6 ms·
Would work great on a VPS endpoint to guarantee “always-on” syncing (plus a VPN tunnel). I won’t touch it until it stabilizes though.
by zshrc 3y ago
Would work great on a VPS endpoint to guarantee “always-on” syncing (plus a VPN tunnel). I won’t touch it until it stabilizes though.
- deleted 3y ago[deleted]
- tarruda 3y agoA cheap and nice self hosted alternative way to have an "always on" sync endpoint is with a raspberry pi 4 with SSD (don't try this with an SD card). My current setup is running a wireguard server, syncthing and DuckDNS on the pi. I also port forward the wireguard port from my ISP's router. With this, my devices are always connected to the VPN, and sync always works (and is fast!) like everything is on a LAN.
- hamandcheese 3y agoI think you are missing the point. If you fully control the hardware, then you probably don't need Untrusted Device Encryption.
- jsiepkes 3y agoThat's not entirely true. For example your Raspberry PI can get stolen. I would definitely encrypt the stuff on my NAS if it was sitting in my garage.
- xzjis 3y agoYou could also have a Raspberry to backup in another place, such as a friend's house.
- hamandcheese 3y agoSure, but the tried and true way to encrypt your NAS would probably be using full-disk-encryption, not something specific only to syncthing.
- ephbit 3y agoIf someone manages to access the running raspberry pi though, FDE doesn't protect against that, while the Syncthing's untrusted device encryption does.
- hamandcheese 3y agoIf your threat model includes someone willing to break into your house, then, well, good luck. [0] [0]: https://xkcd.com/538/ https://xkcd.com/538/
- jsiepkes 3y agoThe threat model described by the post above you is actually not about physical access. It's about the PI getting hacked remotely. If you use Syncthing's encryption then at no point is the decrypted content available to the PI. It gets decrypted locally by other Syncthing peers after they have downloaded it.
- hiq 3y agoBesides, there's still a difference between physical accesses: plain and non-targeted (besides how profitable they're expected) burglaries are way more common than violent targeted attacks meant to extract a secret from an individual.
- hamandcheese 3y agoAre you aware of any non-targeted burglaries where the burglar extracted secrets from a running computers memory?
- hamandcheese 3y agoAn attacker with a wrench will get the information they want from you, regardless of where it's located.
- grotorea 3y ago
- alwayslikethis 3y agoDepends on the setup, disk encryption has disadvantages such as needing to decrypt each time you reboot (and if that's the root partition, you can't really boot unattended). It can be advantageous to not have to trust the server and have a non-encrypted zfs dataset for this.
- rjst01 3y agoI've used dropbear-initramfs on both Debian and Ubuntu to remote-unlock hosts with encrypted root filesystems successfully. It'd be nice if it were better supported though. https://www.cyberciti.biz/security/how-to-unlock-luks-using-dropbear-ssh-keys-remotely-in-linux/ https://www.cyberciti.biz/security/how-to-unlock-luks-using-...
- tarruda 3y agoI understood that point. The raspberry pi would still serve as an always on endpoint regardless of the untrusted device encryption feature. In my case I don't use this feature on the pi, but I do use it on my phone which has 256gb storage. I have configured syncthing to only run when charging the phone, so it is not always on.
- Hamuko 3y agoIt's also a poor solution for an "always on" solution since it's dependent on your home Internet/VPN/power working, which is probably true for your other clients too. If I'm running Syncthing on a desktop computer at home and a laptop with me on the go, adding a Raspberry Pi to the same home network doesn't really improve resiliency of the sync service. But if I have a server in a completely different location, it actually will.
- iforgotpassword 3y agoWho on earth leaves their desktop running when leaving the house? Why?
- ReptileMan 3y agoYes you do. Any device that doesn't support good enough fde should have syncthing encrypted. Because usually you want the device to boot and start operating unattended - it is quite vulnerable.
- plagiarist 3y agoI agree with this. FDE for semi-autonomous network devices is just so you can more safely dispose of the drive at end of life. I would like FDE + untrusted device encryption for a NAS. I am glad Syncthing is working on this.
- BitFlogger 3y agoNot necessarily. Lets say I have a node at my in-laws house. I would use untrusted device encryption in case anyone decided to take the drive and have a look.
- sneak 3y agoThere’s nothing wrong with using an SD card. I use Syncthing on rpi with a 1TB SD card and it works great.