4 ms·
I love nextcloud and have been using it for years. However recently I've considered taking my instance offline or at least behind a VPN because even if only 10%
by NaiveBayesian 4mo ago
I love nextcloud and have been using it for years. However recently I've considered taking my instance offline or at least behind a VPN because even if only 10% is true of what AI folks are claiming about LLMs finding exploits left and right, it seems super risky to be hosting your private data on nextcloud.
How do you folks deal with these massively increased threats to self-hosted open source apps?
- codepoet80 4mo agoI only use my ownCloud instance behind Tailscale...
- snailmailman 4mo agoI use nextcloud all the time, my private instance works great and does everything I need it to. But I keep it behind a VPN. It’s got a lot of parts, and thus a lot of surface area. It may be secure but I just assume it isn’t. I rely on the VPN to be the security boundary.
- 0fflineuser 4mo agoHost it in your home an use a vpn to connect to your home network when you are outside, that way it isn't exposed to the internet but you can still access it.
- theK 4mo agoYup, that's the way it has to be. And thanks to the autocomplete on steroids we call Ai nowadays it actually has become way easyier to do such a thing.
- margalabargala 4mo agoKinda like how once chemistry gets complicated enough we call it biology, LLMs have become complicated/versatile enough that it's no longer useful to call them autocomplete.
- longitudinal93 4mo agoBut then you are losing the ability to use it for file sharing ala Google Drive or Dropbox. I simply moved mine behing a random string with the home of the domain completely innocuous (an HTML re-direct elsewhere)
- onel 4mo agoI think a full blown VPN might be an overkill. Something like tailscale is much easier to set up, even though technically it's the same thing.
- freedomben 4mo agoYeah definitely would put behind a VPN. I run mine on my desktop at home and use Tailscale (Headscale for self-hosting) to make it accessible when I'm out of the house. Blazing fast speeds when at home, and reasonable when not.
- zerkten 4mo agoPutting everything behind a VPN seems like the solution selfhosters have landed on. That way you have some control over how quickly you have to respond.
- 3lpsy 4mo agoI host my entire homelab in my home and use tailscale to access it. You just connect your nextcloud instance to tailscale. Then you connect each client to tailscale. Works on iOS and android (and of course any desktop). When you're on you're home network (LAN), tailscale _should_ use the LAN IP for routing. And then when away, you'll route over derp servers usually. You could also use tailscale for auth, but i like to enforce separate authentication so that you have to be authenticated to the tailnet and have to go through the normal authentication to app.
- bityard 4mo agoThat works okay if you are the only user. I use quite a few Nextcloud features where access via tailscale is either inconvenient or impossible. My whole family uses the calendar on their phones and other devices, which means they would have to either learn about VPNs, or I would be the one managing all their devices for them. (Neither are likely to happen.) I also often share individual files or folders with external contacts as a more private alternative to dropbox or google drive.
- Melatonic 4mo agoCloudflare tunnel instead ?
- longitudinal93 4mo agoMove it behind a random string (i.e. https://yourdomain.com/gd5mka93 https://yourdomain.com/gd5mka93) and leave something simple and inoccuoua at the root.
- onel 4mo agoThat's a good setup. Tailscale, or wire guard like apps, are kindda the future. We're moving towards this more private internet where access is invite only.
- cahaya 4mo agoSame. Solving it by moving complex and sensitive data to an offline desktop app https://document.bot https://document.bot that support offline (self hosted) AI models (and optionally EU/ US AI providers). However, it doesn't integrate yet with shared (org) drives.
- drnick1 4mo ago> I've considered taking my instance offline or at least behind a VPN The practical downside is that you won't really be able to use all the features of Nextcloud that way, such as file sharing with people outside your LAN, or Nextcloud Talk (a Zoom substitute). That being said, I don't store sensitive documents on my Nextcloud instance exposed to the Internet. For that, I have a Samba server on a LAN.
- FabCH 4mo agoI ban almost the entire world using iptables. Or rather, I drop all traffic other than that coming from my geo. This has dropped my „rattling the door handle“ rate to 1/week instead of 1/second.
- throwup238 4mo ago> How do you folks deal with these massively increased threats to self-hosted open source apps? I throw everything behind Cloudflare ZeroTrust SSO or whatever it’s called with a whitelist of Github accounts, and Cloudflare Tunnel to network the containers/VMs without exposing any ports to the outside (except SSH), enforced by both the cloud firewall and iptables/ifw.
- onel 4mo agoI think moving it offline is part of the solution, but the main one is to actually find/fix the issues. So I guess this will require more involvement from us in open source.