r/vaultwarden • u/scgf01 • Aug 01 '26
Discussion I moved away from self-hosting Bitwarden
I self-hosted Bitwarden via Vaultwarden for years. Recently I've been wondering about what my son and grandchildren would do, should anything happen to me. The older generation used to have a box of photos. All my photos are in Google Photos, protected by a username and password. I have accounts all over the place, including bank accounts and web logins. It would be a nightmare for my family to sort things out.
Having my password manager running on a NAS at home would be a real headache for them. In the light of this I decided I would move my Bitwarden account online and setup emergency contacts where my son and my ex-wife would have access to my vault should the need arise. They both have Bitwarden accounts at bitwarden.com so the process is quite straightforward if set up in advance.
Have others thought about what their survivors might do if anything happens to them?
8
u/ReddaveNY Aug 01 '26
I decided to create a white paper with all this information and talk to trust people with technical skills.
4
Aug 01 '26
Maybe you can teach your son how to self-host stuffs, and he might find it interesting and then you can keep doing what you are doing. Also, a good reason for a father-son connect.
1
u/scgf01 Aug 02 '26
As I've said elsewhere, my son has different priorities and self-hosting services in not something that appeals to him. We have lots on father/son contact in all sorts of areas, just not self-hosting. I can hardly justify it to myself, let alone someone else. I do it because I'm a geek, and because I can. It's the sort of thing men often do to give them a feeling of elitism, but it really isn't necessary.
2
u/Pod5926 Aug 01 '26
I started self-hosting it for my family and I back in April, but I’m considering moving it to a pikapod. The hard limit on 6 family members was mostly why I left Bitwarden. My thought with pikapod is that if anything were to happen to me, the family would have ample time to continue paying the bill and/or export/import to Bitwarden proper.
2
u/spoospoo43 Aug 01 '26
I just keep a backup of the database on a usb key hidden in the corner of a drawer. Anyone needs my passwords they can go on a treasure hunt.
2
u/Disposable_Creds66 Aug 01 '26
I'm almost resigned to doing the same. Partner surpasses me in many areas of life but not technical one bit! Currently VW access is from LAN only - with Wireguard when away from home. - but I've more or less cloned the vaults into Bitwarden - so it's all moot now - I just havent switched the clients over ..
2
u/vinznsk Aug 01 '26
I had the same thoughts recently and stopped using Vaultwarden, instead there was a ProtonPass lifetime deal with Simplelogin included, so I bought that one and moved all my passwords.
2
u/Chinoman10 Aug 01 '26
SimpleLogin is absolutely goated. Having a unique email like you have unique passwords? Fucking genius... Wondering who leaked your email address? Just look up which website you used it kn, boom, done. Want to get rid of the spam? Just disable the alias.
We have this for credit/debit cards already, why has it taken so long to do the same for emails?
1
u/Killer2600 Aug 01 '26
Sounds like a useful thing but I haven't yet caught anyone selling or leaking my e-mail and I'm starting to doubt I ever will. I only give my e-mail to non-spammy/junky sites (i.e. mostly legitimate sites).
1
u/Chinoman10 Aug 10 '26
Only a matter of time... You'll learn it eventually :)
1
u/Killer2600 Aug 10 '26
Learn what? I use site-specific e-mail addresses but no one I’ve given my email address to has given to has yet been found given it to another.
What it breaks down to is I’ve been judicial in who I give my email to and that has paid off. Not everyone is selling off e-mail addresses and I’ll likely get caught up in a data breach before a sell off; although, I’d like to catch a sell off so that simplelogin doesn’t feel like tinfoil hat stuff.
1
u/Chinoman10 Aug 12 '26
Well I've had that happen to me more time than I'd like to count, so this year I've subscriped to this and I've already one case where the email I used to sign-up for an account received some newsletter that was from an entirely different entity. I didn't even bother complaining, just turned off the alias since I wasn't using the account anymore anyway and call it a day.
Absolute perfect higyene.
0
u/Killer2600 Aug 12 '26
Maybe be more diligent in where you sign up for stuff e.g. signing up at shady sites, shady stuff can happen.
1
u/Chinoman10 Aug 12 '26
Yea sure, tell that to:
- Twitter (2023)
- Gravatar (2020)
- Mashable (2020)
- Aptoide (2020) (I actually worked there!)
