← Back to context

Comment by doodlesdev

7 hours ago

Proton Pass cannot be self-hosted.

I am using Keepass XC + Keepass DX synchronized with Syncthing. There's really nothing to self-host, other than throwing Syncthing on a NAS so you can make sure you have at least one machine online at all times. But even that isn't critical, since both Keepass XC and Keepass DX have a "Merge" option if anything falls out of sync.

  • ive used keepassxc forever, switched to proton pass after the release, because i was managing my db in git and it was always a pain to keep in sync, but switched back a couple of weeks ago with exactly the same setup, syncthing and KeepassDx also works suprisingly well.

    mostly i was missing power user features and especially ux for the browser plugin, namely you can't operate it fully with the keyboard, with keepassxc you can

As as self-hoster, I recommend vault warden. Supports 2fa, written in rust, works pretty well, is easy to backup, and you can use bitwarden's phone client.

I'm curious why other self hosters think it's a bad idea.

As a self-hoster, I don't think password managers should be self-hosted.

  • On the contrary. If there's one thing you should self-host is definetly password manager.

    • Why, you can of course self-host it, too, but the infrastructure should be entirely separate.

  • I don't see much reason not to self-host a properly built password manager like Vaultwarden or something similar? The clients keep a local encrypted copy of the vault, so the server only needs to be up for syncing. If it went down for a week, you probably wouldn't even notice unless you were saving new logins. And even if the server got hacked, everything on it is encrypted. Why do you think it should not be selfhosted?

  • Can’t relate. If you’re worried about you’re own reliability to keep it online, just keep paper backups