End to end encryption nextcloud

Hello,

I am new to nextcloud. I have a managed instance via Hetzner storageshare. I use it to sync my phone pictures on the instantupload folders, and for 2 way sinc of my laptop files via the nextcloud client.

My objective is to keep my data secure and private.

I installed the nextcloud end to end app, enabled it on my phone and laptop and saved the mnemonic. I realized, it is written in the doc “Encryption must be actively enabled for folders”. However from my tests, if I do this I can’t see as easily access the files on both my devices, I would always need to type the mnemonic which is not convenient and also I am not sure apps like memories or recognize would still work. I saw there is also the folder encryption for another layer of seurity.

So what is the best way to keep my data private? I saw there was a default security in transit, is that sufficient? Is there some warnings signs to having just that one and keeping the my content on the cloud in clear (aka not encrypted)?

I am also open to any suggestions and advice that could enhance my security on my sharedstorage.

So I imagine that it’s actually enabled by just installing the app, I guess then you just have the default secure encryption in transit offered by nextcloud and hetzner but that particular nextcloud app is not doing anything

It depends on your threat model.

Who do you want to keep the photos secret from?

  • From everyone except Hetzner: Encryption in transit is sufficient.
  • From everyone: E2E is necessary.

(I don’t use Nextcloud’s E2E, so I can’t say much about it. I just want to point out that there are also alternatives, like cryptomator, but I don’t have any experience with them either.)

this any other server-side processing like online office will stop working. with e2e encryption your cloud becomes dumb storage.. same applies to cryptomator and any other client-side encryption.

2 Likes

This topic was automatically closed 8 days after the last reply. New replies are no longer allowed.