Objective: Secure & private password management, prevent anyone from stealing your passwords.

Option 1: Store Keepass PW file in personal cloud service like OneDrive/GoogleDrive/etc , download file, use KeepassXC to Open

Option 2: Use ProtonPass or similar solution like Bitwarden

Option 3: Host a solution like Vaultwarden

Which would do you choose? Are there more options ? Assume strong masterpassword and strong technical skills

51 points
*

Keepass on phone, desktop and tablet. Sync serverless via Syncthing.

  • completely private
  • always available when needed
  • no dependency on services which may go away
  • all open source software
  • maximum security
permalink
report
reply
5 points

Yup. Same system here. I really like it.

permalink
report
parent
reply
3 points

Same here. Home server to which desktop and phone connect with OpenVPN.

permalink
report
parent
reply
2 points

Check out tailscale (or headscale)

It lets you connect those devices without necessarily sending all data through your home network when you are remote. (Though that is an option along with many other great features like ssh authentication)

It also uses WireGuard for the backend which is more secure and efficient than openvpn.

permalink
report
parent
reply
1 point

Thx! Will check out.

permalink
report
parent
reply
29 points
*

Keepass + syncthing.

Don’t let your vault go unencrypted through the cloud.

permalink
report
reply
5 points

Your vault is always encrypted very securly except when in RAM. There is no security concern with uploading it directly to the cloud.

permalink
report
parent
reply
1 point

It’s encrypted at rest with a passphrase. Syncthing encrypts it at transit with a random key.

There is a huge difference on the security of those.

permalink
report
parent
reply
3 points
*

Keepass allows you to use a passphrase in combination with a randomly generated keyfile. You only need to copy the keyfiles to your devices once (not via cloud services, obviously). Your actual database can then be synchronized via any cloud provider of your choice (hell, you could even upload it publicly for everyone to see) and it would still be secure.

permalink
report
parent
reply
24 points

I use option 1 with Syncthing for a distributed cloud solution

permalink
report
reply
3 points

Same, works like a charm!

permalink
report
parent
reply
1 point

Ditto, but with Resilio Sync.

permalink
report
parent
reply
24 points

I’m very happy with self-hosted Vaultwarden.

permalink
report
reply
20 points

Keepass fIle in my own nextcloud instances, synced to my phone so I can also use keepass2android. This way if something happens I at least have another copy of it, beyond my backup system.

permalink
report
reply
6 points

that’s actually exactly how I have my setup. I just use syncthing to keep everything dynamically backed up as I add passwords. my main login password is memorized and not written down anywhere so I think I’m good

permalink
report
parent
reply
2 points

I do the same, but synced to Dropbox from computers and phone.

I have the Proton password manager as well but not sure yet if I’ll do a full swap over.

permalink
report
parent
reply

Selfhosted

!selfhosted@lemmy.world

Create post

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Community stats

  • 5.1K

    Monthly active users

  • 3.6K

    Posts

  • 81K

    Comments