I can and do self host, but I'm not willing to provide these services for free. I don't want to be responsible for other peoples passwords or family photos.
Thats where good, privacy-respecting services come into play. Instead of hosting for my neighbours, I would recommend mailbox.org, bitwarden, ente or a hosted nextcloud.
The blog post contains an interesting tineline. Apparently, the first fix was not sufficient. So if you have updated Vaultwaren before November 18, update it again.
Copy of the timeline:
End of October 2024: ERNW assesses Vaultwarden for the customer.
November 08, 2024: ERNW discloses the vulnerabilities to the Vaultwarden team.
November 10, 2024: Fix and release of Vaultwarden v1.32.4.
November 11, 2024: ERNW retests the software and identifies that the fix is not sufficient.
November 11, 2024: Public merge with fix and request for feedback by the Vaultwarden team.
November 12, 2024: ERNW acknowledges that the fix is complete.
November 18, 2024: Release of Vaultwarden v1.32.5.
No dad, YOU never know when you might need them. I know for sure that keeping charging cables and headphones with proprietary connectors will never again be useful.
I'd host it on both webservers. The script sets the A record to all the servers that are online. Obviously, the script als has to check it's own service.
It seems a little hacky though, for a business use case I would use another approach.
Your challenge is that you need a loadbalancer. By hosting the loadbalancer yourself (e.g. on a VPS), you could also host your websites directly there...
My approach would be DNS-based. You can have multiple DNS A records, and the client picks one of them. With a little script you could remove one of the A Records of that server goes down. This way, you wouldn't need a central hardware.
I don't think your brain can be reasonably compared with an LLM, just like it can't be compared with a calculator.