Skip to content

Comment on Bring Your Own Password Manager: Portable BitWarden on a Pi Zeroparent

Comments

It not so much that I do not trust the company today, it is that I do not trust them to not silently become adversarial in the future when the government comes knocking or if they get bought out, or whatever.

This is a bit of attack surface that all hosted cloud solutions share, and it is one that it has never been easier to eliminate.

all of these password managers (including bitwarden) encrypt your data end-to-end and nothing ever leaves your client in a plain state so regardless of who has the backend your data is never touchable. You always only ever need to trust the client, which you do here as well.

The client is made by the same people at the end of the day, so that is of little comfort.

Also, adversarial does not refer to just possibly breaking encryption, it also applies to daily continuity. I trust my ability to keep a small encrypted password database safe more than I trust some random companies to get bought or change their business model and suddenly I have to decide between a massive Flag Day or paying for something I did not have to before or having some kind of other unwelcome limitation placed on me.

I like controlling my own destiny, thank you very much.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.