If you are interested in privacy you are probably interested in password storage … plus I wanted everyone to know about the inevitable future enshitification of this product. Spread the word and replacement recommendations are welcome too.

  • potustheplant@feddit.nl
    link
    fedilink
    arrow-up
    2
    ·
    3 hours ago

    There’s this wild technology called a hotspot. You can use your already authenticated device to give another device access to your services indirectly.

    Even if they break into my NextCloud, they’d have to crack an unreasonable password to break the password database open.

    That level of security is exactly the same as exposing your password manager to the “fucking” internet. Not sure why you criticized it before when you (incorrectly) assumed that I was doing that.

    • AHemlocksLie@lemmy.zip
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      2 hours ago

      There’s this wild technology called a hotspot.

      There’s also this dated technology called a wired connection that some other dated technologies require. Since I don’t get to choose every device I interact with or depend on, that’s not always available.

      That level of security is exactly the same as exposing your password manager to the “fucking” internet.

      I would disagree. A Bitwarden instance identifies itself as such to every visitor that comes by. It advertises itself as a particularly high value target. By contrast, a lot of what a NextCloud instance hosts is often personal and more valuable to the user than a hacker, so it does not become clear if there’s anything of value inside.

      It also decreases the attack surface of my password manager itself because there are fewer features in it that may have a potential exploit. Even if an attacker compromises the NextCloud instance, that may grant access to the file itself, but they still have to contend with the entire security of the password manager. No device will ever make any contact with the server for password purposes other than to sync the database file, and there’s no web interface to inject a password stealing JavaScript file.