In our journey to #DigitalSovereignty, here's where we are:

- Domain registration: TransIP and Prolocation 🇳🇱
- Email, calendar, collaborative writing, and more: mailbox.org 🇩🇪
- Document store: Tresorit 🇨🇭
- Critical infra hosting: Hetzner 🇩🇪
- Discourse hosting: Communiteq 🇳🇱
- Security: 1Password.eu 🇨🇦/🇪🇺 and Yubico 🇸🇪

Next up: GitHub —> Codeberg 🇩🇪

To-do: Slack —> Zulip, Matrix, Mattermost?

#OpenSource #DNS #BGP

Als Antwort auf NLnet Labs

We’re definitely not completely without a hyperscaler dependency though:
Unlike our C projects Unbound, NSD, ldns that are distro packaged ❤️, our Rust projects are not yet in all distros (✅ Fedora, FreeBSD ❌ Debian)
So years back we decided to offer packages as a convenience. The repository hosting .deb and .rpm packages for our Rust software today uses AWS Cloudfront 🇺🇸 (with a standby at Hetzner).
Uptime and cost are important factors. Talk to us if you feel you can make a difference.
Als Antwort auf NLnet Labs

The alternative that is on my list for Cloudfront is bunny.net, except that, like many non-US service providers, they have their own hyperscaler dependencies, such as Google Apps for email.

Also, unless something has changed fairly recently, 1Password depends entirely on AWS for all of their products and services, Google Apps for email, and so forth.

Tresorit seems to be all-in on Azure and M365. Communiteq seems to be running on Cloudflare + Digital Ocean.

So if this is anything more than a PR exercise, you will probably need to do a bit more work 😄

Als Antwort auf JP Mens

@jpmens we are happy users of DNS-OARC’s Mattermost.

On self-hosting, we’ve actually tried to consciously decrease our ops work. Were we find dependable hosted alternatives without lock-in, we prefer to spend our time developing open standards and open source software and let operators do what they do best, operate infrastructure for us.

Not there yet. It’ll be a great day when our ops work is mostly for our research projects.

Als Antwort auf ArneBab

Something I’d wish to see more: sharing mid-sized¹ documents via Freenet / Hyphanet.

It is unexpectedly liberating to be able to just upload a document locally and know that the key you get can be downloaded by someone else while being invisible to other people on the network, so there’s no privacy risk.

¹ 10MiB to 200 MiB, larger is possible but takes too long to upload.

Als Antwort auf Hans de Graaff

@graaff Given the amount of people we have and services we depend on, this is all handled per service. Personal and shared credentials are handled in 1Password. For critical credentials and software signing we have a Yubikey-based process.

"Fun” fact: our security posture is pretty strong, but we don’t have a formally documented and verified process and thus no ISO27001 certification. This is becoming increasingly problematic dealing with (potential) customers. #DigitalSovereignty #OpenSource

Als Antwort auf NLnet Labs

you don't want to go with Mattermost, at least not, if you intend to use the Open Source version.
mastodon.social/@antondollmaie…
Als Antwort auf LΞX/NØVΛ 🇪🇺

@lexinova @nextcloud To be fair, we have also ‘thought about it' for a long time. The ongoing AI enshitification has accelerated this process though.

Yet, reworking our extensive use of GitHub Actions and achieving feature parity for all the runners on our various platforms only became viable recently. See this post for context hachyderm.io/@alexband/1159615…

#DigitalSovereignty #AIslop #OpenSource

Als Antwort auf NLnet Labs

I like the list, really nice.

For DNS and domain registration, have you checked out DeSec 🇩🇪? I use them for quite a while and I am very happy.

Also, for Hardware security keys, ... I know Yubikeys are the most promoted ones. But check out Token2 🇨🇭. They support all the fido2 features with 300 passkeys, openpgp, totp, .... And the price is nearly half of a Yubikey.

* blog.tinned-software.net/frame…

* blog.tinned-software.net/fido2…

Als Antwort auf NLnet Labs

I've heard stories with Hetzner dat you can just lose your access and data because of "terms violations" with no option to resolve. And, for my liking way too active on the US market, so I just wouldn't trust them and absolutely not feel happy to be dependent on them.

They are big, but just too big in America!
They may be Germany based, but they have way to much interests in America.

Als Antwort auf Angela Scholder

@Angela Scholder @NLnet Labs
"I've heard stories with Hetzner" sounds like rumors unless there are sources.
An internetbusiness with big interessts in America in a connected world? No way!
Of course. Unfortunally the US ist the most mighty player in this Internetgame.
For example: en.wikipedia.org/wiki/ICANN
Als Antwort auf Stefan Rower🏴‍☠️🦊 🇺🇳🐧 🏳️‍🌈🤝

@stefanrower Well, as it is individuals from whom I heard their experience I'm not going to divulge their names.
So, yes, it's rumours. Do with the info what you want, but unless you have absulute proof and good experiences with a company, I wouldn't stand up in their defence!
Certainly a really big company like this.
Dieser Beitrag wurde bearbeitet. (9 Stunden her)
Als Antwort auf Angela Scholder

@Angela Scholder @NLnet Labs
I'm using Hetzner since 2028 as partner for my private ans business things.
Domains, Servers, Hostings and so on. There where many problems but everytime a solution an (technical) supporting people willing to help.
If this is not a proof, I don't know what else.

So I stand up to "defend" a businesspartner of mine against rumors that might be true. If they are, that could be a story worth in computer magazines with protecting the customers identity. No one want to dox someone here. And this is what I mean when I'm asking for sources.

Als Antwort auf Angela Scholder

@Angela Scholder @NLnet Labs
Well, no! In my understanding, spreading rumors without source is some kind of attack on a business. I try to clear the situation with my questions and know here we are. You, the one that tries to spread rumors and damage the business, tries also made me the one wich behavior is unappropriated. Whoopsi!
But it is a recurring pattern in our bubble. We are all against BigTechFascistBros in the US. But fighting against each other.
Starting discussions about ... we would say in germany "klein klein" ... little aspects and making succesfull businesses in EU looking bad. Because every successfull business has to be bad. THIS is why we can't win against the US oligarchs. I will not give up.