Live data from Hacker News

Immich 3.0

github.com

261–270 of 313 posts

Re: Immich 3.0

#261
post #259
post #253

Earlier quoted context omitted.

What is the relevant definition of client and server if they are both peer devices under roughly equal level of control of a single entity?

The client in your family members devices has encryption keys that you do not have in your client or on the server

Ok but again, that is introducing an arbitrary split that is not based on tech. What if I have two phones? Would you expect phone A to see images taken by phone B? If yes, obviously my phones need to share keys.

So what is different in saying „All family devices should see images taken by any device“? They are all clients, including the storage&processing device.

Insisting that E2EE have „ends“ on clients is not useful. It’s much better to define „end“ based on control.

Re: Immich 3.0

#262

Immich is such a no-brainer replacement for Apple Photos or Google Photos, combined with VPN like Tailscale, it's almost a drop in replacement

Beware that migrating back from Immich to iCloud/Google is not something Immich cares about. There is no "download all" anywhere, best way is to go to the server and get raw files from there. https://github.com/immich-app/immich/discussions/14365

I put all my files in a folder. I’d simply get them there. No concern about this at all.

Re: Immich 3.0

#263

Earlier quoted context omitted.

If you don’t want self-hosted and you want E2EE, Ente Photos is the best solution on the market that I have found.

Thank you for the tip! Luckily there are some useful and thoughtful commenters on HN too, other than all the downvotes and negativity :-) Apparently HN does not like "not self hosting" and/or "e2e encryption" ? Meanwhile, i also found https://zeitkapsl.eu/

Thanks for the other recommendation, it doesn’t hurt to know of more of them.

Re: Immich 3.0

#264
Shameless plug: I made a native iOS/Mac app that's adjacent to Immich, but narrower in scope. It focuses on local image search and photo organization.

Everything is indexed and searched locally, so the photos never leave the device.

https://photos.getsupercurate.com

Re: Immich 3.0

#265

Earlier quoted context omitted.

I use and like Ente Photos a lot but I’ve never understood the appeal of their other products. Ente Auth and Locker both seem like limited feature subsets of solutions like 1Password.

Ente auth is a really nice secure and private cloud authenticator. It's completely free and there's no lock in, so I suppose it's for getting more people hearing the name. Haven't tried locker but I agree it seemed rather pointless. People say not to use your pw manager for authenticator for security, so that's something for using a separate app. Depends if your using auth for just getting through or actually want th…

I guess the free-ness of auth and I think locker is included with any photos subscription so maybe that’s the appeal.

Maybe it’s bad practice but I don’t mind 2FA being in 1Password because the secret key is the second form of authentication. Nobody can login to my 1Password without the secret key or access to a logged-in device. My credentials can be compromised and it wouldn’t matter.

The secret key is not technically “something you have” but it’s close enough for me.

Re: Immich 3.0

#266
post #161

An incredible piece of software, on par with Google Photos. I've been using it behind Tailscale for months with no problems ever since I first got into homelabbing. Actually, moving from Google Photos to Immich after I hit my 100GB storage limit was the whole reason I got into self-hosting, and what a fun ride that has been! I can't believe self-hosted products of this caliber are free. Huge shout-out to HomeAssistan…

I would like to replace iCloud but it doesn't seem to sync changes/deletions with iPhone yet. I don't want to have to make changes/deletions in two places every time. v3 seems to have improved background uploads which is great as that has been a frequent complaint.

Re: Immich 3.0

#267
post #242

Earlier quoted context omitted.

This is only true if you are so highly individualistic you don’t consider a family unit as a single entity. If you consider nuclear family as an entity, it’s e2ee. Practically. Putting aside the fact that yes, the server can be compromised if somebody chose to attach to the live RAM and recover keys. But practically, nobody will. Same way Google will not deliver a special compromised image of the mobile app on my pho…

It's a definition question. E2ee means in this cases that "the server" cannot decipher the data: the keys to that are only on the client and never shared with the server. This setup simply does fit the definition. And trying to say it is "e2ee practically" is a bit dishonest: there is no definition for "practical e2ee". The point of e2ee is that you do not have to trust the server (see Bitwarden for instance).

I think that is a bit stretch.

Let's see e.g. Wikipedia:

> End-to-end encryption (E2EE) is a method of implementing a secure communication system where only the sender and intended recipient can read the messages

It is only about the sender and intended recipient. In this case, if they actually would self-host, the server and sending devices are in the same entity group and it is encrypted where it matters. In the case of Hetzner, it is not, because Hetzner can access the machines as they are not in the sender's or receivers basement.

But there are some other benefits with E2EE if going strictly with "client-to-client" model - if server is compromised by the bug, there is higher chance that then data gets stolen as plaintext.

Re: Immich 3.0

#268
post #241

Earlier quoted context omitted.

I do happen to have some experience. For 99.99% of the population, does the threat model really include targeted NSA attack with higher probability than „Google’s automated system sent the police to my door“? No, no it doesn’t. It is demonstrably more secure for even a semi experienced sysop to host Immich for their family than for them to use Google/Apple. But I do agree that _some_ experience is required.

Hetzner has fewer employees I guess, but since your photos are decrypted there, you have basically the same problem.

In memory. If the police shows up and they disconnect my server to sieze it, for example, the photos are lost to them.

And the Hetzner employee would need to specifically target me, because I doubt they would implement a dragnet that pierces through the bespoke random process on my bare metal server to scan the photos in memory.

That is a lot more secure than „Google scans all pictures routinely and fully automatically sends the police to your door, and you have no recourse if they are wrong“ that the EFF article discussed.

Re: Immich 3.0

#269

So many comments here about missing end to end encryption, but seriously - why would anyone want this? Lets say burglars break in and steal your homelab. Because you don't have e2ee, they can see all the photos you saved of your dead grandmother! Oh no! Or, in the more likely scenario that something happens to your phone, the lack of e2ee means that even if you lost your keys you didn't lose the only memories that re…

I want to host an instance for me and my family. Right now we have a Google One instance shared by 5 people. Having e2e means my family members can rest assured that I or whoever I share admin rights with cannot look at their private photos. It's an important enough feature even without thinking about 3rd party bad actors.

Re: Immich 3.0

#270
post #267

Earlier quoted context omitted.

It's a definition question. E2ee means in this cases that "the server" cannot decipher the data: the keys to that are only on the client and never shared with the server. This setup simply does fit the definition. And trying to say it is "e2ee practically" is a bit dishonest: there is no definition for "practical e2ee". The point of e2ee is that you do not have to trust the server (see Bitwarden for instance).

I think that is a bit stretch. Let's see e.g. Wikipedia: > End-to-end encryption (E2EE) is a method of implementing a secure communication system where only the sender and intended recipient can read the messages It is only about the sender and intended recipient. In this case, if they actually would self-host, the server and sending devices are in the same entity group and it is encrypted where it matters. In the ca…

True. But the server is not completely unprotected even if not stored in my basement.

The disks are fully encrypted, so the attacker must be careful not to accidentally interrupt power or force a reboot.

And they can’t just log into the machine, it is still a normal Linux machine with passwords.

So they need to attach to a running system and actively hack it, which is completely possible but is not going to be done by a random employee for no reason.

Post reply on HN