Hacker News new | ask | show | jobs
by jospoortvliet 3837 days ago
Self hosting does have this issue in general, yes. It is a bit harder to get at security vulnerabilities in ownCloud as was initially portrayed in the thread you mention (we publish CVE's 2 weeks after updates have hit the net, and these updates contain unmarked security updates).

Client side encryption is a great solution but you lose out on most of the benefits of the cloud.

Honestly, I don't know. I haven't seen any of such attacks but of course, with about 3 million users, ownCloud isn't a HUGE target. I just don't like the idea of giving up on self hosting ;-)

1 comments

I also wonder how successful such automated scanning attacks are against a simple login screen. Esp compared with the fact that on the big services people routinely call the helpdesk and manage to get passwords reset and all that so they get into accounts. That won't happen with your private ownCloud...

With regards to 'usability first' vs 'security first' approaches, this is what 'security first' gets you: https://twitter.com/davide_paltri/status/676696685456826368

I rest my case ;-)