• 1 Post
  • 10 Comments
Joined 27 days ago
cake
Cake day: June 26th, 2026

help-circle
  • I do understand and share people’s hatred of corporate-owned, centralised cloud AI.

    I understand (though share to a lesser degree) people’s ethical concerns about how these models were trained (copyright has been broken for a while now, this just exacerbates it).

    But this level of outrage about using local models on an opt-in basis strikes me as hysterical.

    Feel free to change my mind.


  • I’ve seen Immich mentioned around here before, but I’ve honestly never set up even a real homelab or sever before, so that’s a bit daunting.

    I haven’t been in this space for too long either, but immich is what brought me here. I tried it out locally - no deecated server, just spun up immich on my desktop machine to try it out. And it was just so good it made me want to have a server and learn the ropes.

    I’d recommend you try it out this way too. We’ll see each other on the other side of that rabbit hole. ;)








  • Thank you! While that does allay most security concerns, it does beg the question how useful such a vulnerability tracker is if it doesn’t actually show any relevant vulnerabilies and you constantly have to second-guess what it says. Warning signs that aren’t actually warnings because it’s “just a false alarm” quickly teach personell to not take warnings seriously - unti, onel day, it’s not a false alarm…


  • Thanks for your detailed reply!

    To make that happen, the attacker must […] already have access to the server to upload and process the file, which means that security has already failed.

    Do I correctly assume that by axis you mean shell or even root level access? If not, any of my regular users (turned rogue…) could upload a poisoned raw file which nextcloud would process to, for instance, generate a thumbnail.