Not sure I understand why you’d want to self host a password manager. Bitwarden has never been breached AFAIK. How is it better or safer to keep if self hosted?

  • charmstrong70B
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    Bitwarden has never been breached AFAIK.

    What you mean is it hasn’t been breached *yet*.

    All commercial password managers have a huge, fuck off, target on their backs

    Nobody is going to come after some random blokes self-hosted password manager to get access to their Sonarr (I’m trivialising to make the point) as long as if a similar effort would get them into Bitwarden.

    It’s the same principal as bears in the wood - nobody needs to outrun a bear, just your companion

    • TrashrascallOPB
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      OK, thanks for the solid answer. I suppose the core of my question was that pretty much: is it just as secure AND a less likely target than bitwarden. That makes a lot of sense to me. I would probably still worry about the strength of the code , though. Do we know if/how it’s been audited?

      • charmstrong70B
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        OK, thanks for the solid answer. I suppose the core of my question was that pretty much: is it just as secure AND a less likely target than bitwarden. That makes a lot of sense to me. I would probably still worry about the strength of the code , though. Do we know if/how it’s been audited?

        I mean, your best having a look at the official Git but, i’d say, access/visibility is the most important.

        Is it on your LAN/not open then even if it was less secure, it’d still be more secure if you know what I mean.

        I host mine on a VPS but it’s behind traefik with authelia (and 2FA). Plan is to get fail2ban setup over the next couple of evenings. SSH is cert only, probably going to change the port too but not sure if that’s really necessary. I’m comfortable exposing on that basis.

        • awildboopB
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 year ago

          change ssh port, put an ssh tarpit on the default