Fellow selfhoster, do you encrypt your drives where you put data to avoid privacy problems in case of theft? If yes, how? How much does that impact performances? I selfhost (amongst other services) NextCloud where I keep my pictures, medical staff, …in short, private stuff and I know that it’s pretty difficult that a thief would steal my server, buuut, you never know! 🤷🏻‍♂️

36 points

This shouldn’t even be a question lol. Even if you aren’t worried about theft, encryption has a nice bonus: you don’t have to worry about secure erasing your drives when you want to get rid of them. I mean, sure it’s not that big of a deal to wipe a drive, but sometimes you’re unable to do so - for instance, the drive could fail and you may not be able to do the wipe. So you end up getting rid of the drive as-is, but an opportunist could get a hold of that drive and attempt to repair it and recover your data. Or maybe the drive fails, but it’s still under warranty and you want to RMA it - with encryption on, you don’t have to worry about some random accessing your data.

permalink
report
reply
29 points

If you’re getting rid of a (rusty) drive and it leaves your hands with the cool magnets and shiny frisbees still inside, you’re doing something wrong.

permalink
report
parent
reply
1 point

Dude just use a hammer

permalink
report
parent
reply
21 points

Yes of course, with dm-crypt (luks), very little as AES-NI is incredibly fast.

permalink
report
reply
3 points

Do you insert the key/password manually every time (it’s a server, so not so many times, but could happen) you boot the server?

permalink
report
parent
reply
3 points

https://www.cyberciti.biz/security/how-to-unlock-luks-using-dropbear-ssh-keys-remotely-in-linux/

As mentioned in another comment I haven’t quite gotten it working but it should be possible to do this via SSH

permalink
report
parent
reply
20 points

Nope. This isn’t part of my threat model.

I don’t have sensitive data and stealing a drive would be inconvenient for a thief.

permalink
report
reply
6 points

You don’t have sensitive data? Would you mind expanding on that a bit for me? Just curious how you like, live, and stuff.

permalink
report
parent
reply
7 points

Plex data, pi hole, and home assistant don’t contain anything meaningful. No credentials are stored in a form that can be reused.

The most sensitive is immich, which I’m more concerned about backups than I am someone might steal my nudes. Their online anyway.

Email is hosted off-site and I still have physical files for a lot of my documents. If someone stole hdds out of my server, they’d get a lot of Linux isos, pictures of cars, porn, tons of versioned software and games installers, etc.

Maybe my definition of sensitive is different than yours though.

permalink
report
parent
reply
4 points

I’m surprized as well, like I guess I would understand if it’s a no log DNS server but, what else wouldn’t have sensitive information.

permalink
report
parent
reply
1 point

My Music, Movies and Shows, I dont consider them private/sensitive, as they aren’t illegal to possess or even download in my country. I would even donate my filled but corrupted drive to a repair guy, he can have the media if he can repair it.

permalink
report
parent
reply
17 points

No,

There is all the backup of all my family pictures in the drives.

If something happens to me I want to make due that they will have access to it.

permalink
report
reply
17 points

I keep my drives encrypted with a key currently hosted in my router hoping they wouldn’t steal that. I’m thinking of actually putting it to cloud so I can disable it remotely.

It was quite a ride to make everything work and I made a blog post explaining it so I remember what I did.

https://nowicki.io/self-hosting-lvm-raid1-with-key-over-ftp/

permalink
report
reply
2 points

Interesting, thanks!

permalink
report
parent
reply

Selfhosted

!selfhosted@lemmy.world

Create post

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Community stats

  • 3.4K

    Monthly active users

  • 3.3K

    Posts

  • 71K

    Comments