Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Vaultwarden
  3. Use of Vaultwarden: do you feel comfortable hosting all your passwords remotely?

Use of Vaultwarden: do you feel comfortable hosting all your passwords remotely?

Scheduled Pinned Locked Moved Vaultwarden
11 Posts 6 Posters 5.0k Views 7 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P Offline
    P Offline
    p44
    translator
    wrote on last edited by
    #1

    Dear all,

    I've been saving passwords locally for years, using an app that only saves passwords to disk.

    However, with repeated web logins and varying passwords, I was thinking of starting a Vaultwarden instance on Cloudron to pass all the passwords. This would give several advantages, including immediate synchronization of all devices and integration with various apps.

    At this point, however, I wonder how you are using Vaultwarden: do you use it only for some passwords, or all passwords? Do you also use it for credit cards or other sensitive information?

    Do you feel safe to remotely put all passwords? Do you use any additional security measures regarding the Vaultwarden instance? (Eg IP filtering, ports, etc).

    Thanks so much for sharing your experience 🙏

    timconsidineT 1 Reply Last reply
    0
    • murgeroM Offline
      murgeroM Offline
      murgero
      App Dev
      wrote on last edited by
      #2

      As far as I know Vaultwarden is End to End Encrypted which means even if someone got access to the data, they can't read any of it (unless they guess the main password). I use my Vaultwarden with 2FA, a long master password, and only on devices where I trust my data being secure (encrypted & password protected PC and iPhone)

      Vaultwarden is safe. Cloudron's package is pretty good - if you wanted added security you can self-host outside of cloudron, IP filter like you mentioned, or even use it over a VPN so it's not directly accessible via internet.

      --
      https://urgero.org
      ~ Professional Nerd. Freelance Programmer. ~

      P 1 Reply Last reply
      6
      • P p44

        Dear all,

        I've been saving passwords locally for years, using an app that only saves passwords to disk.

        However, with repeated web logins and varying passwords, I was thinking of starting a Vaultwarden instance on Cloudron to pass all the passwords. This would give several advantages, including immediate synchronization of all devices and integration with various apps.

        At this point, however, I wonder how you are using Vaultwarden: do you use it only for some passwords, or all passwords? Do you also use it for credit cards or other sensitive information?

        Do you feel safe to remotely put all passwords? Do you use any additional security measures regarding the Vaultwarden instance? (Eg IP filtering, ports, etc).

        Thanks so much for sharing your experience 🙏

        timconsidineT Offline
        timconsidineT Offline
        timconsidine
        App Dev
        wrote on last edited by
        #3

        @p44 what @murgero said
        used it for years
        store all passwords in it AND bank cards
        love the syncing as I jump between devices
        have considered something like KeePass but syncing is a hassle
        useful for passwords needed by multiple users

        P 1 Reply Last reply
        6
        • murgeroM murgero

          As far as I know Vaultwarden is End to End Encrypted which means even if someone got access to the data, they can't read any of it (unless they guess the main password). I use my Vaultwarden with 2FA, a long master password, and only on devices where I trust my data being secure (encrypted & password protected PC and iPhone)

          Vaultwarden is safe. Cloudron's package is pretty good - if you wanted added security you can self-host outside of cloudron, IP filter like you mentioned, or even use it over a VPN so it's not directly accessible via internet.

          P Offline
          P Offline
          p44
          translator
          wrote on last edited by
          #4

          Thank's a lot for your feedback @murgero

          You will understand that it is a paradigm shift and therefore for those approaching these solutions it is better to have "real" feedback.

          About "use it over a VPN so it's not directly accessible via internet", can you give me a concrete example? There are several providers that offer intranet services – with no Public IP –, but I've never looked into it: are they these?

          Thank's again

          murgeroM 1 Reply Last reply
          0
          • timconsidineT timconsidine

            @p44 what @murgero said
            used it for years
            store all passwords in it AND bank cards
            love the syncing as I jump between devices
            have considered something like KeePass but syncing is a hassle
            useful for passwords needed by multiple users

            P Offline
            P Offline
            p44
            translator
            wrote on last edited by
            #5

            @timconsidine it looks great. Do you use any additional safety measures? (Eg. host on your local home server, or other else)

            Thank's a lot

            1 Reply Last reply
            0
            • P p44

              Thank's a lot for your feedback @murgero

              You will understand that it is a paradigm shift and therefore for those approaching these solutions it is better to have "real" feedback.

