3 ms·
Speaking of security concerns, you might think twice before continuing to use OwnCloud as a part of your password vault solution. It's had critical security bug
by oneJob 11y ago
Speaking of security concerns, you might think twice before continuing to use OwnCloud as a part of your password vault solution. It's had critical security bugs in the past, and I'd wager more in the future.
http://www.pcworld.com/article/2845072/ubuntu-owncloud-and-a-hidden-dark-side-of-linux-software-repositories.html http://www.pcworld.com/article/2845072/ubuntu-owncloud-and-a...
Part of the value of a service like LastPass (not a fan personally, but for argument sake I think ths still holds for this issue) is that someone is (should be) always on duty to monitor the service for suspicious activity and be ready to respond to security issues in the code base. While you're in class or a meeting or a movie or asleep, they can already be locking ish down and implementing patches / fixes.
- distances 11y agoYes, I'm aware of the Ubuntu/ownCloud repository mess, as I was also affected myself. I'm not too worried though -- it's a personal virtual server with a custom ownCloud endpoint, and the password file is encrypted anyway. These are always a bit of a balancing act on what's good use of third-party services and what's worth handling yourself. Services hopefully have a competent team behind it monitoring it (not guaranteed though!), but at the same time provide a much more lucrative attack target. And in my case at least, in a completely different jurisdiction. Monthly feels, service continuity, learning aspect... There are lots of different points influencing the choices.
- oneJob 11y agoAll awesome points. I host my own email on pretty much the same line of reasoning. The "more lucrative attack target" is a great point I hadn't factored in.