Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Discuss
  3. Security and emergency strategy

Security and emergency strategy

Scheduled Pinned Locked Moved Discuss
4 Posts 4 Posters 488 Views 4 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E Offline
      E Offline
      ekevu123
      wrote on last edited by
      #1

      I am currently contemplating about a good security and emergency strategy and maybe others here have thought about this too, so maybe someone has some deeper thoughts about this:

      I am currently running two cloudron instances, "private" and "business". Only I have access to "business" but it gives me the opportunity to split apps between two instances in case one fails.

      However, I am generally willing and interested to host both passwords via vaultwarden and also 2-factor-authentication on Cloudron, possibly on separate instances. However, I need to secure my vaultwarden instance with 2FA, obviously.

      Now I am thinking, let's say worst case, both my laptop and my mobile phone get stolen. How do I get access now to my server and my data, considering that I cannot get access to my passwords or to confirm 2FA on a separate device?

      Probably I need some sort of lifeline, but I am not really sure how this would look like, considering both security and practicability.

      1 Reply Last reply
      2
      • necrevistonnezrN Offline
        necrevistonnezrN Offline
        necrevistonnezr
        wrote on last edited by
        #2

        I’m logged into Bitwarden at work and keep Bitwarden backups (via bitwarden-cli) there as well (password protected).

        1 Reply Last reply
        1
        • humptydumptyH Offline
          humptydumptyH Offline
          humptydumpty
          wrote on last edited by
          #3

          I use a Yubikey to secure my VW. I had trouble logging in on a new device this week and thought it was Yubikey related, turned out to be date/time issue on the local machine. VW backups up to an encrypted S3 bucket (at Backblaze). It's recommended to have at least two Yubikeys (one active, one backup). The only con is the initial investment cost as they're a bit pricey. I got mine during a Cloudflare promo.

          1 Reply Last reply
          0
          • fbartelsF Offline
            fbartelsF Offline
            fbartels
            App Dev
            wrote on last edited by fbartels
            #4

            Vaultwarden/Bitwarden actually has a few mechanisms for that.

            For the second factor you will get a "recovery code" that they ask you to store in a secure location. This is a letter and numbers string that can be used to override all configured second factors.

            If you have lost your master password, or you're simply no longer around to give it to someone else then Vaultwarden has a feature called "emergency access" where you can designate another user to gain access to your safe after a configurable wait time (so you could still object and prevent misuse). https://bitwarden.com/help/emergency-access/

            For me personally I have added my wife as my emergency contact, but since I know that she is not really a technical minded person I also have a backup yubikey at a secure location that has my master password stored as a static key and the above recovery key written down next to it.

            1 Reply Last reply
            4
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


              • Login

              • Don't have an account? Register

              • Login or register to search.
              • First post
                Last post
              0
              • Categories
              • Recent
              • Tags
              • Popular
              • Bookmarks
              • Search