• 0 Posts
  • 1 Comment
Joined 1 year ago
cake
Cake day: December 29th, 2023

help-circle
  • When you login to the Vaultwarden web application it’s going to exchange your passphrase for a private key.

    bitwarden is end to end encrypted: your decryption keys never leave your device, and the server certainly never sees them

    you must always be able to trust your network

    this would be a horrible password manager. this is also not how bitwarden works

    you do still need to trust your server if you use the web interface, because any web interface can serve malicious components to exfiltrate whatever they like but native apps, assuming they’re verified appropriately, could communicate over HTTP and still not allow anyone actively monitoring your network to see any data that would be particularly useful