Hacker News new | ask | show | jobs
by gexcolo 3808 days ago
"Mr. Canfield" here,

I don't know if I would say I was "trusting of authorities" but I'm definitely distrusting now. I didn't bother with FDE because I figured it was more trouble than it was worth for a server that I ultimately don't own and can't control or protect against the oodles of key recovery attacks I'd have to worry about. In the event of a seizure I don't want to be like "hey uh they might have gotten everything maybe not!" so it's just not something I bothered with.

The situation is different now though as the service is being colocated instead of hosted on a rented server, which gives me a lot more freedom what can be done to secure the server against data theft. I'm also hosting with a privacy-conscious host (FlokiNET) I know will cooperate with me and fight bullshit government requests if/when they arrive (not saying what happened with Germany is bullshit, it's yet to be seen and I've been advised not to speculate).

Data theft aside, the service is in a more secure position it's ever been in. There's comfort in that, at least...