#vaultwarden

12 posts · Last used 14d

Replying to

@karlauerbach@sfba.social @gemelen@mammut.moe

Karl, I've been evangelizing Ente Auth for a little more than two years now. It remains the ONLY fully cross-platform syncing FOSS solution available.

Mobile versions were available more than a year prior, but that didn't satisfy basic cross platform requirements. Back then there was Twilio (Authy), a proprietary solution that announced the sunset of their desktop version soon after the release of Authy desktop, and you could actually migrate your database by exporting it, interestingly enough.

Not surprisingly, they soon pushed and "update" to the desktop version which cripplewared it -presumably in anticipation of Ente Auth mass migrations.

There was a report of a flakey sync between KeepassDX and KeepassSX some time ago, yet I've never experienced issues.

Having said that, you should know that NextCloud itself reports issues with .kdbx syncing if you are stupid enough to install from the Google playstore, other sources like the git repo or F-Droid are not intentionally crippled in this way, by design, and virtue of their contract with Google.

I usually don't mention using password managers together with #MFA authenticators out of an abundance of concern for being flamed by fellow security professionals, but felt it prudent to mention here; the fact is that people will do so anyway because it's convenient.

I do separate, as a best practice, the use of my passwords and my only authenticator, Ente Auth, yet keep backup copies of my #TOTP MFA keys in a .kdbx file (in the comments - not active). I believe that's advisable to keep them in a separate vault and avoids the issue of not being able to migrate (i.e., Twillio's Authy lockdown cripple).

Sure, one could break and reinitialize their MFA on each of their myriad accounts but that's indeed a Major Pain (that's a TV pun).

So for me, I'm a staunch supporter of Pass/OpenKeyChain (sync via Git) & #Ente_Auth on all of my platforms: Android, FreeBSD, Linux (I no longer use Windows) - Sync via my self-hosted Ente Auth server; and a .kdbx client appropriate for my OS, syncing that via #NextCloud. You can use #Peergoss if you prefer.

For everyone else, I usually recommend they go with a combination of Ente Auth and [VaultWarden}(https://vaultwarden.com)

That keeps everything absolutely self-hosted and 💯% #FOSS.

If you're not a stickler for self-hosting those very same solutions are still available to you, except that for #VaultWarden you need to go [HERE](https ://VaultWarden.org).

I don't do Apple, but I am aware of .kdbx clients for that particular manufacturers products and the iPhone was, I believe, the first platform that Ente Auth was released for.

Beyond that I just urge everyone to stick with 100% FOSS solutions whenever feasible (i.e., Use VaultWarden instead of BitWarden) and make sure to contribute whatever they feel is fair to the developer teams that make all of this possible.

I hope that helps!

#tallship #Privacy #fdroid #kdbx #opensource #selfhosting

⛵

0
0
0
0
New #blog post: Migrating from #1Password to #VaultWarden The recent news about @1password@1password.social funding DHH hasn't sat well with me. By luck, my annual renewal was only a few weeks away too. So, I decided to change #passwordmanager This post talks about how to set Vaultwarden up as well as how to migrate credentials across (the process is the same for #bitwarden) https://www.bentasker.co.uk/posts/blog/general/migrating-from-1password-to-vaultwarden.html
51
7
34
2
If you're wanting to self-host a password manager you might want to check out Vaultwarden. It's a free open source alternative to 1Password, Bitwarden etc. It is compatible with Bitwarden clients but is a totally separate project. More info at: 🌱 https://github.com/dani-garcia/vaultwarden It's available to self-host through @yunohost@toot.aquilenet.fr at https://apps.yunohost.org/app/vaultwarden or by installing manually using the instructions at https://github.com/dani-garcia/vaultwarden#usage #SelfHosting #Vaultwarden #1Password #Bitwarden #Alternatives #FOSS
36
7
34
1
Hello Mastodon! 👋 #Introduction I'm Rado, owner of RL Advice. I help people or companies with open source-solutions such as 🐧 Migrating old or unsupported Windows PCs to Linux (#Ubuntu) 🏠 Self-hosting solutions like #UbuntuServer, #Nextcloud, #Vaultwarden, and #HomeAssistant Looking forward to connecting with fellow tech enthusiasts, developers, and open-source advocates here! Based in 🇳🇱 | posts in 🇬🇧 & 🇳🇱 #FOSS #SelfHosting #Linux #Privacy #OpenSource #TechAdvice
0
0
1
0
Replying to
semua kena! termasuk add ons Helium gw, semua update ke 2026.7.0 terpaksa uninstall dan install manual versi 2026.6.1 gw cek di freshport versi 1.37.0 sudah nongol, jadi nunggu waktu saja bakalan landing ke repo setelah itu bisa pakai versi desktop dan browser dengan lancar. ga sabar nungguin ChiPass! #freebsd #vaultwarden #bitwarden #chipass
0
1
0
0
Bitwarden shipped a client update that requires Vaultwarden 1.37.0 — which also happens to close 8 medium-severity security advisories that don't even have CVEs assigned yet. Nixpkgs hasn't caught up. Stable currently points to 1.36.0. So I spent some time (unplanned) patching my server before the apps auto updated and relegated me to server website only. https://blog.ppb1701.com/when-bitwarden-breaks-vaultwarden-before-nixpkgs-catches-up-part-18-of-building-a-resilient-home #blog #nixos #homeserver #selfhosting #vaultwarden #security
0
0
5
0

