1
Concerns about publicy hosted Vaultwarden's
Source: dani-garcia/vaultwarden#3810 · opened by @secwarz
As a newcomer to this project, I have been looking around the internet about it and came across this website: vaultwarden.xx . Initially, I naively assumed that the site might be affiliated with the project creators. However, in adherence to good security practices, I habitually verify affiliations from both parties involved. Upon conducting this due diligence, I found no evidence to suggest that the aforementioned website is officially connected to this project, apart from the name similarity. Given that this is open-source software, I recognize that any individual can deploy an instance of it online and make it accessible to the public. Nevertheless, it raises concerns when dealing with a password manager application. Specifically, the issue is that any entity can operate the software under its original name, but as a closed service on a website, potentially compromising security. Consequently, I recommend that there be explicit indications about the official channels endorsed…
No pledges yet. Be the first to back this.
Comments
Similar requests
Re-License of Vaultwarden to AGPLv3
26 votes · 0 comments
Migration to organization
1 vote · 0 comments
Prebuild-Archive possible? Excessive RAM requirements for Vaultwarden builds (>= 7GB during install/update)
1 vote · 0 comments
Wiki: configuration file is not easy to find
1 vote · 0 comments
Missing authentication for the /icons/ endpoint
1 vote · 0 comments
No comments yet.