this post was submitted on 08 Oct 2024
166 points (96.6% liked)

Selfhosted

60887 readers
617 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

I'm going to move away from lastpass because the user experience is pretty fucking shit. I was going to look at 1pass as I use it a lot at work and so know it. However I have heard a lot of praise for BitWarden and VaultWarden on here and so probably going to try them out first.

My questions are to those of you who self-host, firstly: why?

And how do you mitigate the risk of your internet going down at home and blocking your access while away?

BitWarden's paid tier is only $10 a year which I'm happy to pay to support a decent service, but im curious about the benefits of the above. I already run syncthing on a pi so adding a password manager wouldn't need any additional hardware.

you are viewing a single comment's thread
view the rest of the comments
[–] dan@upvote.au 1 points 2 years ago* (last edited 2 years ago) (2 children)

Accessing Vaultwarden through a VPN

Hmm maybe I should move mine to my VPN. Currently I have it publicly accessible so I can access it from systems where I can't run other VPNs for security reasons (work systems). I use a physical token with FIDO2 (Yubikey) for two factor authentication though, so I'm not too worried about unauthorized access.

[–] Chewy7324@discuss.tchncs.de 2 points 2 years ago (1 children)

Vaultwarden is one of the few services I'd actually trust to be secure, so I wouldn't worry if you update timely to new versions.

[–] dan@upvote.au 1 points 2 years ago (1 children)

I hope it gets security audited one day, like Bitwarden was.

[–] Chewy7324@discuss.tchncs.de 2 points 2 years ago (1 children)

Because they use the official apps/web-vault, they don't need to implement most of the vault/encryption features, so at least the actual data should be fine.

Security audits are expensive, so I don't expect it to happen, unless some sponsor pays for it.

They have processes for CVEs and it seems like there wasn't any major security issues (altough I wouldn't host a public instance for unknown users).

[–] dan@upvote.au 2 points 2 years ago

That's a good point. I didn't consider the fact that all the encryption is done client-side, so that's the most important part to audit (which Bitwarden has already done).

[–] k4j8@lemmy.world 1 points 2 years ago

I have my Vaultwarden public so I can use it at work too, but my firewall blocks all external IPs except my work's IP.