| ▲ | techjamie 2 hours ago | |||||||
People are going to try much harder to break into the main Bitwarden servers than they are my little Vaultwarden instance. Plus, I have the ability to lock it behind a VPN so it isn't even publicly exposed. But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager. I'm not sure where your sentiment comes from here. | ||||||||
| ▲ | judge2020 2 hours ago | parent | next [-] | |||||||
> But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager. A PW manager relying on only a single password as the encryption key - and one that you type in frequently, mind you - has always been a little of a design issue to me. I much prefer 1Password's approach where they have a usually-hidden second secret (the "Secret Key") that both (A) isn't shown unless you're setting up another device, and (B) acts as extra data needed to form the decryption key for your vault. The main threat model I'm thinking of protecting against is a 1password vault data breach of some kind (or possibly cooperation with government agencies) + password exposure in some way (be it from CCTV-extracted password entries, over-the-shoulder watching, etc), as even with both of those factors, they would somehow need to get your secret key to decrypt vaults. Like, all of those lastpass vaults obtained during the Lastpass hack would be de-facto useless even with a correct password if their design included some sort of hidden secret secret. | ||||||||
| ▲ | atherton94027 2 hours ago | parent | prev | next [-] | |||||||
I'm not sure that calculus is going to be true for much longer – with the costs of AI falling, it's going to be much easier to throw tokens at the problem even tiny targets that wouldn't have been worth it before. Can you guarantee your VPN is patched and secure at all times? | ||||||||
| ||||||||
| ▲ | technolo-g 2 hours ago | parent | prev | next [-] | |||||||
I took it to mean non-self hosted is like publishing your passwords online, which I agree with. | ||||||||
| ▲ | iohvvbhdyh 2 hours ago | parent | prev [-] | |||||||
AI will do it | ||||||||