586
submitted 1 month ago by [email protected] to c/[email protected]
you are viewing a single comment's thread
view the rest of the comments
[-] [email protected] 34 points 1 month ago
[-] [email protected] 17 points 1 month ago

Exactly! Self hosted FTW. Chances of a data breach.... Typically pretty minor if you are smart.

[-] [email protected] 19 points 1 month ago

Chances of losing the data is higher with selfhosting too. Unless you’re doing some sort of multizone replication, or course.

[-] [email protected] 10 points 1 month ago

I use syncthing so there's a copy of my password database on each of my devices.

[-] [email protected] 4 points 1 month ago

I would rather lose my passwords than have my password database be accessed by someone else. Most websites have a "forgot password" function, and for passwords that don't have that (e.g. to decrypt my hard drive or log into my computer) I've memorised the passphrase and always type it manually anyway. And for passwords where neither applies, it's probably not a huge loss anyway if I've not prepared for the possibility of losing my password db for that particular password.

[-] [email protected] 4 points 1 month ago

Yeah. Daily and weekly cloud backups solve that for myself for sure.

[-] [email protected] 3 points 1 month ago

I am hosting on Home Assistant which itself gets a backup to my Google drive and my personal machine. So there are two backups, as long as HA doesn't create a corrupted backup 3 weeks in a row I am good.

[-] [email protected] 3 points 1 month ago

Borg backup to borgbase is not very expensive and borg will encrypt the data plus the vault is also encrypted

[-] [email protected] 2 points 1 month ago

As long as you're still signed into BW from any of your devices, you can always export the vault from there.

(But yes, actual backups are always a plus)

[-] [email protected] 2 points 1 month ago

Keep vaultwarden behind wireguard for local only access then also use https certs and good master password. Very secure like this

[-] [email protected] 1 points 1 month ago

Why https if the traffic is already encrypted by the vpn?

[-] [email protected] 2 points 1 month ago

Security in layers.

All your services should be using https. Vaultwarden in particular won't even run without https unless you bypass a bunch of security measures.

This is how to setup local only and external https, I highly recommend this as a baseline setup for every homelab. It allows you to choose how much security you want on a per app basis and makes adding new apps trivially easy.

https://youtu.be/liV3c9m_OX8?si=TSWXoN_8SJDpAHaW

[-] [email protected] 7 points 1 month ago

+1 for a self-hosted Vaultwarden instance. If you’re technically capable and have extra hardware laying around this is the best way to go.

[-] [email protected] 4 points 1 month ago

Although a backup is still required or you are gambling on hardware outliving your need for your data.

[-] [email protected] 3 points 1 month ago

100%. Make sure to follow the 3-2-1 backup rule with all things you do.

[-] [email protected] 3 points 1 month ago

Anyone with the knowledge to self host will quickly discover 3-2-1. If they choose to follow it, that's on them but data loss won't be from ignorance

this post was submitted on 28 Jul 2024
586 points (98.5% liked)

Technology

58133 readers
4381 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS