|
|
|
|
|
by bigiain
4707 days ago
|
|
Self signed certs, along with the handholding required to get your intended users to install them on their devices (probably not too big a deal for a tech crowd - perhaps not something I'd jump at for a "family and friends" targeted system). At that level of paranoia – I'd question the appropriateness of relying on a "cloud VM". If you're worried about compromised CAs, perhaps a RaspberryPi (or similar inexpensive device) on your home net connection - with a write-locked SD card to boot from and a usb drive mounted with no-exec - and firewalled up the wazoo. Who knows how many guys have Snowden-like access to the VM hypervisor at n-random cloud hosting provider? Inside your "server", all the cleartext and metadata is readily available to root, and to root on the hypervisor as well. |
|