itzgee.com

Where should your passwords live? Google, Apple or your own

Your password manager opens every other account. What Google and Apple's built-in options actually do, and when running your own vault is worth it.

passwordsencryptionsecurityvaultwardenself-hosting

First, the part that matters more than anything else in this article: use a password manager. Which one is a detail. Using none is the actual problem, and the built-in ones are free, already installed and work well.

If you are choosing, though, it is worth understanding what the choice is — because this is the one vault that opens all the others.

Who can open the box?

Encryption gets used loosely, and the difference that matters is simple: who holds the key.

If the provider holds it, your data is encrypted on their disks — genuinely useful, protects you if a drive is stolen or a datacentre is burgled — but they can open it. For support, for scanning, or if legally compelled.

If only you hold it, they are storing a sealed box they cannot open. Nobody can be made to hand over contents they do not have.

who holds the key

they hold the key

Encrypted on their disks

Genuinely useful. Protects you if a drive is stolen.

They can open it

For support, for scanning, or if they are legally compelled to.

A breach reaches the contents

Because the key is in the same building as the box.

only you hold the key

They store a sealed box

And have no way of seeing what is inside it.

Nobody can be made to open it

You cannot hand over contents you do not have.

Lose the key, lose the contents

This is the real trade, and it lands entirely on you.

Encrypted on their disks and encrypted so only you can open it are very different things. The second is stronger and it removes your safety net at the same time.

For password managers specifically, the good news is that all the serious options — including Google’s and Apple’s — are built so the provider cannot read your passwords. This is one area where the industry got it right.

So the difference is not really “can they read it”. It is everything around it.

What the built-in options actually cost you

They tie you to an ecosystem. Apple’s works beautifully on Apple devices and awkwardly elsewhere. Google’s is at its best in Chrome. If your household runs a mix — and most do — you will hit the seams constantly, and the friction pushes people back toward bad habits.

Your vault depends on that one account. If your Google or Apple account is locked, disabled, or lost, the thing that opens everything else goes with it. Account lockouts are rare, and they are catastrophic when they happen, and there is often no human to appeal to.

You inherit their decisions. Features, sharing, what happens on a platform they stop supporting. Fine, until it is not.

Sharing barely works. Household sharing across two ecosystems is where most people give up and start messaging passwords to each other, which is worse than anything else discussed here.

What a self-hosted vault changes

Running your own — Vaultwarden is the common choice, and it works with the standard Bitwarden apps on every platform — changes three things.

The vault is yours. It lives on a machine you chose, in a country you chose. No third party can lock you out of it because no third party is involved.

It works everywhere equally. Apps for every phone and browser, and none of them care which ecosystem the rest of your life is in. In a mixed household this is often the real reason people switch.

Sharing actually functions. Household vaults, shared logins for the shared accounts, without anyone texting a password.

And because it is open source, anybody can inspect how it works. That is a weaker claim than people sometimes make — most of us will never read the code — but it does mean a great many people have, and problems get found and published rather than staying quiet.

The part that should worry you

You are now the recovery process.

Lose the master password and the recovery material, and the vault is gone. Not “gone until support helps” — gone, permanently, by design. That is the same property that stops anyone else opening it.

Lose the server without a backup and you have the same outcome.

This is the whole trade, and anyone who glosses over it is selling something. Complete control means complete responsibility, and for some households the honest answer is that a big provider’s recovery process is worth more than the independence.

If you do it, do these

  1. Write the master password down on paper and put it somewhere you keep important documents. Not a file. Paper. This advice sounds wrong and is right — the realistic threat to your vault is you forgetting, not a burglar searching your filing cabinet for a password.
  2. Save the recovery material the same way, separately.
  3. Back the vault up automatically, somewhere that is not the machine it runs on.
  4. Test a restore. An untested backup is a belief, not a backup.
  5. Tell one other person where those pieces are, if anyone would need your accounts should something happen to you.

The straight answer

Using nothing is the actual emergency. Fix that today with whatever is already on your phone.

Google or Apple’s built-in manager is a good choice if your household lives in one ecosystem and you would rather somebody else carried the recovery problem. That is a legitimate, sensible position.

Your own vault is the better answer if you run a mix of platforms, want household sharing that works, or find it genuinely uncomfortable that one account you do not control holds the keys to everything else.

The deciding question is not really about security — all three options encrypt properly. It is: who do you want holding the ability to lock you out? A company, or only yourself.

Both answers are defensible. Only one of them is a decision you have actually made.

more in guides

← back to blog more in guides →