this post was submitted on 16 Oct 2023
26 points (90.6% liked)
Privacy
32039 readers
627 users here now
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
Chat rooms
-
[Matrix/Element]Dead
much thanks to @gary_host_laptop for the logo design :)
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
You can do all of that on your own.
OR, you can create a single attack vector that can potentially be exploited and put everything at risk, at the same time.
If you've ever worked in, or adjacent to, IT, then you've heard the phase "single pane of glass", meaning you can manage all your infrastructure, or IOT, through a single terminal/UI.
This is basically a single pane of glass that you're getting through a side loaded repo, to manage your entire digital life. That means it can also become a single pane of glass for anyone able to exploit that application i.e. supply chain attack, phone AND/OR app specific vulnerabilities, etc.
Not really, sort of, but different threat models IMO.
The app this thread was about is asking to become a single pane for external services e.g. cloud, which is why it requires your Hertzner API.
For the following, I'm reaching into my memory hole, so definitely check elsewhere to confirm before doing anything.
FreedomBox, if I recall, is basically Debian Linux with a variety of self-hosted tools that are easily configurable e.g. Media servers, torrents, NextCloud, etc. It's been around for a while and I don't recall ever hearing anything bad about the project.
Ultimately, sure, you're still trusting the maintainers to some degree, like with any distro/spin, but that's a judgement you'll have to make for yourself.
If you're going to use Freedom box for all of your most critical and private parts of your digital life, then you should probably weigh the risks more heavily, than if you're just going to make it a media and torrent box.
Anything with "Freedom" in its name sounds sketchy.
The other side of that being Security through Obscurity.
If you're not running all your stuff through a major well-known host like Google or Amazon you're less likely to be a target than if you're just self-hosting.
Supposedly Google and Amazon have "good" security, but they still get hacked.