My son was just born, and while a few photos will go on the likes of Facebook and Instagram, overall my partner and I are wanting to keep our shared photos private from the EULA abuses that we all know and hate.
Does anyone here have any good suggestions? I would create my own front end, but I can’t swing hosting or a static IP to do it from my local box. Are there any companies out there who aren’t total shit bags who claim immediate irrevocable license to all of my photos to do with whatever the fuck they please?
Haven’t tried it myself but https://ente.io/ seems to be pretty decent
Been a customer for half a year here now and it is such a good service! Easily worth the cost. Highly recommend checking out there website to go through their feature set, their level of transparency is beyond good 🙌
If you and your partner both have iphones then iCloud should be sufficient for keeping the photos to yourselves if you turn on Advanced Data Protection. I think it requires you and your partner to have two yubikeys at a minimum though.
https://support.apple.com/guide/security/advanced-data-protection-for-icloud-sec973254c5f
Photos encrypted at rest, only you and your partner will have access to the keys. If you want the convenience of icloud backup then the government would be able to subpoena your decryption keys from your phone backups, but it’s not going to be available for casual employee access. Automated tagging/face matching is done by your iPhone when it’s plugged in so there’s some organization. Nothing close to Google’s AI organization.
I know Apple is a shit company. But they’ve learned a thing or two after the Fappening.
Advanced Data Protection should be the minimum setting for you to consider Apple as your photo storage. Your photos will auto upload from your phones, apple has partner sharing so photo libraries will automatically be shared between you and your partner, and they recently implemented a system similar to “signal key verification”, but again limited to ADP turned on.
Otherwise you’re looking at Proton or Tresorit.
I will happily look at the alternatives. We avoid Apple like it carries the plague, mostly on my objections to their licensing policies alone. Also, I love that you linked to something about The Fappening, have a 💯 and my heartiest appreciation for you as a scholar and a gentleman.
Syncthing
It can become really messy if one family member deletes a picture by accident and everyone complains. I’d use Syncthing for machines I personally manage.
You can control which devices can make and propagate changes to shared folders.
I self-host Photoprism, and use it to share albums privately with people.
The flow goes:
- I take pictures with my phone
- Those get synced via Syncthing to my photos folder.
- Photoprism is set up via docker, with my photos folder added.
This has potential in many ways. I will have to set it up and see how it feels.
Seafile?
This could be a good option. I will have to look into it. I know some of our family is not the most savvy (lucky to be able to use FB) so I may have to look into building a front end on top of it for them, but this is a solid start.
Good luck mate…
Maybe don’t share online?
We have a printing center in my area that prints high quality full color photos for 75 cents a page.
Photo development booths, printing centres and later phone repair shops (before phones regularly got encrypted) used to be the number one avenue for getting photos leaked.
As true as that is, we’re talking about photos of a newborn infant. Like for real, who would intentionally leak photos of a newborn?
Oh yeah, that’s right, artificial intelligence!
Don’t feed the online machine, take the photos into a print shop via USB flash drive, and I’m pretty sure anyone with a soul will have respect for family privacy.
Not so with online cloud services though ☹️
I know you said you can’t do your local box, but there’s no necessity for a static IP to do that. Dynamic DNS is relatively easy to set up, I suppose provided you have a domain name you own (which you can find for very reasonable prices).
Dynamic DNS only works if your IP is publicly routable. My ISP (not sure about OP) puts us behind NAT, so the only way to expose services on my network is through a tunnel, like a VPN.
But many ISPs do provide a routable IP. My last ISP did, so it’s not uncommon.
And you don’t necessarily need to own an IP, services like FreeDNS let you use a subdomain from someone else, but a domain can be as little as $1/year (for TLDs like .site and .store), so it’s probably better to just get one. I have like 10 domains, and they only cost $10/year each or so. But if you just want to try out hosting something, using someone else’s isn’t a bad way to go.
Or setup Tailscale and enable the Funnel feature for whatever service you want to expose.
This way it’s a bit more secure, since the exposed endpoint is hosted by Tailscale and routed to your device via your Tailscale (encrypted) network.
Using Funnel, no one needs to have the Tailscale client.
Store them in an s3 bucket or put them in a gh-pages repo.
Any way to get a gallery browse and light box viewer?
While self hosted will obviously be better, you have to balance that with simplicity for non tech users.
We use the paid app tinybeans. Doing it now, I’d consider hosting a stability photos folder.
Best guess would be a privacy focused chat app like Signal or Matrix.
Otherwise you may want to look at crypto bases file storage ala Filecoin or potentially even Pixelfed
I do:
- own domain with cloudflare
- ddns with their API
- NextCloud in docker
- caddy reverse proxy takes care of SSL cert
Or:
- Plex can do photos too and they have a docker container
- invite family to your server
Or:
- Immich with same setup as NextCloud
Could set up a nextcloud instance, but might be a bit overkill for your use case as it is a full Google workspace replacement
I use DokuWiki for this type of thing. With a few add-ons it is nicely configurable (galleries, discussions etc), could be run from any webspace, and doesn’t need a database. You can have ACLs that make sure that only registered users get access. But it is a bit of a DIY solution, and takes a bit of work to set up.
I’m not above getting my hands dirty and this sounds like it could have promise. Thank you.
Immich if you selfhost
This is the way, immich is insanely fast and performant
Does it support SSO with OIDC?
Yes, have it running right now!
Proton offers a cloud photo storage similar to Googles but its all E2EE. A bit clunky compared to google but much more privacy friendly.
Proton
What is this photo storage thing? All I can find is proton drive.
Its part of proton drive. Drive has a section for photos.
Mega is e2ee and much cheaper
Mega doesn’t come with VPN, encrypted email and PW manager with integrated simplemail that ties in to your proton mail.
Different levels of service of course costs different amounts. If you don’t want or need any of the other things, then yeah Mega could be the best option for you.
Does come with vpn though https://mega.io/vpn
Pw manager bitwarden works great.
Proton mail is great but doesn’t really come with much usable cloud storage
Ah fair enough, didn’t know they also had a VPN service.
Does bitwarden integrate with something like simplemail to create unique addresses on the fly for accounts you create? That’s the feature I like the most about protons PW manager. I can easily just create a new mail address for an account somewhere that automatically forwards to my proton mail, but I can also answer with that unique mail from my proton mail.
I don’t use my mail for storage, and santiize content often, so I only need a few mb.
The 500gb on the drive is more than enough for my photo backup. There’s almost 10 years worth of photos on mine and I still have plenty space left.
it’s small though.