For the same reason why I don't throw my apartment keys into the local train stations safebox.
For the same reason why I don't throw my apartment keys into the local train stations safebox.
Remember, these organizations fix the issues weeks, sometimes months, before they release the statement.
If you use open-source and a critical bug is found, you'll get a patch with a press release, while all other large services fixed that already. For average Jane or Joe, the risk-benefit ratio favors services against self-hosted solutions.
They can't and they won't because these are different threat models with vastly different incentives.
Which then somehow manages to exfiltrate and decrypt data that is still encrypted with a public key, the private key to which is not stored on that system, and itself encrypted symetrically?
Yeah, that doesn't sound like a "random attack" to me, that sounds like a subplot in a Keanu Reeves Movie...
There is probably a half way decent chance that the vast majority of participants here, in singular, that would be economically gold mines for compromise.
While probably true most of the time. It does give you a false sense of security, which makes you a very easy and potentially profitable catch. If you fail to update and a scripted bot catches you, the actor notified will certainly see what's in there.
And if anything you're more likely never to find out. Which means they can just come after a few months later. Maybe they stole your first CC and then your second CC. I think there is possibilities there that make sense.
Why would you assume the self-hosted alternative even has a server to be breached? If this is the same Okta breach from this week it was a human support channel that was breached. There's nobody like that in front of my setup, and no server or open ports.
> And people keep asking me why I use a self-hosted, self synced, password manager instead of using one of those super-easy, super-helpful online services to do it for me.
The security of self-hosting and keeping the backups up to date (trivial to automate for computer-literate users) is not false compared to getting pwned by customer service with enough access to be dangerous. You're making it sound way more difficult than it is.
So simply in terms of attack surface, exposure and discoverability, doing that is a REALLY tall order. Many animals on this world survive not because they are huge and strong, but because they are tiny, fast and next to invisible.
Economics play a huge role in attacking systems. Targeted attacks are time consuming, costly, and if the end result is one guys passwords, usually not worth it. People carrying out such attacks want to use a dragnet, not a fishing rope.
> If you use open-source and a critical bug is found
...then many many many large organisations have the same problems as I do, only while being a lot more exposed and visible than me. Because the software I use relies on the same standardized, battle tested, vetted and re-vetted for years technologies as many commercial products.
So is my password store.
> I HIGHLY doubt that you can keep your homeserver more secure than 1password can its servers.
I also highly doubt that my trousers pockets are harder than the 1.5cm thick hardened-steel-doors of the storage lockers at the local train station, or that my pyhsical constitution is superior to those of the trained security guards they have there.
And yet, guess where the keys to my apartment are kept. Hint: Not at the train station.
I'd recommend only exposing bitwarden on an intranet, or controlling access with a strict firewall, but the setup guide makes no such suggestion. https://bitwarden.com/help/install-on-premise-linux/
Are they? How does the vault password recovery work, then?
1Password themselves don't hold these keys.
My point is not so much to throw 1Password under the bus (I'm a happy user), but I'd be curious to see a description of how this works.
And so mediocre protection of irrelevant target can be far more effective than good protection of juicy target
Additionally I can even use it in scripts.
There's no server breach, no web extension exploit, no server errors making me lose me all my passwords, it just works.
And I am, same as I am worried everyday about losing the keys to my apartment. I am speaking as a person who once only got them back by sheer luck (and a young mans honesty), after they fell out of a hole in my trousers pocket.
However, I would be even more nervous if the security of these keys were up to someone other than me. For example a random employee of a big company, whos access to the system I have no say in, who I never met, and whos actions I can neither see nor regulate.
Bottom line is: I prefer worrying about myself failing, than someone else. Because I can do something about the former.
I prefer a qualified pilot worrying about keeping the Boeing I'm traveling in airborne, than myself.
But indeed, I rather worry myself about my house keys than someone else.
For me, keeping extremely sensitive data always available and securely secret forever is more like flying an airplane than not losing my house keys.
Yeah...about that...
https://password-managers.bestreviews.net/faq/which-password...
And while I am certainly not qualified to fly an aircraft, I do feel that I am quite qualified when it comes to software engineering and systems administration.
So yeah, this is something I rather do myself.
The data files are encrypted with keys of the CM main servers and other admins, GIt has history in case something that should not get removed got removed and if you want you can also force that the data will always be signed with certain keys on server side git hooks if you want to have more accountability than just git logs.
With little config even git diff/git log work showing unencrypted (if you have right key) content.