So I’m using bit warden self hosted and now I’m freaking out about the very real possibility of my passwords getting stolen or lost in a fire. Having passwords on my phone makes no sense.

We need some sort of distributed password manager safety net. Like I keep your passwords safe if you keep mine. But how can I trust you? Can you trust me?

  • MaggiWuerze@feddit.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 months ago

    Why would your passwords be stolen? If you have a good master password you could pass around thumb drives with the database and noone would be able to acces them, wince they are securely encrypted. Having them on your phone makes no difference as long as you don’t leave your phone and password manager app unlocked and out in the open (which both actively warn you against)

    • BCsven@lemmy.ca
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 months ago

      Use a yubikey hardware device, only the person with the hardware in hand and password can unlock your accounts

      • MDCCCLV@lemmy.ca
        link
        fedilink
        English
        arrow-up
        0
        ·
        3 months ago

        You don’t want that as the only option though, because you can definitely lose that and it’s not incredibly hard to break.

    • BCsven@lemmy.ca
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 months ago

      Just takes a brute force or 0 day vulnerability to get master password access, them they have everything.

      Something that seems secure never is online, like the 2017 Intel managetment vulnerability where remote attackers could access your computer by sending a null password, and access your keyboard and camera etc