Comment on please recommend a simple selfhosted photo gallery
potustheplant@feddit.nl 1 week agoDoes that matter if you’re self hosting and not exposing it to the internet?
Comment on please recommend a simple selfhosted photo gallery
potustheplant@feddit.nl 1 week agoDoes that matter if you’re self hosting and not exposing it to the internet?
notfromhere@lemmy.ml 1 week ago
That entirely depends on what your threat model is. You may not get any value out of that feature, but others may want it. One reason may be ease of storage drive disposal upon drive failure; i.e., if your drive is unencrypted and has your personal photos on it and it fails, the data is still recoverable with no easy way for you to destroy the data. If it was encrypted at rest, you wouldn’t have to worry about it because you would only have to rotate the encryption key.
potustheplant@feddit.nl 1 week ago
If you’re using a raidz array (which you should) the data would be irrecoverable anyways when you dispose of a single drive, wouldn’t it? Also, why would you throw away a server drive that still works?
notfromhere@lemmy.ml 1 week ago
Why should I use a raidz array? I use other scalable storage solutions. Encryption at rest is a standard core tenant to cybersecurity. If one of the raidz drives is removed from the array, and you’re not encrypting your datasets, someone could recover data from the drive.
potustheplant@feddit.nl 1 week ago
Well, if you’re storing data you care about on your server you kind of need to have redundancy. The best filesystem for that (imo) is ZFS so yes, you should use that (or something similar). Apparently you do use a “scalable storage solution” but you also seem fond of mystery.
The solution is in the question. Just encrypt the dataset.