Might be a nice idea to haveand not to use a cloud based system to store passwords, is there anyone who knows what would exist of open source local hosted tools that make this possible and also make it possible to use it on various devices like smartphone, browser,… with an app that links to te local hosted password server.
password safe?
Then store the password database in the cloud…retrieve it/save it back to the cloud
Password Safe works very hard to make sure you password information is saved properly. However, Password Safe cannot protect against physical damage or loss to your hard disk, laptop or PC. Therefore, we strongly recommend that you make regular copies of your password database ‘off-line’, that is, to another PC or disk. This can be done manually, or by using a cloud storage service such as DropBox, SugarSync or JungleDisk, to name a few.
Another thing you might want to consider is arranging for access to your password database by relatives or co-workers if you are no longer able to do so. Password Safe has no ‘back door’ or ‘recovery password’ mechanism by design. This means that you are responsible for making the master key available to others under the appropriate circumstances. This can be as simple as a sealed envelope in a drawer or safe-deposit box, or a more elaborate mechanism such as splitting the master password and giving different parts to different parties.
Nextcloud also has a password manager app. But of course this is an overkill if you don’t need the file sharing features in general.
There were two password managers mentioned in this thread: https://dietpi.com/forum/t/password-manager/933/1
KeeWeb can be run with little effort and adjustments.
Check Self-Hosting at https://github.com/keeweb/keeweb
sysPass looks also promising
https://github.com/nuxsmin/sysPass
https://doc.syspass.org/en/3.0/installing/index.html
Both might be a great addition to the software packages list
I think for keeweb there is already an open feature request. In every case, to get more attention and priority consider to open an issue on GitHub (https://github.com/MichaIng/DietPi) and on FeatHub to collect votes: https://feathub.com/MichaIng/DietPi
Bitwarden is open source and available for self hosting IIRC.
Personally, the risk of trying to secure a self hosted password server is greater than the risk of a cloud provider (bitwarden in my case) being hacked.
Thanks for sharing good codes!
I have made a Github Repo at GitHub - YasinAdn/password-manager · GitHub . i will be very happy for some feedback.
I’m using Vaultwarden: GitHub - dani-garcia/vaultwarden: Unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs · GitHub
Unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs
which is available on dietpi-software
of course, I’m very grateful that one of the best open source password manager is available on dietpi-software, works like charm on my slow Raspberry Pi Zero 2W (512MB RAM) together with PiHole, unbound and Gitea ![]()
Supabase is a database service provider, that offers mainly/only PostgreSQL? Would it be generally possible to use a self-hosted PostgreSQL instance instead, or does Supabase provide an entirely different API?
That it stores the account password as dated bcrypt hash instead of modern Argon2ID, or yescrypt or such, is a negative point. But since actual data encryption happens at the client, this does not have an impact on the security of your (other) passwords. Worst case attackers being able to hijack your account or delete your encrypted passwords => have and maintain offsite backups!
But it says “the same master password”. Does that mean the Supabase shares the same password with the vaults master password for decrypting your passwords? That would IMO need to be changed, as a cracked Supabase account password must not put your passwords at risk. Unlikely nowadays with bcrypt, but in the light of low memory needs for brcypt and quantum computing, a future risk I wouldn’t accept when choosing a new password manager now.