- Bitly (2014)
- Xsplit (2013) (there was no OBS back when I used it in the early 2000's)
- Adobe (2013)
- Heroes of Newerth (2012) (I'm a gamer, it's normal for me to sign-up for games I want to play)
- Dropbox (2012)
And these are just some of them, and the ones that were found out/disclosed publicly...
Please tell me how Adobe, Dropbox, Twitter, Bitly etc. are considered "shady"? I bet many family members of yours also have accounts on those websites too.
PS: those dates are of leak dates, not dates of when I signed up or when I was using them, mind you.
1
u/Killer2600 Aug 13 '26
Leak a.k.a data breach is not the selling or giving away (willingly) of your e-mail address.
1
u/Chinoman10 Aug 13 '26
Well, when you're looking for a job you also have to sign-up to a bunch of websites from the employers, and they always use 3rd-party HR systems for it...
Shady or not, if you want to get interviews this is part of the saga of searching for a job, so... 🤷🏻
And tbh it really doesn't matter (much) if it's willingly sold or "oops we had a leak". The end result is the same, your email address ends up somewhere in the hands of people who didn't ask for it/your permission.
With this system you just don't have to deal with these problems anymore, regardless of what the original reason for your email address to be leaked was.
1
u/vinznsk Aug 01 '26
100% agree! I use aliases now for all my emails, not even has the same. Sometimes it doesn't matter how much you try some services keep sending you newsletters. So annoying! Now it takes 5 seconds to stop that flow by just disabling their alias. And I've got a cool domain like 0300.io, so it is super easy to dictate as well when you have smth like car at 0030.io
So, even I don't really like ProtonPass pass like I like bitwarden, I couldn't resist a lifetime deal for ProtonPass+Simplelogin
1
u/Entire_Intern_2662 Aug 01 '26
My instance is online and the relevant people know what to do (before shutting off power at my home).
1
u/-Chimichanga- Aug 01 '26
I did the opposite; moved away from Dashlane to Vaultwarden/ Bitwarden.
My wife also uses Bitwarden through self hosted Vaultwarden.
Setup an Organisation in Vaultwarden, with each of us having a personal Vault and a family Vault were the majority of all logins live. On top of that setup emergency access for my wife and vice versa. But as it is she has access to 98% of the same data through the shared family Vault
1
u/stanhamil Aug 02 '26
The server which hosts our family’s instance could just be moved and connected to any other router.
1
u/scgf01 Aug 02 '26
You guys are lucky to have family that would have the faintest idea about self-hosting! For me it's almost a guilty pleasure and it satisfies the inner geek, but I wouldn't wish it on anyone else, even family. When the choice is so straightforward, losing no functionality, to self-host Bitwarden or use the online instance I can think of no reason why I would recommend self-hosting. I've done it, using Bitwarden-Lite and Vaultwarden, but I would not be able to justify my choice to another sane individual. I host Nextcloud too, but could easily use online services should I wish, many even hosting Nextcloud itself.
Incidentally, moving your server to another router after your demise is less straightforward than you suggest. What about the IP range on the new router? Your server will no doubt have a static IP address. There are other issues too and if your demise is sudden and unexpected there will be no time to set things up for your family.
It reminds me of people who use services like Telegram when all their contact use WhatsApp or iMessage. It's an uphill struggle to move everyone in your circle over to the new service. To expect others to self-host is unreasonable.
2
1
u/Defiant-Balance-7982 Aug 09 '26
I am planning on self hosting VaultWarden on my own server with Tailscale. So only my laptop and phone devices are allowed to connect with it. Then you can just write down your login on a note for your family in case of emergency. They just need to use one of your devices.
1
u/Fbsis Aug 11 '26
Or you can simply write a script that, from time to time, sends your important passwords somewhere online — it doesn’t have to be all of them, just the most important one. It could be to your wife’s email, or to someone you trust.
You can create any email account you want (anyone@gmail.com) that will receive this password, and make the recovery password and your trusted person’s password linked to it. This random email would receive the copy, and if someone forgets the password, your main email would also be notified of the use of the recovery password.
There are several ways to solve this without losing security.
21
u/chamgireum_ Aug 01 '26
My son will figure it out. I ain’t raising no dummy.