this post was submitted on 30 Apr 2025
58 points (95.3% liked)

Selfhosted

46479 readers
344 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

I am looking into password managers, as number of my accounts are increasing. Currently I am weighing two options:

  • Host Vaultwarden on a VPS, or
  • Use the free bitwarden service.

I want to know how they are in practical aspects.

While I am fine self-hosting many services, password managers seem to be one of the most critical services that should not admit downtime. I surely cannot keep it up, as I need to update it time to time.

On the other hand, using bitwarden might require some level of trust. How much should I trust the company to use the free service? How do I know if my passwords would be safe, not being exposed to the wide net?

I want to gauge pros and cons, are there aspects I missed? How are your opinions on this? If you are self-hosting vaultwarden, how do you manage the downtime? Thanks in advance!

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 2 points 1 day ago (1 children)

On the other hand, using bitwarden might require some level of trust. How much should I trust the company to use the free service?
How do I know if my passwords would be safe, not being exposed to the wide net?

Wouldn't these questions be as true of the VPS service that hosts Vaultwarden as of Bitwarden?
If my internet at home was better I would be selfhosting Vaultwarden and use a full vpn on my laptop/phone/tablet when leaving the house.
Now I'm using KeepassXC with my home pc as the true source and syncing copies of the database to my laptop and phone.

[–] [email protected] 2 points 1 day ago (1 children)

No, you don't need to trust the VPS provider. The VaultaWarden password storage is encrypted, and the master password is never transmitted to the server. The passwords are decrypted only locally on your device.

[–] [email protected] 2 points 1 day ago (1 children)

How does that differ from Bitwarden?

[–] [email protected] 2 points 1 day ago

To my knowledge it's not supposed to differ.

If you trust that the client (which is open source) is doing what it's supposed to do, security-wise I don't think there's a difference between self-hosting and using Bitwarden's service.