Achtung! Wichtig! Nicht bei vaultwarden.com registrieren! Bitte boosten!

Begründung:

Manche wissen vielleicht, dass ich vaultwarden.net hoste und auch in Kontakt und guter Beziehung zu vaultwarden.uk bin und wir uns auch gegenseitig unterstützen. Ich habe nichts gegen andere öffentliche Vaultwarden-Instanzen, nein ich finde es sogar gut je mehr Leute diesen Service anbieten. Das verteilt den Druck keine Downtimes zu produzieren und jeder kann sich dort niederlassen wo man dem Admin vertraut. Ich mach den Service ja hauptsächlich für non-techies die sich nicht mal eben ein Vaultwarden aufsetzen können und empfehle auch allen die das können oder wollen es sich selbst zu hosten. Kommenm wir nun zu vaultwarden.com. Warum nicht bei vaultwarden.com registrieren?

  1. Die website ist extrem jung. Gut wir haben alle mal angefangen. aber sie haben auf reddit gepostet und anscheinend nicht mit ihren Server-Kenntnissen geglänzt und den Post dann wieder gelöscht. Das lässt sich aber nur durch den Kommentar nachvollziehen.
  2. Die Website versucht aktiv als offizielle Website von Vaultwarden zu wirken, im gegensatz zu den Websites die vaultwarden.uk und ich hosten wo wir explizit darauf hinweisen, dass wir keine offiziellen vaultwarden Server sind und nur community projekte und auch versuchen im Auftritt nicht offiziell auszusehen. Das spiegelt sich nicht nur im wording wieder, sondern auch in der allgemeinen aufmachung. Auch wenn ich zugeben muss, dass die website hübscher ist als unsere. Aber mein Partner bei vaultwarden.uk arbeitet schon an einer neuen.
  3. Ich habe eine Email bekommen. Von vaultwarden.com. Sie wollen meine Userbase kaufen und auch meine Domain. Ehm mal ganz davon unabhängig, dass ich mir nicht sicher bin ob das überhaupt geht die daten von einer anderen Instanz einzuspielen, ist das extrem fishy und ich würde sowas natürlich nie tun. Auch aus dem Grund, dass ich den Service ja hoste weil ich die Kontrolle über meine Passwörter haben möchte aber es halt kaum mehraufwand ist den Service öffentlich zu betreiben wenn man jetzt nicht betrachtet, dass halt noch mehr Leute betroffen sind, wenn es nicht online ist. Ich habe jetzt mal aus Neugierde gefragt wie viel sie mir den zahlen würden.

Viel mehr Anhaltspunkte habe ich noch nicht aber ich habe auch mit dem Maintainer von vaultwarden.uk geschrieben und er meinte auch das sei ziemlich fishy alles.

Deshalb die Empfehlung von uns beiden. Registriert euch nicht bei vaultwarden.com!

