• 1 Post
  • 15 Comments
Joined 1 month ago
cake
Cake day: June 26th, 2026

help-circle
  • Personally I would absolutely not want to ever feed my documents into an off-device model, but the point of self-hosted software is that it does what you tell it to and they absolutely should include letting you make bad decisions. decide what’s right for you.

    FTFY (although I share your judgment). No disagreement about the rest.



  • Long-time immich user here, similar problem. The issue (for now) is that only the owner of the media has write access. With partner sharing, all you can do is read the media (and add them to albums).

    What I do for now with “trash media” (e.g. photos of receipts and other stuff that one snaps pics of for practical reasons and then forgets): I add my partner’s trash to an album named “please delete”. I periodically ask them to go through it and remove anything they want to keep, then have them select and delete everything in that album in batch.

    Why this may not be practical for you, OP: you have two “trash producers”, so you’d have to keep a “trash” album for each of them (and sort trash media correctly). This is tedious work and error-prone: if you have only one pic in you “trash” album that your account does not own, selecting and deleting everything will fail, sending you on a hunt for the one misclassified picture in a batch of >200…

    What immich may do about this in the future, as according to their roadmap: in the past, they were planning to add “more granular permissions controls”. Right now, they’ve renamed that to

    User groups: Manage groups of users and share albums with a group

    I hope this will include permissions management as well.

    Wither way, the feature is likely to come with a greater overhaul of partner sharing. Partner sharing, as of now, is partly “broken” due to past design decisions: you can’t

    • write to your partner’s files
    • share facial recognition data: each one needs to classify people in their pictures individually (e.g. both need to tag “Uncle Fred” individually in their own accounts)
    • share memories: only pictures owned by you will show up in memories, not your partner’s

    And before anybody asks: no, there’s no ETA…

    Soon




  • _Nemo_@lemmy.mltoSelfhosted@lemmy.world[AIT] paperless-ngx 3.0.0
    link
    fedilink
    English
    arrow-up
    38
    arrow-down
    1
    ·
    5 days ago

    I do understand and share people’s hatred of corporate-owned, centralised cloud AI.

    I understand (though share to a lesser degree) people’s ethical concerns about how these models were trained (copyright has been broken for a while now, this just exacerbates it).

    But this level of outrage about using local models on an opt-in basis strikes me as hysterical.

    Feel free to change my mind.









  • Thank you! While that does allay most security concerns, it does beg the question how useful such a vulnerability tracker is if it doesn’t actually show any relevant vulnerabilies and you constantly have to second-guess what it says. Warning signs that aren’t actually warnings because it’s “just a false alarm” quickly teach personell to not take warnings seriously - unti, onel day, it’s not a false alarm…


  • Thanks for your detailed reply!

    To make that happen, the attacker must […] already have access to the server to upload and process the file, which means that security has already failed.

    Do I correctly assume that by axis you mean shell or even root level access? If not, any of my regular users (turned rogue…) could upload a poisoned raw file which nextcloud would process to, for instance, generate a thumbnail.