← Back to context

Comment by Havoc

5 months ago

After the LastPass fiasco I switched to selfhosting a password manager (bw).

Rapidly starting to think even a vibecoded solution may be a better plan relying on commercial options. High risk of don’t roll your own crypto mistakes but realistically that’s not the threat model here anymore for the random individual. It’s online breaches or perhaps a wrench attack not highly skilled crypto adversary. Plus there are probably ready made crypto modules so wouldn’t be a true handroll

Vibecoding a password manager might be the worst idea ever. You'd be better off with an encrypted Excel sheet. But otherwise, 1Password is great imo and there are other free open source password managers.

  • >Vibecoding a password manager might be the worst idea ever.

    I mean I'm just spitballing here, but not convinced this is true.

    From a formal security theory perspective certainly, but practically...nobody with half an ounce of skill is going to spend their time breaking one individual's custom solution that almost certainly just contains their hn password. That's if you can even get to it - selfhosted password managers are usually on LAN/behind vpn.

    Risk profile wise the thing could be a god damn plain text .txt on a LAN network drive and still outperform a Lastpass.com that by definition has a giant hack-me sign on it's back.

    The crypto part barely moves the needles here

    • Part of it being a bad idea imo is just that it's wasteful to vibe code something that already exists and works well. But I guess that's my attitude to a lot of this AI hype.

  • People mock Excel's encryption, mostly based on the outdated binary format's "encryption" (which admittedly was a joke). Modern Excel is actually legitimately secure, it uses PBKDF2 (5K rounds) to hash the user's password then AES-256 for the actual encryption.

    So while Bitwarden is more secure than modern Excel out of the box, neither one is a slouch. You'll definitely spend a lot of compute cracking either one. The weakest part, as always, is the user's password.

Yeah, I'm thinking the same thing - wondering if security-by-obscurity may compensate for some lack of quality.

The LLMs also help a script kiddie become a highly skilled crypto adversary though.

Especially if the concerns around Mythos are well founded.