Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I understand your point, but if my password vault was a self hosted piece of software and a self hosted vault file, I'd be nervous every day of losing data.


> I'd be nervous every day of losing data

And I am, same as I am worried everyday about losing the keys to my apartment. I am speaking as a person who once only got them back by sheer luck (and a young mans honesty), after they fell out of a hole in my trousers pocket.

However, I would be even more nervous if the security of these keys were up to someone other than me. For example a random employee of a big company, whos access to the system I have no say in, who I never met, and whos actions I can neither see nor regulate.

Bottom line is: I prefer worrying about myself failing, than someone else. Because I can do something about the former.


I think it depends on the skills and risks involved.

I prefer a qualified pilot worrying about keeping the Boeing I'm traveling in airborne, than myself.

But indeed, I rather worry myself about my house keys than someone else.

For me, keeping extremely sensitive data always available and securely secret forever is more like flying an airplane than not losing my house keys.


> always available and securely secret forever

Yeah...about that...

https://password-managers.bestreviews.net/faq/which-password...

And while I am certainly not qualified to fly an aircraft, I do feel that I am quite qualified when it comes to software engineering and systems administration.

So yeah, this is something I rather do myself.


I think the self-hosted bit is just for syncing, as long as you have multiple devices its not likely to lose data even if you don't follow the 3-2-1 backups.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: