deadbug
web log
i ditched the iCloud keychain why and how i switched to self-hosting a vaultwarden instance published on the 26th of april of 2026
834 clicks
0 claps

i like the iCloud keychain (or Apple Passwords, as they call it now). it's convenient, and one of those iPhone elements that just work. apple also provides a free e-mail relay service for some apps, so your real e-mail doesn't ever get exposed. and it's got the best password generator of any password manager that i've ever used. they follow a few simple rules that make the generated passwords easy to parse by my dumb, dumb head.

take this password for example: depsy0-supgop-ziXnog. this is a real, current password for one of my many e-mail accounts. it contains two special characters, one number, and a capital letter; so no website will complain. i can read the components like they're "actual words", since the numbers always come afront or aback the hyphen-separated parts, and they seem to use some kind of algorithm to make the "words" more human-friendly. it's 20 characters long, which means that it would take an insane amount of time to crack, according to some chart i found on the internet (and it only goes up to 18 characters!). it would probably take less than the quintillion years if one knew that it's a password in this exact format, but i'm not a mathematician so i can't verify. if you know some in-depth analysis of whether these passwords are secure, assuming that an attacker knows one was iCloud-generated, please drop a comment, i'm interested!

also, apple seems to manage some sort of database of website rules, since i've seen it fall back to another generator when a website required a password with a maximal amount of 16 characters.

the crisis

my phone was dead.    not really, all my stuf was still in it, but because of my error i couldn't access anything on it: the touchscreen was boke. both the touch and the screen. i quickly realized that i'm logged out of all my e-mail accounts on my pc. all of my passwords are on the keychain. no biggie: i'll just log into iCloud on the web and get them from there. i enter my passphrase. 2fa code on my iPhone... right. i'll just swap the SIM card with another device and get the SMS code. i'm in. click on «all apps». aaaand: sike. no «passwords» option there.

access to the iCloud keychain is only given to iOS, macOS, and – since recently – Windows devices, through an app. and i just happen to have none of these. the most logical thing to do would be to install Windows on another drive or use a VM. i might be a "technical" person, but think about this theoretical user: someone who owns an iPhone, and just an iPhone, no personal computers. what are they supposed to do? i had nothing important on that e-mail account. but there are situations where one might need access now.

i ended up inconveniencing my friend, and getting him to log out of his iCloud account on his phone, and log into mine. i exported my passwords (which also got merged with his 🫩) to a csv file, and copied them onto my terribly slow temporary-replacement 2017 budget phone. i knew i needed to change out that piece of shit software.

the solution

the solution is to use a password manager that has a web interface. that's it. the web is the one platform that is accessible from all consumer informational electronic personal devices. there are many options, but i went a bit further and hosted a vaultwarden instance myself instead of using a public service. vaultwarden is an unofficial implementation of the bitwarden server, written in the big rust (of course) instead of the evil and vile c#. the official server apparently allocates around 3gb of ram and requires running many containers with init scripts to glue everything together — reddit data. (also, i'm pretty sure that this defeats the point of using containers? but i'm not really a server person). my vaultwarden instance is using 88mb at the moment. of course vw isn't aimed at running an enterprise password manager service like Bitwarden, Inc. does, and has some tradeoffs. there is an official bitwarden self-hosted project, but it's not as popular (i haven't heard of it before doing research), so i just settled on the unofficial option.

all that it took to set up was adding a new A record on namecheap, starting vaultwarden as a docker service and adding one reverse_proxy directive to my caddyfile. i could also get away with not using a reverse proxy, or having a purchased domain by using wireguard, but this option is more convenient to me.

now i can access my passwords, passkeys and auth codes on all of my devices, and the iOS integration is great! i thought i wouldn't get the usual convenient password fill-in popups and keyboard prompts, but they're there! and i don't have to type the passwords myself on the pc. i just wish that the password generator was as good as the iCloud one. there is a passphrase option, which i do use, but there is just something about the old passwords being all equal length, and parsable while not being real words, that makes me like them a lot. unfortunately, on iOS, i have to generate and save the passwords myself in the bitwarden app when i make an account somewhere, and i can't just click «save and fill» to generate a new password and immediately add it to the vault. but how often do you have to make accounts, right?

i've also ordered my first thin client computer, which will arrive soon, and i might host the manager from my home, which would be super swag. i still would need to keep the reverse proxy on my vps of course. i'm hyped about the computer since it uses only a few watts of power, even while not idling.