| You're ignoring threat modelling. If I keep a KeepassXC database on a set of devices, sync'd using syncthing, then for a large range of threats I'd need to be a target of interest. This is in contrast to LastPass which is going to attract a ton of blackhat attention. Yes, supply chain attacks are possible but they're equally possible for lastpass. Switching to a self-hosted solution isn't perfect. Nothing is, and pointing that out isn't particularly useful. What it does do is eliminate whole class of threats: large scale, broad based attacks against a single, high value target. In fact I'd argue writing passwords down in a notebook or putting them in a naked text file on your computer is better than trusting a centralized service like LP. Of course, if you are a target of interest, the calculus changes entirely. |