4 ms·
Until you get spammed to hell, or the next vulnerability leaves your system broken, you're utterly owned. There's a lot more that goes into self administration
by PenguinCoder 5y ago
Until you get spammed to hell, or the next vulnerability leaves your system broken, you're utterly owned. There's a lot more that goes into self administration then just "put a server up".
- KronisLV 5y agoIf updating a Docker tag every month or so after verifying that your backups are working is too hard, then it is probably indeed a better choice to rely on SaaS, however that line of thinking is dangerously close to falling into the trap of SaaSS: https://www.gnu.org/philosophy/who-does-that-server-really-serve.html https://www.gnu.org/philosophy/who-does-that-server-really-s... And if you want automatic updates, then either use the :latest tag, use apt/yum/... packages with unattended upgrades or something like Snaps for Ubuntu. However, in my experience, updates should be done manually and only when you're ready to roll them back (unless there are non-breaking security updates which are only available for OSes most of the time). As for spam, if you can't moderate your Discord or Slack Space, then the same will apply here, of course. As for getting owned: if your passwords are simple enough to be guessed or you don't follow other best practices, then the same will apply both to SaaS offerings and the software you're hosting yourself. Basic common sense like not exposing DBs to the Internet and using your firewall to only expose the ports you want was assumed, but not explicitly pointed out in my post.
- marcellus23 5y agoThat's a lot of stuff to worry about and get right vs. just paying $XX a month for someone else to deal with it.
- KronisLV 5y agoYou know, that's a fair point. On one hand, feeding a YAML file into a container orchestration solution takes care of some of those concerns, as does enabling VPS backups and using something like KeePass to generate passwords (which can also be used for everything else, should you so desire). On the other hand, not everyone necessarily knows how to do that, or wants to do that. To that, i'll indeed concede. It's just that claiming that these things are too hard for the average technically inclined person to do (regardless of whether they have 2 or 10 years of experience) leads to a mindset in which people rely on SaaSS for everything and never even learn how to run their own software, thus either paying too much for it (relative to the worth it provides them with), or just locking themselves into a particular vendor. Lastly, by hosting your own software, you are a smaller target than the larger and more centralized SaaS platforms. If a large SaaS gets hacked, although unlikely, it will affect a large amount of people. If your own instance gets hacked, even if more likely (less visible to hackers, almost no gain to be had for hacking John Doe's Nextcloud instance, yet probably also easier to do), it will only affect the few people using it.