Live data from Hacker News

Bring Your Own Password Manager: Portable BitWarden on a Pi Zero

novamostra.com

81–90 of 93 posts

Re: Bring Your Own Password Manager: Portable BitWarden on a Pi Zero

#81

honestly to me this falls into the category of LARP security. the entire point of encryption is to move sensitive data across adversarial channels. Meaning, if you trust Bitwarden enough to use it at all there's no benefit to not just using their servers (you keep a local copy of your data anyway). If you want to keep your data secure by keeping them on you, just use a notebook. Cheaper than this and works without a…

It not so much that I do not trust the company today, it is that I do not trust them to not silently become adversarial in the future when the government comes knocking or if they get bought out, or whatever.

This is a bit of attack surface that all hosted cloud solutions share, and it is one that it has never been easier to eliminate.

Re: Bring Your Own Password Manager: Portable BitWarden on a Pi Zero

#82

honestly to me this falls into the category of LARP security. the entire point of encryption is to move sensitive data across adversarial channels. Meaning, if you trust Bitwarden enough to use it at all there's no benefit to not just using their servers (you keep a local copy of your data anyway). If you want to keep your data secure by keeping them on you, just use a notebook. Cheaper than this and works without a…

It not so much that I do not trust the company today, it is that I do not trust them to not silently become adversarial in the future when the government comes knocking or if they get bought out, or whatever. This is a bit of attack surface that all hosted cloud solutions share, and it is one that it has never been easier to eliminate.

all of these password managers (including bitwarden) encrypt your data end-to-end and nothing ever leaves your client in a plain state so regardless of who has the backend your data is never touchable. You always only ever need to trust the client, which you do here as well.

Re: Bring Your Own Password Manager: Portable BitWarden on a Pi Zero

#83
post #57

Earlier quoted context omitted.

Good questions and I think they show some of the blind spots I have. I don't share my passwords database. Right now my wife and I do have a very limited number of shared accounts but I set up the same system for her and we simply duplicate the few shared logins we have in our two databases. This could be an issue if we need to share more. Creating new accounts is easy. Both my windows and iOS Keepass clients open the…

Oh, that's neat. What iOS app do you use? I've been using minikeepass but it has been no longer supported for a while now (I've got a copy of the .kdbx for my phone elsewhere, so when it eventually self-destructs I'll still have that at least).

Keepassium. Free, has some limitations that don’t affect me.

Re: Bring Your Own Password Manager: Portable BitWarden on a Pi Zero

#84

Earlier quoted context omitted.

you could use the dns authentication, just set the ip to the local one this box for the domain you own/will be always use then all you have to be able to do is hit external dns and letsencrypt to update the cert.

Ah but I use a personal TLD which does not really exist in the real internet. Can I still use letsencrypt with that?

afaik you can't because then there are no dns records to verify against. You could use a subdomain of a real tld if you had one though, or just bite the bullet and spend 10 bucks a year.

Re: Bring Your Own Password Manager: Portable BitWarden on a Pi Zero

#85
post #46

Earlier quoted context omitted.

What happens when there's more than you who uses the Keepass file and how do you store new passwords to the file when you create new accounts on the web (for various services)? What's the usage flow? Is there browser extension that allows you to interact with it without opening Keepass program? Maintenance you described is easy, but what about the actual usage and sharing passwords?

What's the use case for sharing passwords? I've never had the need to share one in 20+ years of being a power user. If I end up dead, my master password will be shared in my will with appropriate parties. > Is there browser extension that allows you to interact with it without opening Keepass program? I sure hope not.

> What's the use case for sharing passwords?

There's plenty.

> I sure hope not.

Why? I'm not suggesting to have an extension that has access to your file system. Bitwarden has browser extension that communicates to Bitwarden vault via HTTP and it's easy to autofill passwords or generate new credentials.

For throwaway accounts or demo accounts or any kind of new web service/app accounts, it's easy to memorize username and autogenerate a strong, safe password which are saved to vault.

You have the access to that same vault from a different device (smartphone etc), it makes interacting with passwords and its storage extremely easy and without mistakes.

Re: Bring Your Own Password Manager: Portable BitWarden on a Pi Zero

#87

Earlier quoted context omitted.

What's the use case for sharing passwords? I've never had the need to share one in 20+ years of being a power user. If I end up dead, my master password will be shared in my will with appropriate parties. > Is there browser extension that allows you to interact with it without opening Keepass program? I sure hope not.

Unless you live alone and have no family, there are all sorts of scenarios for sharing passwords. Fedex/UPS only lets one account get detailed tracking numbers for an address, so I need to share my Fedex account. To check and pay my freeway tolls I'm only allowed a single account - so it gets shared. Plenty of people share all sorts of subscriptions, be they to Netflix, the New Yorker, or more. I need to share access…

Good luck with SMS MFA then.

Also, for many of my accounts today, I use "Sign in with Google" so it's not even possible for me to share a password or credentials unless I share my whole Google account shebang.

Re: Bring Your Own Password Manager: Portable BitWarden on a Pi Zero

#88

Earlier quoted context omitted.

It not so much that I do not trust the company today, it is that I do not trust them to not silently become adversarial in the future when the government comes knocking or if they get bought out, or whatever. This is a bit of attack surface that all hosted cloud solutions share, and it is one that it has never been easier to eliminate.

all of these password managers (including bitwarden) encrypt your data end-to-end and nothing ever leaves your client in a plain state so regardless of who has the backend your data is never touchable. You always only ever need to trust the client, which you do here as well.

The client is made by the same people at the end of the day, so that is of little comfort.

Also, adversarial does not refer to just possibly breaking encryption, it also applies to daily continuity. I trust my ability to keep a small encrypted password database safe more than I trust some random companies to get bought or change their business model and suddenly I have to decide between a massive Flag Day or paying for something I did not have to before or having some kind of other unwelcome limitation placed on me.

I like controlling my own destiny, thank you very much.

Re: Bring Your Own Password Manager: Portable BitWarden on a Pi Zero

#89
post #56

Earlier quoted context omitted.

Because a password manager is a tiny piece of software. Instead, it is now a multi-component black box installation with a general purpose operating system running on a full-scale Linux machine with a containerization platform designed for datacenters. I am not a fan of this kind of redundancy and opaqueness.

Reminds me of someone writing a little status light app (in the macOS menu bar / windows tray) and choosing Electron for that. Something ridiculous like 200MB+ install size and 150MB memory use.

It's like the old OOP banana/jungle quote but dialed to 11.

Re: Bring Your Own Password Manager: Portable BitWarden on a Pi Zero

#90
post #89
post #56

Earlier quoted context omitted.

Reminds me of someone writing a little status light app (in the macOS menu bar / windows tray) and choosing Electron for that. Something ridiculous like 200MB+ install size and 150MB memory use.

It's like the old OOP banana/jungle quote but dialed to 11.

You wanted a banana, but what you've got is a monkey holding a banana, the whole jungle, the continent on which the jungle is growing, the atmosphere for holding evaporated water for irrigating the jungle, the Sun for providing energy to the jungle trees, and the whole universe.
Post reply on HN