Hacker News new | ask | show | jobs
by 8organicbits 965 days ago
I wouldn't worry about a targeted attack if I was "nobody" and I was self hosting. Likely bitwarden? I'd worry about an attacker scanning and exploiting every instance they can find. Scanning is cheap and provides value in aggregate.

I'd recommend only exposing bitwarden on an intranet, or controlling access with a strict firewall, but the setup guide makes no such suggestion. https://bitwarden.com/help/install-on-premise-linux/

1 comments

I thank you for your advice and no, it's not bitwarden. I have losely described my setup elsewhere in this thread.