49
submitted 6 months ago by Blaze@piefed.zip to c/privacy@programming.dev

That's my next project to get things from Google/Apple.

The options I've seen so far

Any option I am missing?

you are viewing a single comment's thread
view the rest of the comments
[-] smiletolerantly@awful.systems 2 points 6 months ago

LUKS isn't cumbersome, you should really enable it on nearly every Linux system.

Anyways, what do you mean "allowed"?

I have a Hetzner root server set up this way btw, have to ssh in to decrypt the zfs pool before boot.

Do note though, this does not protect from an attacker with physical access reading memory.

[-] Blaze@piefed.zip 1 points 6 months ago

I use LUKS on my personal machines, I'm just not sure if I want to enable it for a VPS. Now if you tell me you're doing that without any issue, that's good to know.

this does not protect from an attacker with physical access reading memory.

So in this case, the VPS provider can still access your photos when they are being used by the photos management software?

Seems to be another argument for E2EE embedded photos software.

[-] smiletolerantly@awful.systems 3 points 6 months ago

I mean... Depends on your threat model. Hetzner is a very reputable German hoster. The only way someone is going to try and read and puzzle together memory dumps is if you're under investigation for something seriously heinous.

Shutting the VPS down also solves this.

But really, this is a general problem with every "someone else's computer" solution.

E2EE still nice though, wish Immich had it.

[-] Blaze@piefed.zip 1 points 6 months ago

I see. Thanks. E2EE would indeed be nice, but the Immich devs have made it clear for a long time that it woudn't work due to the way Immich has been developed.

this post was submitted on 07 Feb 2026
49 points (98.0% liked)

Privacy

5091 readers
287 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS