• pulsewidth@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    arrow-down
    8
    ·
    edit-2
    4 hours ago

    (Edit - I misread as Bitwarden and went off on the wrong tangent. Vaultwarden is not centralized, and it’s FOSS - my bad.)

    The person you’re replying to already gave you one: it’s free.

    Second: its not a prime target for attack like centralized, hosted webservices are. See: LastPass being cracked and people’s login data stolen… Twice.

    Yes, it is cryptographically superior to LastPass, and attempts to design around their flaws - but the threat still exists because its a very tasty target on the open internet for cybercrime.

    My little Keepass DB synched over personal VPN by Syncthing? Much harder to find a vector for attack. But it does require more moving parts and maintenance.

    Each have their pros and cons.

    • chris@l.roofo.cc
      link
      fedilink
      English
      arrow-up
      17
      arrow-down
      1
      ·
      1 day ago

      I think you misread. Lastweakness was talking about Vaultwarden which is a 100% FOSS reimplementation of bitwarden that you self host.

    • halcyoncmdr@piefed.social
      link
      fedilink
      English
      arrow-up
      6
      ·
      1 day ago

      Vaultwarden, self-hosted is free as well. And since it’s not using the Bitwarden infrastructure, you’re only as exposed as your own network anyway.

      But you can still use all the standard Bitwarden apps and extensions on any device, you just need to point it at your server. Easy to set up for friends and family as well. No need to try and teach them about VPNs, setting up syncthing, etc.

      • pulsewidth@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        15 hours ago

        Thanks, I appreciate the clarification. I misread as Bitwarden.

        Vaultwarden sounds like it resolves any concerns had about Bitwarden.