logoalt Hacker News

giancarlostoroyesterday at 5:22 PM7 repliesview on HN

Not my project but Vaultwarden is an open source (in Rust) alternative backend for Bitwarden. I believe its been around a while, and is still maintained.

https://github.com/dani-garcia/vaultwarden


Replies

duckmysickyesterday at 5:41 PM

Question for anyone self-hosting vaultwarden: how reliable is it and how do you harden it?

I'm thinking about running it in a container (Podman Quadlet with systemd) behind a VPN, with daily backups with borg. Anything I'm overlooking here?

show 6 replies
vovavilitoday at 3:04 AM

No matter where Bitwarden ends up, passwords are one of these few things I am very hesitant to self-host. The stakes are just too high, and my knowledge of security has too many unknown unknowns to take that risk.

afavouryesterday at 9:33 PM

Personally, I want to avoid the responsibility for hosting it myself. I'm happy to pay for that. But a reasonable amount. Today Bitwarden's price is fine for me, but I worry about what's coming.

danielmeskinyesterday at 9:51 PM

It is still maintained, but I believe the maintainer is employed by Bitwarden now, and is working on projects in addition to Vaultwarden.

pocksuppetyesterday at 6:28 PM

Is there an alternative frontend as well, or are you still locked in?

show 2 replies
SilverElfintoday at 1:00 AM

How do you trust that it will be kept maintained and secure?

WesolyKubeczekyesterday at 9:28 PM

Don't I have to rely on the OG frontend/GUI components, though? They are one automatic update away from bundling taking custom server address away with important security fixes, in a way that you are damned if you do and damned if you don't.

show 1 reply