Discussion summary

Discussions around Immich 3.0 highlight concerns about management, encryption, and alternatives for photo storage. Some favor self-hosted solutions, while others prefer cloud options or VPN tunneling.

What the discussion says

  • Self-hosting can be manageable with backups and energy considerations.
  • End-to-end encryption is a concern; some suggest encrypting data manually.
  • Cloud providers like Google Photos and iCloud are alternatives.
  • Tools like Ente Photos offer E2EE solutions.
  • VPN tunnels can provide secure access to self-hosted services.
“Immich is not end-to-end encrypted.”
— FabCH
“System administration is easier now with LLMs.”
— amelius

Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • There's a lot of things I spent a ton of time setting up, use once, and then never again. Tons of things that are easy to set up, and provide small benefits every day for a long time. Immich has got to be the thing that I've spent ages setting up, use extremely infrequently but the one time a year I use it I'm so happy I did. Great software.
  • Immich is such a no-brainer replacement for Apple Photos or Google Photos, combined with VPN like Tailscale, it's almost a drop in replacement
  • When I was switching to GrapheneOS from iOS, I decided to self host my photos. I considered Immich, but I settled on Ente because of the encryption. Ente Photos is extremely polished and it's comparable quality to Apple photos.

    It's cool they keep the server open and selfhostable instead of only open clients like many e2ee projects do.

    I like how you can share an album and anyone can contribute to it without an account. Another cool feature is that you can select photos to lock when you hand your phone to somebody so they can only see the ones you selected without your device unlock.

  • So many comments here about missing end to end encryption, but seriously - why would anyone want this?

    Lets say burglars break in and steal your homelab. Because you don't have e2ee, they can see all the photos you saved of your dead grandmother! Oh no!

    Or, in the more likely scenario that something happens to your phone, the lack of e2ee means that even if you lost your keys you didn't lose the only memories that remain of your grandma - you just copy across the .jpgs to a new device.

  • A lot of people talking about encryption in the comment section, thought I would share my setup. I have been running Immich for family and friends on a Hetzner auction server for about 1.5 years now.

    Hetzner community provides official full-disk encryption documentation:

    https://community.hetzner.com/tutorials/install-debian-with-...

    Letsencrypt gives free reliable SSL. You can easily hide Immich behind Nginx proxy that handles SSL for you.

    Add cron based automated backup of the entire Immich data to a local encrypted NAS and there you go. Reliable, end-to-end, encrypted at rest setup. So far, it required exactly 0 maintenance.

    It’s also more secure because I just drop traffic from all but 3 geographies at the IP level. And you can also add a WAP on the Nginx proxy.

    It is also more more secure than Google/iCloude because the „employee of the company“ attack vector is much smaller. It’s documented that Google looks at your photos and is perfectly happy to file false police reports: https://www.eff.org/deeplinks/2022/08/googles-scans-private-...

    By comparison, yes it is theoretically possible for Hetzner employees to access my server physically and extract the encryption key from RAM, or setup a fake SSH server to try to steal the key, but that is far more complicated attack and hasn’t been documented yet. And it risks detection.

  • An incredible piece of software, on par with Google Photos. I've been using it behind Tailscale for months with no problems ever since I first got into homelabbing.

    Actually, moving from Google Photos to Immich after I hit my 100GB storage limit was the whole reason I got into self-hosting, and what a fun ride that has been!

    I can't believe self-hosted products of this caliber are free. Huge shout-out to HomeAssistant, PiHole, paperless-ngx, Dawarich, and countless others for the same reason.

    Congrats to the team on the release and thank you for helping me catalogue my personal memories

  • I teach a free software development course to my undergrad students. It's really exciting to stumble upon one of the work they did for my class in the wild (it's the first listed bug fix — which is the last of the three pull requests this student got merged in Immich during my course). I feel so proud! :)
  • > Welcome to Immich v3.0.0!

    > After months of hard work from the team and our amazing contributors, we're thrilled to announce the next major version of Immich: v3.0.0!

    A quite amazing open source project, that COMPLETELY FAILS to explain to a newcomer what it is, what problem it solves, etc.

Explore Birbla archives