44
A entry-based password manager?
(feddit.de)
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
much thanks to @gary_host_laptop for the logo design :)
Bitwarden if you want it in the cloud, Keepass if you want it on the device. I'd recommend PrivacyGuides.org's recommendations this time. They are rather careful as to what they recommend, still doesn't mean they always get it right.
You can also self-host Bitwarden using Vaultwarden.
You can also run Bitwarden proper locally but unless you really know how to run and maintain a web server I wouldn’t recommend this.
The official docker image uses a lot more resources than the vaultwarden container, but it allows significantly more than 100 users. If it’s just for yourself and your family I suggest just going with Vaultwarden.
Why would any private person need this?
You don’t. I meant to say that only large organizations need the official Bitwarden docker setup, but I did not communicate that clearly enough.
Yes, but that is still cloud based. Keepass is local
Well, only if you host it in the cloud. Not if you host it at home, for example.
I think what they meant is that one option uses network connectivity while the other functions entirely offline
No, I did mean cloud based. Thank you anyways
Which would make it hardly accessible outside of your home. Still not locally saved as well. And imho if he is not sure which password manager he should choose, he should maybe not self host just yet.
Bitwarden keeps a local encrypted copy of the database and only connects to the server for synchronisation.
I am aware. Why are you telling me this?
Maybe because it seems you claim self-hosting bit warden is cloud only and that self-hosted is not accessible outside the house?
Note: I do not recommending self-hosting bitwarden
Why not? I have my own instance running on my NAS and I love to have it self-hosted because this way I keep the passwords where I know nobody else can get them.
Because a password manager is critical and if you ask me I’d say no. If you have the know how and understand the risk you won’t be asking
Well, I work in the IT so I know some stuff about security in the digital world. But these systems (password managers in general) are built to be secure and not just tell every password they store without some security measures. Yes, I know there can be security holes, bugs and so on. But that's why these tools get thoroughly tested.
You always have to take risks in the world of computers. So what's the point? Being as secure as possible? Then better not even bother with password managers at all because they all can have security holes.
It's more about how much you trust a password manager and how much you trust yourself in how cautious you use it. The risk is always there.
Ok. I’m quite the IT person myself, and I can say I’d not recommend you running your own either.
That's fair. Everyone has a different opinion. But I think it's always better to self-host Bitwarden than using the cloud service because then your passwords are stored in a place where you have full control of. Afaik if you use the official Bitwarden vault your passwords are stored on some Amazon servers.
Self hosting is not for everyone. You need to understand backup, redundancy and recovery. That would be the main reason I don’t recommend self-hosting. Bitwardens self-hosting package are mature enough for me.
So it’s more about loosing all your passwords than someone breaking in to your vault
Actually it's not that big of a problem. All clients make a local copy of the server's database when they sync. So even when the server is unavailable you still keep your local copy on your client. Every client of Bitwarden offers the option to export your whole database. This means you could easily use that to import your exported database to any other instance.
The only "big problem" I see is to learn how to self-host. Most people are not tech-savvy so they don't know how to do it and don't even want to learn it.
Security is only one part of it. If you host a password manager yourself then things like availability, backups, disaster recovery and monitoring also become your responsibility. I'm hosting my own vaultwarden but there is only a very limited amount of people I would suggest self hosting a password manager to, because I know they have the knowledge to do it and understand the risks.
Since every client of Bitwarden makes a copy of the whole database on the server when it syncs, it's not like all your credentials are lost when the server gets unavailable. You can make an export of your database on that client and import it on another instance. This said you already have a built-in backup feature.
KeePassDX + Syncthing is the best solution.
Use that but its not about that topic. Its about storing unencrypted metadata (or usinh android Keystore for example) and having autofill work always even if the database is locked, and its quickly unlocked just for that entry
I don't think any password managers that don't have that feature currently are likely to implement this feature after the beating that LastPass took in the press about it:
LastPass breach is worse than you think because URLs were unencrypted
Maybe an app might be able to cache the metadata locally but I don't think it would be something people expect to be unprotected at this point.
I like this solution but it's not really entry level
What do you think about PrivacyTools.io? Are they on the same level as PrivacyGuides.org?
Taken straight from the privacytools.io subreddit description. This will tell you more.
Privacytools.io does seem to be quite outdated currently. There are other good sources out there however.