Comment on Ditching the VPN and port forwarding the selfhosted way
Schlemmy@lemmy.ml 3 weeks agoI’ve set up some tunnels. Works nice but then the voices came. ‘Why would you trust a company like Cloudflare with all your data?’ ‘Why rely on this one company for all your services?’
Nearly a year into my selfhosting journey and I’m more confused than ever.
EmbarrassedDrum@lemmy.dbzer0.com 3 weeks ago
tl;dr: classic convenience/privacy. depends on your threat model. surely better than Google. models of zero trust will help.
That’s a great question, that I have asked myself before too. It doesn’t have one answer, and any one would make their own choices based on their own respective threat model. I’ll answer you with some of my thoughts, and why I do use their services.
I’ll take as an example my usage of NextCloud, coming as a replacement to Google Drive for example.
let’s break up the setups:
It’s oversimplified, but to the point: In Google’s setup, you have control of 0 out of three things.
In NextCloud’s setup,
From just this look, NC is clearly better off. now, it’s not perfect, and each one will do their own convenience vs privacy deal and decide their deal.
If you deploy some sort of e2ee, the severity level of CF drops even more, because they’re exposed to less data. specifically for NC they do do e2ee, but each solution to its own. nextcloud.com/encryption/ this goes as an example for zero trust model. if you handle the encryption yourself (like using an e2ee service), you don’t have to trust the medium your data is going through. like the open internet.
fmstrat@lemmy.nowsci.com 3 weeks ago
This contradicts your threat model comment, though. If you fear Google’s access to your data, you fear nation states, or hate Google. Cloudflare is in the same boat for size, scope, and US ownership.
EmbarrassedDrum@lemmy.dbzer0.com 3 weeks ago
Obviously I’m not avoiding it all together, but I’m taking a step in the right direction.
And it’s not just replacing Google by CF, because CF has much less access in comparison as I explain.
you can deploy some zero trust models in your setup, and eliminate the threat even further. for example end to end encryption
fmstrat@lemmy.nowsci.com 3 weeks ago
Oh yes, wasn’t trying to say it was a bad decision at all. If it fits your threat model, and it makes life easier, it’s probably the right choice.
Schlemmy@lemmy.ml 3 weeks ago
Thanks. I agree with your conclusion. I probably have spent too much time in privacy communities. In the end you’ll have to trust someone.
EmbarrassedDrum@lemmy.dbzer0.com 3 weeks ago
that’s not to wear off of the importance of awareness. you should be aware always, even if you don’t take action.