​:boost_animated:​

#vaultwarden #hosting #bitwarden

140
7
243
0
Da ich gestern auch auf #SelfHosting angesprochen wurde... Nicht jeder hat die Möglichkeit oder das Interesse an SelfHosting. Aber wenn man es "kann" und sich ein wenig unabhängiger machen möchte - es gibt viele Möglichkeiten! Kleines persönliches Beispiel von mir: Angefangen hatte ich mit einem ausgedienten Raspberry, auf der ich Nextcloud installierte. Mittlerweile - mit mehreren Zwischenstationen - steht bei mir daheim mit allen selbstgehosteten Diensten ein ausgedienter, gebrauchter Lenovo ThinkCentre, den ich letztes Jahr geschenkt bekommen hatte. Da wir noch eine dazu passende CPU hatten, bekam der ThinkCentre ein feines Upgrade auf einen i7. 😁 Darauf installiert ist Debian in der Minimal-Konfiguration und - weil ich es mir einfach machen wollte - Docker. Darüber habe ich u.a. installiert: #BookStack (dient mir als mein persönliches Server-Verwaltungs-Logbuch)#Glance (Dashboard)#Heimdall (Dashboard)#Homarr (Dashboard)#Immich (Foto-Verwaltung und Backup, ähnlich Google Photos)#Jellyfin (Media Center)#Joplin (Umfangreiche Notizen-App)#Linkwarden (Bookmark-Verwaltung)#Mealie (Rezepte-Verwaltung)#OpenCloud (Backup-Cloud für Dateien aller Art, inkl. selbsgehosteten Office, Markdown und mehr)#Organizr (Dashboard)#SearXNG (Umfangreiche Suchmaschine)#Vaultwarden (Passwort-Verwaltung)#WordPress (Blogging-Software) Zusätzlich werkelt darauf auch noch eine #Nextcloud, allerdings nicht über Docker installiert. Ein #Minecraft-Server ist darauf ebenfalls installiert sowie ein #Emulator zum zocken. 😎 Das alles nutze ich mal mehr, mal weniger. Gerade bezüglich der Suchmaschine SearXNG war ich erst echt skeptisch. Aber ich nutze diese nun schon über ein Jahr und bin sehr, sehr zufrieden damit. Die Ergebnisse sind nicht - wie bei Google z.B. - voll mit zusammengefassten KI-Ergebnissen, die kein Mensch sehen möchte, sondern mit "echten" Ergebnissen. Meine Fotos landen allesamt bei Immich - eine wundervolle Software, die ich gerne nutze. Auch die OpenCloud, deren Anfänge ich miterleben durfte, hat sich sehr etabliert und ist für meine gesamten Daten absolute Nummer 1 bei mir, da sie schnell und zügig lädt und Collabora Online als #selbstgehostete #Office-Lösung integriert hat. Auch Bookstack finde ich super nützlich. Wenn ich Änderungen an der Konfiguration der Server vornehme, trage ich diese Änderungen mit Datum und Uhrzeit hier ein und kann später so nachsehen, was ich wann geändert habe. Ebenso habe ich mir in Bookstack Anleitungen hinterlegt, tägliche Checks, die ich auf den Servern durchführe und weitere Dinge, die ich einfach nur schnell per Copy & Paste ins Terminal einfügen kann. Am Lenovo ThinkCentre angeschlossen habe ich 3 2,5 Zoll HDDs. Thema Sicherheit: Das alles ist nur für mich in meinem lokalen Netzwerk erreichbar. Ausschließlich. Zusätzlich ist der Login abgesichert mittels #Yubikey (ein kleiner, physischer Hardware-Sicherheitsschlüssel). Trotz all dieser Maßnahmen bin ich nach wie vor noch an einige Dinge gebunden. So nutze ich z.B. Proton. Auch habe ich meine persönliche Daten an mehreren Stellen als Backup hinterlegt, auch online, nicht nur bei mir selbstgehostet daheim. Wer technisches Interesse und Verständnis hat, kann also auch diesen Schritt gehen und ein wenig unabhängiger werden, um von Google und Co. wegzukommen. Und wer noch einen Schritt weitergehen möchte, kann natürlich auch seine ganz eigenes Mastodon, Friendica o.ä. auf seinem Heimserver installieren - auch das ist gut umsetzbar. So kann man sich noch einen Schritt unabhängiger machen. Die Möglichkeiten, digital unabhängiger zu werden sind groß - man muss es nur umsetzen! 😉 #UnfollowBigTech, #DIDit, #DUTgemacht, #DIDAY, #UnplugBigTech
0
11
0
0
Replying to
@jaybird110127@dragonscave.space Having a message allowing someone to guess the server version would allow a downgrade style attack where an attacker would purposely try to force the server to switch to an older version of the protocol which may be affected by a flaw. Having a non descript error message will make users look for assistance from the server administrator which may at a point understand that he needs to upgrade it's instance. #vaultwarden and #bitwarden are docker based both, having a once a week script to auto update your container could help prevent such misdemeanor.
0
0
1
0
You've seen all posts