              About "use it over a VPN so it's not directly accessible via internet", can you give me a concrete example? There are several providers that offer intranet services – with no Public IP –, but I've never looked into it: are they these?

              Thank's again

              murgeroM Offline
              murgeroM Offline
              murgero
              App Dev
              wrote on last edited by
              #6

              @p44 You can setup Vaultwarden on a VM in your house (or for example, on a Raspberry Pi or similar SBC) and use a VPN on your router to access it externally.

              --
              https://urgero.org
              ~ Professional Nerd. Freelance Programmer. ~

              1 Reply Last reply
              2
              • KubernetesK Offline
                KubernetesK Offline
                Kubernetes
                App Dev
                wrote on last edited by
                #7

                @mugero if you do that, how do you solve the problem with valid SSL certificates?

                murgeroM 1 Reply Last reply
                0
                • KubernetesK Kubernetes

                  @mugero if you do that, how do you solve the problem with valid SSL certificates?

                  murgeroM Offline
                  murgeroM Offline
                  murgero
                  App Dev
                  wrote on last edited by
                  #8

                  Oh yeah I did not think of that - If you install vaultwarden with an SSL cert for a domain you own like vault.example.com, you can use internal DNS to make an A record internally to point to that.

                  Example:

                  vault IN A 192.168.1.123

                  • vault being the A record in your DNS server for the example.com zone. Pi Hole can do this easily and a lot of 3rd party routers support it as well.

                  --
                  https://urgero.org
                  ~ Professional Nerd. Freelance Programmer. ~

                  1 Reply Last reply
                  1
                  • marcusquinnM Offline
                    marcusquinnM Offline
                    marcusquinn
                    wrote on last edited by
                    #9

                    For me it's Vaultwarden for Business and Enpass for personal.

                    I prefer the Enpass UX with its widget shortcut, and lots of sync options that all work well.

                    Bitwarden/Vaultwarden I find better for business in sharing with specific groups of users, and instances per organisation. Plus it has the Emergency Access feature, which is an essential feature need for modern digital asset life and legacy.

                    BW/VW still doesn't do multi-account through the browser extension, hence the multi-app approach, but overall this setup has worked for me for years.

                    HTHs

                    Web Design https://www.evergreen.je
                    Development https://brandlight.org
                    Life https://marcusquinn.com

                    1 Reply Last reply
                    2
                    • ericdrgnE Offline
                      ericdrgnE Offline
                      ericdrgn
                      wrote on last edited by
                      #10

                      @p44 I think @murgero hit the perfect use case for you. I have also been using bitwarden for many years. Transitioned to vaultwarden a few years ago. I would recommend you just run it yourself on something like a raspberry pi or something then you get the "local" feel that you are used to. Not running it in someone else's cloud but with the "cloud" benefits. Then if you want to up security make it only accessible on your home network so you need a VPN to get to it when you are out and about.

                      Another thing to think about as a safety/reliability thing is that if whatever you are running it on goes down you still have access to your passwords on whatever device you've used it on. So your phone would be able to access everything still even if your Raspberry Pi goes down. And worst case if for whatever reason those things can never come back up you can export it from your phone and move on to something else with your file of passwords.

                      All in all it is worth giving it a shot. If you wanted to be really over the top about it you could have separate users (so separate master passwords) for each of your type of things if you are worried about it. Passwords under one user, addresses/personal info on another, and bank/cards on yet another.

                      1 Reply Last reply
                      3
                      • P Offline
                        P Offline
                        p44
                        translator
                        wrote on last edited by
                        #11

                        @ericdrgn Thanks for sharing your experience here with Vaultwarden. For me Raspberry Pi is little bit complex to understand due to lacking of knowledge, but I'll consider to use VPN and filter IP with Firewall.

                        1 Reply Last reply
                        0
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        • Login

                        • Don't have an account? Register

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • Bookmarks
                        • Search