed. But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager. I'm not sure where your sentiment comes from here. |
| |
| ▲ | judge2020 2 hours ago | parent | next [-] | | > But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager. A PW manager relying on only a single password as the encryption key - and one that you type in frequently, mind you - has always been a little of a design issue to me. I much prefer 1Password's approach where they have a usually-hidden second secret (the "Secret Key") that both (A) isn't shown unless you're setting up another device, and (B) acts as extra data needed to form the decryption key for your vault. The main threat model I'm thinking of protecting against is a 1password vault data breach of some kind (or possibly cooperation with government agencies) + password exposure in some way (be it from CCTV-extracted password entries, over-the-shoulder watching, etc), as even with both of those factors, they would somehow need to get your secret key to decrypt vaults. Like, all of those lastpass vaults obtained during the Lastpass hack would be de-facto useless even with a correct password if their design included some sort of hidden secret secret. | |
| ▲ | atherton94027 2 hours ago | parent | prev | next [-] | | I'm not sure that calculus is going to be true for much longer – with the costs of AI falling, it's going to be much easier to throw tokens at the problem even tiny targets that wouldn't have been worth it before. Can you guarantee your VPN is patched and secure at all times? | | | |
| ▲ | technolo-g 2 hours ago | parent | prev | next [-] | | I took it to mean non-self hosted is like publishing your passwords online, which I agree with. | |
| ▲ | iohvvbhdyh 2 hours ago | parent | prev [-] | | AI will do it |
|
|
| ▲ | selectodude 2 hours ago | parent | prev | next [-] |
| I mean, no it's absolutely nothing like "publishing all your passwords outright" but fine. Pay the $20/yr and don't have them host it, host it yourself. Just pay them the $20. |
|
| ▲ | orf 2 hours ago | parent | prev | next [-] |
| Your comment is generally ignorant on infosec. |
|
| ▲ | willmadden 2 hours ago | parent | prev [-] |
| Do you have a quantum computer from the future and a file of passwords that haven't been changed in 50 years? Complete nonsense. |