2/7/2026 at 2:19:23 AM
I made one of these once and stopped using it for some of the same reasons folks have in the comments:- losing the master is catastrophic - sign ins with dumb password rules meant I had to sync metadata - a bad actor knowing my resulting password, their site, my username, and potentially my password version meant in theory they could brute force offline and see if they could infer my master - I had to do silly things to use my passwords on not-my-device - getting my password on not-my-device felt extremely dangerous
by collingreen
2/7/2026 at 3:32:32 AM
Bastion has the same failure model as a hardware wallet or SSH private key. If you want recoverability, you accept third-party trust. Bastion refuses that trade.by KevinChasse