When you all self-host this, you also do the following, right? - Create threat models that identify weaknesses in the design of your self-hosted setup. - Harden the OS with things like MAC, and harden the container with dropped privs, read-only root filesystem, and outbound network filtering. - Deploy an intrusion detection system to know if you've been compromised. - Perform all OS and app patching automatically, or…
The bigger risk is likely your client, which might even be inside your browser, gets hacked / compromised. And that is the same regardless if you self-host.
Vaultwarden: Unofficial Bitwarden compatible server written in Rust
81–90 of 124 posts
Re: Vaultwarden: Unofficial Bitwarden compatible server written in Rust
#82Earlier quoted context omitted.
Not to defend them, but it doesn't matter if a hosting provider does that. So long as you can sue them for your full damages when it goes wrong. That's the whole point of SaaS isn't it? We pay you to manage this, you manage it appropriately taking advantage of economies of scale, we sue the shit outta you if it goes wrong.
> So long as you can sue them for your full damages when it goes wrong. Generally, you cannot.
Your identity is still stolen, your private photos leaked, your company destroyed, etc.
Re: Vaultwarden: Unofficial Bitwarden compatible server written in Rust
#83I've been self-hosting this for years now, works flawlessly.
Same, although in the end I figured I'll give BitWarden my money, as it's more than cheap enough.
Re: Vaultwarden: Unofficial Bitwarden compatible server written in Rust
#84When you all self-host this, you also do the following, right? - Create threat models that identify weaknesses in the design of your self-hosted setup. - Harden the OS with things like MAC, and harden the container with dropped privs, read-only root filesystem, and outbound network filtering. - Deploy an intrusion detection system to know if you've been compromised. - Perform all OS and app patching automatically, or…
Re: Vaultwarden: Unofficial Bitwarden compatible server written in Rust
#85When you all self-host this, you also do the following, right? - Create threat models that identify weaknesses in the design of your self-hosted setup. - Harden the OS with things like MAC, and harden the container with dropped privs, read-only root filesystem, and outbound network filtering. - Deploy an intrusion detection system to know if you've been compromised. - Perform all OS and app patching automatically, or…
For personal use, why bother with this instead of something like Strongbox syncing to a cloud drive?
Re: Vaultwarden: Unofficial Bitwarden compatible server written in Rust
#86After being fed up with AgileBits' (1P's owner) shenanigans (hiding critical threads on their user forum, ignoring customer voices wilfully, being generally dismissive of criticism), I decided to give Bitwarden a try. I used it in conjunction with Vaultwarden for a year with the idea that I'd evaluate it as a family-wide replacement for 1P. In the end I went back to 1P. 1P does some things amazingly well. Here's the…
Also, I get a lot of mileage out of the Fastmail "masked email" integration with 1P
I also still run KeePassXC just for its GPG agent support, which 1P hasn't (and I suspect won't) supported. I think 1P is all-in on using SSH keys to sign commits, which yes, is one GPG use case, but come on
Re: Vaultwarden: Unofficial Bitwarden compatible server written in Rust
#87After being fed up with AgileBits' (1P's owner) shenanigans (hiding critical threads on their user forum, ignoring customer voices wilfully, being generally dismissive of criticism), I decided to give Bitwarden a try. I used it in conjunction with Vaultwarden for a year with the idea that I'd evaluate it as a family-wide replacement for 1P. In the end I went back to 1P. 1P does some things amazingly well. Here's the…
Re: Vaultwarden: Unofficial Bitwarden compatible server written in Rust
#88Re: Vaultwarden: Unofficial Bitwarden compatible server written in Rust
#89When you all self-host this, you also do the following, right? - Create threat models that identify weaknesses in the design of your self-hosted setup. - Harden the OS with things like MAC, and harden the container with dropped privs, read-only root filesystem, and outbound network filtering. - Deploy an intrusion detection system to know if you've been compromised. - Perform all OS and app patching automatically, or…
You’re really, really sure your hosted provider does all of that correctly, right?
I don't really understand why people bother with this security theater, all the self hosting is completely redundant.
Re: Vaultwarden: Unofficial Bitwarden compatible server written in Rust
#90When you all self-host this, you also do the following, right? - Create threat models that identify weaknesses in the design of your self-hosted setup. - Harden the OS with things like MAC, and harden the container with dropped privs, read-only root filesystem, and outbound network filtering. - Deploy an intrusion detection system to know if you've been compromised. - Perform all OS and app patching automatically, or…