Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Run your own cloud (specifically OwnCloud). The setup takes effort, but afterwards it's easy. I run it on a microserver at home, with port forwarding for access.

All the benefits of "cloud", but you know where your data is. Do remember to make backups, but you need those for commercial services as well.



Considering OwnCloud’s current breach following recent acquisition, you might want to check out the NextCloud fork, which seems to be actively worked on

https://nextcloud.com/blog/security-statement/


NextCloud is certainly also an option.

That said, the security issue wasn't really the fault of OwnCloud. They use a Microsoft library, which itself included a further library. That downstream library had the security issue. Unfortunately, it happened to interact especially badly with the containerized version of OwnCloud.

That kind of downstream security issue can bite any project. I don't blame OwnCloud in the slightest, and they were very quick to acknowledge the problem and post the solution.


In the past I've been hacked for some owncloud lldap vulnerability.

Do not allow access to owncloud without a vpn!!


I don't doubt your experience, but I wonder what the issue was. The only LDAP-related issue I find (cve-2021-40537) also requires compromised admin-credentials to exploit. Of course, with compromised admin credentials, all bets are off anyway.

I know it is only anecdotal, but I have been running OwnCloud for many years now, available without a VPN, with no security problems.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: