On the other hand, Bitwarden lets you self-host a complete server that handles everything. If you want something less resources intensive you can take a look at Vaultwarden which is a re-implementation of the server in Rust instead of C#. The main advantage is that it uses MySQL or Postgres instead of the heavy MS SQL Server.
I personally don't.
Sure I have a password manager on my phone, but it only gets a small subset of my passwords anyway. Similar any password I add on my phone is very likely to be somewhat irrelevant mostly throwaway.
{Bit,Vault}warden} both now support emergency access which will be useful if it's ever needed
Apart from that bitwarden is just wayyy easier, you simply tell the (official) app the URL to your vault and it's basically good to go. You don't have to worry about synchronization one bit. The app is also fairly nice and has all the features you need. Bitwarden also does the browser integration well, unlike keepass where it's a major pia.
Isn't the self-host server (Vaultwarden) also 3rd party?
You are implying that this is a problem, but KeePass actually explicitly supports this and merges your changes. I've been using KeePass like this for many years and never had a problem editing the database from multiple devices.
There's an alternative implementation of the server API called Vaultwarden that works nicely with all the frontends but is unofficial.
If Keepass works for you, you're likely not gaining much from switching. They're both just password managers at heart.
bitwarden:
container_name: bitwarden
networks:
- bitwarden
image: vaultwarden/server:latest
restart: always
environment:
SIGNUPS_ALLOWED: "false" # Set to true when making your accounts
DOMAIN: "https://bw.domain.nl"
WEBSOCKET_ENABLED: "true"
# ADMIN_TOKEN: "SomeTokenForResetPurposes"
volumes:
- ./bw-data:/data
labels:
- traefik.enable=true
- traefik.http.middlewares.redirect-https.redirectScheme.scheme=https
- traefik.http.middlewares.redirect-https.redirectScheme.permanent=true
- traefik.http.routers.bitwarden-ui-https.rule=Host(`bw.domain.nl`)
- traefik.http.routers.bitwarden-ui-https.entrypoints=websecure
- traefik.http.routers.bitwarden-ui-https.tls=true
- traefik.http.routers.bitwarden-ui-https.service=bitwarden-ui
- traefik.http.routers.bitwarden-ui-http.rule=Host(`bw.domain.nl`)
- traefik.http.routers.bitwarden-ui-http.entrypoints=web
- traefik.http.routers.bitwarden-ui-http.middlewares=redirect-https
- traefik.http.routers.bitwarden-ui-http.service=bitwarden-ui
- traefik.http.services.bitwarden-ui.loadbalancer.server.port=80
- traefik.http.routers.bitwarden-websocket-https.rule=Host(`bw.domain.nl`) && Path(`/notifications/hub`)
- traefik.http.routers.bitwarden-websocket-https.entrypoints=websecure
- traefik.http.routers.bitwarden-websocket-https.tls=true
- traefik.http.routers.bitwarden-websocket-https.service=bitwarden-websocket
- traefik.http.routers.bitwarden-websocket-http.rule=Host(`bw.domain.nl`) && Path(`/notifications/hub`)
- traefik.http.routers.bitwarden-websocket-http.entrypoints=web
- traefik.http.routers.bitwarden-websocket-http.middlewares=redirect-https
- traefik.http.routers.bitwarden-websocket-http.service=bitwarden-websocket
- traefik.http.services.bitwarden-websocket.loadbalancer.server.port=3012
- traefik.http.routers.bitwarden-ui-https.tls.certresolver=mytlschallengeI was using KeepassXC, but I liked the the TOTP backup/share with partner functionality and iOS strongbox app.
I attempted to set her up with her own database but it's difficult to manage accounts that we both share in two separate databases.
Most people do not add passwords often, so that works just fine.
You also can have multiple database file, one for the common shared password which is always read only synced from a single source. And one for local passwords which are not yet, or should not, go into the shared database.
I had that problem on iOS, and it disappeared since I moved to Android. There is probably an issue in what they are (not) allowed to do in background on iOS.
Could it be that you weren't using it correctly? KeePass database files aren't supposed to remain open (for security of course) and it has quite a number of options to automatically close it after certain amount of time or when the window isn't focus, computer is locked, etc. This would trigger a sync with the (NC) server and assuming that all your clients follow the same usage pattern and close the DB after a small window of time, there shouldn't be any conflict.
> NextCloud to be always up of course, also self-hosted
You could use NextCloud's own hosting. But then Bitwarden's server needs to always be up too, and optionally self-hosted.
> Bitwarden just works
A low bar to recommend a password manager, don't you think so?
For me BW has always just worked, meanwhile I have several KeePassXC dbs with a date in their name because of conflicts. Which arguably is because of NextCloud issues, which are my own "fault" (issues include, on work PC file sync services are not allowed, on Server somehow NC disconnects after every container update, since it is "headless" I often notice this very late, the shitty state of NC client packaging on Ubuntu will let you install very old clients that may stop syncing, you need to be aware of this... etc). Perhaps KeePass(XC) just works if you outsource syncing, but then still, it is easier to have sync conflicts than with BW.
And then there is the ability to share PWs with relatives with a BW account on the same server, KeePass does not have this concept as far as I am aware.
KeepassXC on the desktop 'Keepass2Android Offline' on android Keep my database in dropbox. Keep things synced on Android via Dropsync.
I know it's not a self-hosted solution, but I think dropbox as a sync solution in this particular case is a pretty good solution for personal use.