Vaultwarden update out as of ~15 minutes ago, includes security updates.

It says “unconfirmed owner can purge entire organization vault”. That seems probably not great, so updating is probably a good idea.

  • TVA@thebrainbin.org
    link
    fedilink
    arrow-up
    16
    arrow-down
    3
    ·
    21 hours ago

    Updated mine, but, realistically, I don’t think most of us are directly exposing our VaultWarden instances to the internet … I can’t imagine I’m all that weird by only exposing it over VPN for remote use.

        • TrumpetX@programming.dev
          link
          fedilink
          English
          arrow-up
          6
          ·
          8 hours ago

          I understand why some would do this. It’s definitely a more secure setup, but I highly doubt “most”. I like having passwords on my work laptop. I couldn’t sync there with a VPN, for example. My wife, kids and parents aren’t going to run VPNs on their phones, etc.

          • mpramann@discuss.tchncs.de
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            2
            ·
            3 hours ago

            Vaultwarden is specifically used for self hosting. Setting up a Wireguard VPN on your server at home can be tricky in specific instances. Most of the time it’s dead simple though. Installing a Wireguard Client on your mobile devices is as simple as scanning a QR code. And to be fair: If you’re going to expose the Vaultwarden instance to the internet why not just use the official Bitwarden service then? I’m sure they can handle security better than someone who has trouble setting up an VPN server.

    • oyzmo@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      17 hours ago

      True! Good and relative safe on my Tailscale network. The only thing I`m brave enough to expose to the big and scary internet/botnet is my little Pi running Headscale, and I’ve put that on a separate network.