• pulsewidth@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    arrow-down
    8
    ·
    14 hours ago

    The person you’re replying to already gave you one: it’s free.

    Second: its not a prime target for attack like centralized, hosted webservices are. See: LastPass being cracked and people’s login data stolen… Twice.

    Yes, it is cryptographically superior to LastPass, and attempts to design around their flaws - but the threat still exists because its a very tasty target on the open internet for cybercrime.

    My little Keepass DB synched over personal VPN by Syncthing? Much harder to find a vector for attack. But it does require more moving parts and maintenance.

    Each have their pros and cons.

    • chris@l.roofo.cc
      link
      fedilink
      English
      arrow-up
      16
      arrow-down
      1
      ·
      13 hours ago

      I think you misread. Lastweakness was talking about Vaultwarden which is a 100% FOSS reimplementation of bitwarden that you self host.

    • halcyoncmdr@piefed.social
      link
      fedilink
      English
      arrow-up
      5
      ·
      13 hours ago

      Vaultwarden, self-hosted is free as well. And since it’s not using the Bitwarden infrastructure, you’re only as exposed as your own network anyway.

      But you can still use all the standard Bitwarden apps and extensions on any device, you just need to point it at your server. Easy to set up for friends and family as well. No need to try and teach them about VPNs, setting up syncthing, etc.