this post was submitted on 28 Jun 2026
17 points (90.5% liked)

Selfhosted

60426 readers
405 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

This is an alternative to manually typing your password to decrypt your home server disks.

The idea is that you have a Tang server somewhere on your local network. When your server boots up, it needs to communicate with the Tang server to unlock the disk. Tang doesn't store the key and is stateless, but the client requires Tang's cooperation to compute the key.

For me, I'm thinking about someone breaking into my house and stealing my computer. Currently, I have LUKS read a keyfile from a USB drive... but I almost always leave it plugged in... so a thief would probably accidentally steal that too.

With this setup, I'm thinking maybe I could setup a Pi on the opposite side of my house, ideally hidden. And then if my home server gets stolen, LUKS wouldn't be able to reach my Tang server, and therefore not unlock anything.

you are viewing a single comment's thread
view the rest of the comments
[–] rumba@piefed.zip 1 points 6 days ago (1 children)

Not sure raidproof exists. If they get there and it's running, all they need is something that is already connected and can read it, so your surface area is huge. If they know you have things they need, and are aware you are technically competent, They're just going to disconnect network, leave it running and call in pros. Anything is probably enough to get past local LEO, but if the feds come in, they're going to get what they want unless you're rolling your own drivers.

[–] Natanox@discuss.tchncs.de 2 points 5 days ago

I was assuming devices being shut down. With running ones you're of course right, the lengths e.g. GrapheneOS has to go to secure these are insane.

With home devices you very much could make them shut down, which would of course be necessary. E.g. various deadman switches, physical and logical ones. It sucks how common people have to think about this shit by now… fucking fascists…