Physics and Free Software
I’ve been rocking it on a fairphone 4 for 3-4 years. I pretty heavily modified it to get it where I wanted, but I enjoy doing that kind of thing. App lounge is slow, but I don’t use any proprietary aps so F Droid and Obtainium gets me everything I need.
I’ve had Shelter in the background for proprietary apps. Traveling in particular.
My aunt did this along with posting a bunch of family photos and falling for those quizzes that ask your pet’s name or your childhood address. If you have one person like that the privacy of your entire family is compromised.
We told her back around 2010 not to do this kind of stuff, but she’s somewhere between “If I have nothing to hide” and “what’s the harm?”. I hope she gets it now, but we don’t talk to her often
Companies like google, facebook, and apple typically have better security. Other companies know that so rather than contracting with another third party or implementing themselves, they use oauth.
With oauth, apple, google, microsoft etc. will vouch for you. There are advantages and drawbacks, with, imo, the drawbacks outweighing the benefits. Key benefit being better security over poor practices and convenience. Drawbacks being less control of your accounts, consolidating your credentials into one basket, (especially if you use weak authorization), and the potential (likely) situation those accounts are monitored
There’s often the ‘security vs. convenience’ tradeoff, but for most people you have both sides with Bitwarden over KeePass.
Bitwarden is undoubtedly more convenient. If you can create an account, you can use it. I have a family account, and have both of my parents using it. The love it now, but given the friction to get them there in the first place, it would impossible to get them on KeePass. Especially because they wanted their passwords on all devices.
Regardless of using Vaultwarden or KeePass, you need to have quite a bit of expertise to self host. And you are trusting your own ability to secure your attack surface. I’m sure many if not most in this thread can, but it would take me quite a while to convince myself I have. I would much rather trust security professionals.
Somewhat, although, potentially related. Have you seen Bitwarden’s git repos? It is immaculately organized.
Consistent, clear naming convention. There is literally one called ‘self-host’. If you put that much effort into keeping your code that useable/available/auditable etc. Oh yea. I’m going to trust you to handle security for me
If it’s going to be as useful as possible, yes.