• Enoril
    link
    fedilink
    English
    1
    edit-2
    4 months ago

    Do you really need that ?

    Self hosting means you have outside your phone your real vault and the phone is just connecting to it to refresh its local data.

    I’ve setup my vaulwarden in my local network kit’s the local bitwarden server i use), my phone, tablet or simple webbrowser can connect to it when i’m home via the classic bitwarden (with self hosting parameters).

    If i travel, i have just to start my openVpn session and connect to my home but it’s only needed if I want to update something (the encrypted cache it’s enough for consulation). If I have nothing to change, no need to have a vpn. I just use the cached data.

    If my phone is stolen the data are safe (cache is encrypted, source is not on the phone). I revoke the vpn access by precaution and move one. No sms scenario needed here.

    You only need to have a backup phone or computer to setup your new access on the new phone.

    Edit: of course my vpn connection is protected by a passphrase so nobody can connect to my home network without me around. And the bitwarden app is also protected of course.

    • @[email protected]
      link
      fedilink
      English
      14 months ago

      Do you have a second factor for your VPN? Or is it literally just a passphrase and you’re in? I also need a shared key to access mine, which puts new back at square one (I will not compromise on this)

      I do really need what I’ve described because it’s literally a situation I’ve been in.

      • Enoril
        link
        fedilink
        English
        1
        edit-2
        4 months ago

        passphrase yes. It’s a long sentence than only me know.

        As i use this vpn only when travelling and the passphrase doesn’t change, i can use my phone or tablet cached data to get the passphrase if i forget it.

        And once connected to my home network via my vpn, i have access to all my services (vaultwarden, jellyfin, storage, etc…). All require of course login as i’m not accessing them from my local network.