I am looking into password managers, as number of my accounts are increasing. Currently I am weighing two options:

  • Host Vaultwarden on a VPS, or
  • Use the free bitwarden service.

I want to know how they are in practical aspects.

While I am fine self-hosting many services, password managers seem to be one of the most critical services that should not admit downtime. I surely cannot keep it up, as I need to update it time to time.

On the other hand, using bitwarden might require some level of trust. How much should I trust the company to use the free service? How do I know if my passwords would be safe, not being exposed to the wide net?

I want to gauge pros and cons, are there aspects I missed? How are your opinions on this? If you are self-hosting vaultwarden, how do you manage the downtime? Thanks in advance!

  • irmadlad@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 day ago

    I have used the free Bitwarden now for untold years. It not only houses passwords for personal applications, I use it to keep track of my business account passwords as well. The only problem I’ve had with Bitwarden is their recent UI retool which ended up causing a huge ruckus among the user base to the point where they gave an option to switch back.

    There is a certain level of trust for whatever option you choose. If you use Bitwarden free, then you have to trust that Bitwarden will keep your data is safe on their servers. If you self host, the onus of trust lies in you’re ability to secure your server, and to the extent that you trust your host as well. The latter option leaves me a bit queasy, so I do not selfhost my passwords in a selfhosted vault.

    Others may have more trust in their security skills than I do. LOL There’s just a lot of sensitive data I have housed within Bitwarden free. Selfhosting it would keep me up at nights.

    • Mike Wooskey@lemmy.thewooskeys.com
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      The only problem I’ve had with Bitwarden is their recent UI retool which ended up causing a huge ruckus among the user base to the point where they gave an option to switch back.

      I think the new UI is pretty terrible. I didn’t know until you mentioned it, irmadlad@lemmy.world, that there was an option to revert. I can’t find it in the settings - how does one revert to the prior UI?

      • irmadlad@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        Ok so, I got a popup asking to adjust the Appearance in Settings (Windows/Firefox edition) a little while ago, it seems like it was a month or so ago. I have all the settings there ticked. However, I think what a lot of people who knew, went to their official GitHub and downloaded the previous version’s xpi and sideloaded it. You would have to untick auto updates. That way you can just go back to clicking on the entry in Bitwarden and that autofills instead of having to click the $@#%$$$ ‘Fill’ button. The only caution would be if they upgraded the security components in the new version, meaning the last version may or may not have the same security components baked in.

        Yes, the new theme is absolute crap.