• guy@piefed.social
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Would love to selfhost. However, I have no trust in my skills to secure my device in the same manner as a provider, and I do not wish my database to be compromised.

      • communism@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        I’ve had my VPS exposed to the internet for a while and never been pwned. No professional experience. Use SSH keys, not password authentication. Use FDE if physical access is in your threat model. Use a firewall to prevent connection on internal-only ports.

        Vaultwarden will store your passwords encrypted (obviously) so even if your database does get stolen, the attacker shouldn’t be able to read your passwords without your master password.

          • communism@lemmy.ml
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 months ago

            I know about Tailscale. I don’t use it because I want my VPS to be exposed to the internet; some of my services are supposed to be public. And those that aren’t, have their own authentication systems that are adequately secure for their purposes. I just don’t need Tailscale so I’ve not bothered with the setup.

        • guy@piefed.social
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          I have used KeePass, but Bitwarden is far more convenient when you have different devices

          • village604@adultswim.fan
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 months ago

            There’s a plugin that lets you store your database file in the cloud to solve this. Although I only used it for work because I use ProtonPass.

      • ComradeMiao@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        I never get this excuse except for ignorance (not being mean to you)—you can export your entire db as a text file then encrypt it if you wanted. Also, if your server goes offline its offline first on all devices

        • guy@piefed.social
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          I mean that I don’t have the necessary knowledge to make sure no one can get into my network and server, and having my entire life thus possibly vulnerable is too risky. Heck, I can’t even get Caddy to work properly.

          • AvocadoSandwich@eviltoast.org
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 months ago

            My view on this is that I also do not trust a company to properly secure something so if it’s going to be a hack job I might as well attempt it myself!

            • guy@piefed.social
              link
              fedilink
              English
              arrow-up
              0
              ·
              2 months ago

              Understandable! However I’d rather have the provider tell me that they were hacked and my data compromised than me being hacked and never finding out because I have no clue to look 😆

          • compostgoblin@piefed.blahaj.zone
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 months ago

            Right there with you! Selfhosting Vaultwarden would be cool, but I barely know what I’m doing. I trust Bitwarden’s security knowledge and abilities way more than my own.

      • XLE@piefed.social
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        Would you be okay with synchronizing only when you’re on your own Wi-Fi network? If that’s the case, you don’t have to try exposing anything to the Internet.

        You can also purchase a server online to install it on, but you’re going to get saddled with some kind of monthly fee there.

        • boonhet@sopuli.xyz
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          Plus you’ll still have to pay at least some attention to security if you get a server.