3 ms·
Isn't the upside of hosted platforms like this that they have teams of people securing and monitoring the platform, which can be a bit much for one person who's
by bithaze 6y ago
Isn't the upside of hosted platforms like this that they have teams of people securing and monitoring the platform, which can be a bit much for one person who's self-hosting? I do self-host other things but the article doesn't say anything about how the breach might've occurred (e.g. 2FA not enabled?).
- Frost1x 6y agoThat's the SaaS sales mantra repeated. It may or may not be true no matter how appealing the argument is. Ultimately, your weakest point ends up being humans who are prone to mistakes. You can mitigate some of those mistakes with technology but you can't mitigate all of them. So SaaS may help shore up certain attack vectors but it may increase focus on the remaining vectors and may potentially make failure points more significant (more impact for a security breach from a large provider vs less impact of a security breach from systems of independent providers). Some of that can be mitigated with smart designs, but you lose some advantage of traditional "security through obscurity" which has some value (though it shouldn't be relied on as a failsafe).
- _jal 6y agoThe counterargument is that a SAAS platform like Github's interests are in the ongoing viability of the service, while my interests are only about in my data in the service. Those are only somewhat aligned, as anyone with a dispute about terms of service can tell you. > which can be a bit much for one person who's self-hosting If your repo serves one person, why do you need your repo to be hosted in public at all? `git init` and a backup are all you need.
- flak48 6y agoMany consider hosting the repo (privately) on Github etc to be the backup.