Proton Pass. I stopped using Bitwarden for a different reason, the mobile app was too slow when not connected to internet. I can't accept such slowness, the company will definitely give justifications for this. But I don't care, let me see my passwords or notes for a website immediately. Proton Pass is better in this regard.
I am using Keepass XC + Keepass DX synchronized with Syncthing. There's really nothing to self-host, other than throwing Syncthing on a NAS so you can make sure you have at least one machine online at all times. But even that isn't critical, since both Keepass XC and Keepass DX have a "Merge" option if anything falls out of sync.
ive used keepassxc forever, switched to proton pass after the release, because i was managing my db in git and it was always a pain to keep in sync, but switched back a couple of weeks ago with exactly the same setup, syncthing and KeepassDx also works suprisingly well.
mostly i was missing power user features and especially ux for the browser plugin, namely you can't operate it fully with the keyboard, with keepassxc you can
As as self-hoster, I recommend vault warden. Supports 2fa, written in rust, works pretty well, is easy to backup, and you can use bitwarden's phone client.
I'm curious why other self hosters think it's a bad idea.
For me, vaultwarden's RSS is ~45 MB, with ~13MB of that being shared. I have it running as a secondary thing on a 512 MB machine and don't notice it's there. Is there a reason you presume it's a memory hog?
I'm surprised, actually. I expected at least an order of magnitude more. In my humble opinion, this is still a lot of memory -- probably an order of magnitude (or even two) more than what is realistically required for the task. But this is just my own philosophy, and I do realize that the days of careful memory utilization are long gone.
For me, RSS 35 MB, SHR 23 MB. The vaultwarden executable is 38 MB (typical Rust executable that links Rust code statically, and only dynamically links libssl.so and libc.so dynamically).
So probably its RSS usage is just mostly its own executable code?
I moved to the cloud for a simple reason: if I die tomorrow people who depend in the service are screwed. And this is an important service, like email or digital archives.
I don't see much reason not to self-host a properly built password manager like Vaultwarden or something similar? The clients keep a local encrypted copy of the vault, so the server only needs to be up for syncing. If it went down for a week, you probably wouldn't even notice unless you were saving new logins. And even if the server got hacked, everything on it is encrypted. Why do you think it should not be selfhosted?
Thanks, on these topics I feel like I’m fucking crazy for not wanting to self host.
If you believe that the technology works, that encryption is happening and that the decryption is only happening on your local machine then why in the fuck would I host this myself?
You need to believe that it does not work when they do it, but does work when you do it.
It should be something like, well, git (but likely not directly git): something that replicates easily, so that you'd have a remote copy accessed via internet ("hosted"), and local copies where you see fit.
Keepass people always in these topics with ”offline rules!! … now let me tell you how I use it with a copy on my phone and sync it with Dropbox and a backup on a git repo”
Proton Pass. I stopped using Bitwarden for a different reason, the mobile app was too slow when not connected to internet. I can't accept such slowness, the company will definitely give justifications for this. But I don't care, let me see my passwords or notes for a website immediately. Proton Pass is better in this regard.
Proton Pass cannot be self-hosted.
I am using Keepass XC + Keepass DX synchronized with Syncthing. There's really nothing to self-host, other than throwing Syncthing on a NAS so you can make sure you have at least one machine online at all times. But even that isn't critical, since both Keepass XC and Keepass DX have a "Merge" option if anything falls out of sync.
ive used keepassxc forever, switched to proton pass after the release, because i was managing my db in git and it was always a pain to keep in sync, but switched back a couple of weeks ago with exactly the same setup, syncthing and KeepassDx also works suprisingly well.
mostly i was missing power user features and especially ux for the browser plugin, namely you can't operate it fully with the keyboard, with keepassxc you can
As as self-hoster, I recommend vault warden. Supports 2fa, written in rust, works pretty well, is easy to backup, and you can use bitwarden's phone client.
I'm curious why other self hosters think it's a bad idea.
> and you can use bitwarden's phone client
What will you use when this stops working in the near future?
You use Keyguard (https://github.com/AChep/keyguard-app).
Presumably, it's a memory hog. What is your RAM usage?
I think the memory hog you're thinking of is the official Bitwarden self-hosted backend. Vaultwarden is pretty light on resources.
For me, vaultwarden's RSS is ~45 MB, with ~13MB of that being shared. I have it running as a secondary thing on a 512 MB machine and don't notice it's there. Is there a reason you presume it's a memory hog?
I'm surprised, actually. I expected at least an order of magnitude more. In my humble opinion, this is still a lot of memory -- probably an order of magnitude (or even two) more than what is realistically required for the task. But this is just my own philosophy, and I do realize that the days of careful memory utilization are long gone.
Thanks for sharing.
For me, RSS 35 MB, SHR 23 MB. The vaultwarden executable is 38 MB (typical Rust executable that links Rust code statically, and only dynamically links libssl.so and libc.so dynamically).
So probably its RSS usage is just mostly its own executable code?
I moved to the cloud for a simple reason: if I die tomorrow people who depend in the service are screwed. And this is an important service, like email or digital archives.
I'm confused, so you are self hosting it for other people?
Yes I was - for me and my family (and a few friends)
As a self-hoster, I don't think password managers should be self-hosted.
On the contrary. If there's one thing you should self-host is definetly password manager.
Why, you can of course self-host it, too, but the infrastructure should be entirely separate.
I don't see much reason not to self-host a properly built password manager like Vaultwarden or something similar? The clients keep a local encrypted copy of the vault, so the server only needs to be up for syncing. If it went down for a week, you probably wouldn't even notice unless you were saving new logins. And even if the server got hacked, everything on it is encrypted. Why do you think it should not be selfhosted?
you just listed all the reasons why you don't need to self host yourself
Thanks, on these topics I feel like I’m fucking crazy for not wanting to self host.
If you believe that the technology works, that encryption is happening and that the decryption is only happening on your local machine then why in the fuck would I host this myself?
You need to believe that it does not work when they do it, but does work when you do it.
I have not seen any evidence of that.
Can’t relate. If you’re worried about you’re own reliability to keep it online, just keep paper backups
What? Why not?
password managers should not involve hosting at all, use something file-local, keepass(xc) or alike
It should be something like, well, git (but likely not directly git): something that replicates easily, so that you'd have a remote copy accessed via internet ("hosted"), and local copies where you see fit.
pass can use git
https://www.passwordstore.org/
Keepass people always in these topics with ”offline rules!! … now let me tell you how I use it with a copy on my phone and sync it with Dropbox and a backup on a git repo”
But passwordstore.org can.
No reason to use anything more complicated.