So I’m using bit warden self hosted and now I’m freaking out about the very real possibility of my passwords getting stolen or lost in a fire. Having passwords on my phone makes no sense.

We need some sort of distributed password manager safety net. Like I keep your passwords safe if you keep mine. But how can I trust you? Can you trust me?

  • BCsven@lemmy.ca
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    9
    ·
    edit-2
    1 day ago

    Just takes a brute force or 0 day vulnerability to get master password access, then they have everything.

    Something that seems secure never is online, like the 2017 Intel managetment vulnerability where remote attackers could access your computer by sending a null password, and access your keyboard and camera etc

    • hummingbird@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      1 day ago

      That’s why tools like keepass allow you to require more than just a password to decrypt.

      • BCsven@lemmy.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        Yes 2FA is good, but most people default to their phone being the tool, but your phone number can be ported by scammers, or is often the target of theft