49
submitted 6 months ago by Blaze@piefed.zip to c/privacy@programming.dev

That's my next project to get things from Google/Apple.

The options I've seen so far

Any option I am missing?

all 20 comments
sorted by: hot top new old
[-] Twongo@lemmy.ml 10 points 6 months ago

may i ask why self hosting isn't an option?

i run immich on an old pc i literally found in a dumpster

[-] Blaze@piefed.zip 16 points 6 months ago

My close family would rely on the hosted service for their photos.

I would prefer avoid having the responsibility of keeping the service availability and integrity.

I'm not the best at managing data (I lost a few years of pictures due to a hard drive failure and insufficient backup testing) and I don't have a lot of time to allocate to that stuff, so I don't trust myself with it

[-] PonyOfWar@pawb.social 8 points 6 months ago* (last edited 6 months ago)

Self hosting is great but if you want to make sure you can't lose your data, your backup should be in a different location than your main photo storage. Otherwise, in case of a fire or similar, you'll lose everything.

[-] Spaniard@lemmy.world 6 points 6 months ago* (last edited 6 months ago)

jottacloud, self-hosted photoprism and syncthing with desktop-pc and nas.

[-] 6nk06@sh.itjust.works 5 points 6 months ago* (last edited 6 months ago)

https://ente.io/ is a paid service, not expensive, E2E encrypted, and maybe open-source.

Edit: sorry, you already mentioned it without the URL.

[-] Blaze@piefed.zip 4 points 6 months ago* (last edited 6 months ago)

Yes I'm using Ente at the moment, ideally I would prefer to use a European provider (they would basically self host the Ente software with a fee for users), but at the moment there aren't any that I know of.

[-] cosmicrookie@lemmy.world 6 points 6 months ago* (last edited 6 months ago)

I went through this dilemma too and actually talked with ente about it. It turns out that they did initially try to set it up in Europe as they are a global team, but the EU requirement for physical presence in the country was limiting for them.

They said that there were workarounds for this but decided on setting it up in the US because it was very straightforward with no workarounds or limitations

I like the way they are going with ente though and feel like it's a fair price. The software works well too

[-] Blaze@piefed.zip 3 points 6 months ago

Interesting, thank you

[-] A_norny_mousse@piefed.zip 5 points 6 months ago

But if you get a VPS then you are self-hosting, so Immich is an option again?

If you need to have a so-called one-click solution, Zeitkapsl looks interesting (EU, yay) I guess.

And a general question, if you use SSL everything is encrypted anyhow? Or is the advertised E2EE something on top of that, which might be necessary if you don't have your own certificate or don't run your own server?

[-] Blaze@piefed.zip 1 points 6 months ago

If you host Immich on a VPS, there are three scenarios

  1. You just install Immich on the VPS normally. In that case, the VPS provider (e.g. Hetzner) can access your photos. Not ideal for me.
  2. You use disk encryption to encrypt the whole disk at the disk level (such as https://www.accruedwisdom.com/articles/hetzner-lvm-full-disk-encryption/). Seems a bit cumbersome to be honest, and even if the link says how to do it, I'm not sure it's completely allowed by Hetzner.
  3. You encrypt the files at the file level, but then you break most of the Immich features.
[-] smiletolerantly@awful.systems 2 points 6 months ago

LUKS isn't cumbersome, you should really enable it on nearly every Linux system.

Anyways, what do you mean "allowed"?

I have a Hetzner root server set up this way btw, have to ssh in to decrypt the zfs pool before boot.

Do note though, this does not protect from an attacker with physical access reading memory.

[-] Blaze@piefed.zip 1 points 6 months ago

I use LUKS on my personal machines, I'm just not sure if I want to enable it for a VPS. Now if you tell me you're doing that without any issue, that's good to know.

this does not protect from an attacker with physical access reading memory.

So in this case, the VPS provider can still access your photos when they are being used by the photos management software?

Seems to be another argument for E2EE embedded photos software.

[-] smiletolerantly@awful.systems 3 points 6 months ago

I mean... Depends on your threat model. Hetzner is a very reputable German hoster. The only way someone is going to try and read and puzzle together memory dumps is if you're under investigation for something seriously heinous.

Shutting the VPS down also solves this.

But really, this is a general problem with every "someone else's computer" solution.

E2EE still nice though, wish Immich had it.

[-] Blaze@piefed.zip 1 points 6 months ago

I see. Thanks. E2EE would indeed be nice, but the Immich devs have made it clear for a long time that it woudn't work due to the way Immich has been developed.

[-] A_norny_mousse@piefed.zip 1 points 6 months ago* (last edited 6 months ago)

What? Disk encryption is definitely "allowed", and yes, that is how you should do it. It's not "cumbersome" either, most installers have a GUI for that, and if Hetzner offers preconfigured images, full disk encryption is probably one of the offers.

I am now convinced that you are a little overwhelmed by the thought of managing a VPS. That is totally OK! But don't go talking out your ass because of it.

[-] Blaze@piefed.zip 1 points 6 months ago

I was answering based on this thread ( https://old.reddit.com/r/hetzner/comments/1hi6ktq/how_to_use_encrypted_rootfs_on_cloud_instancesvps/ ) with the following steps

The definition of "cumbersome" will vary from person to person.

I am now convinced that you are a little overwhelmed by the thought of managing a VPS.

Indeed, that's why I want to avoid to self host in the first place.

Not sure about the "talking out of my ass" part.

[-] ElwinManglyeong@lemmy.zip 2 points 6 months ago* (last edited 6 months ago)

What about https://www.photoprism.app/ ? Don't know much about it, but perhaps worth a mention?

[-] Blaze@piefed.zip 2 points 6 months ago

If I understand correctly, photoprism is also only self hosted? If that's the case, I prefer not to (see my other comment: I'm just a bad sysadmin)

[-] lena@gregtech.eu 1 points 6 months ago

I use Cryptomator connected to an Exoscale S3 bucket. It's not particularly convenient, but it's very cheap and I use it just for photo backup anyway.

this post was submitted on 07 Feb 2026
49 points (98.0% liked)

Privacy

5085 readers
267 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS