this post was submitted on 26 Apr 2026
160 points (97.6% liked)

Selfhosted

62377 readers
660 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] panda_abyss@lemmy.ca 2 points 5 months ago (1 children)

Rustfs is sketchy as fuck though.

[–] hendrik@palaver.p3x.de 1 points 5 months ago (1 children)

Thanks for pointing it out. Yeah it does. I just copy-pasted what I found and didn't check.

[–] panda_abyss@lemmy.ca 2 points 5 months ago (1 children)

For posterity because I didn’t explain why/how it’s sketchy:

  • they just found a hardcoded key that skips all security that was in the wild for like two years
  • significant vibe coding means nobody actually understands the codebase. Hence not finding the backdoor key
  • some of the documentation is only in Chinese, which isn’t sketchy in itself, but given the backdoor key does seem fucking sketchy.
  • they have an X link you cannot remove from the admin console
  • the admin console has minor but stupid bugs: you can’t go from a bucket to the list of buckets, auth is janky, etc.

Just because it’s good a good name doesn’t make it good pedigree (which is a bone I have with rustXYZ named projects). The fact nobody caught serious backdoors for years is damning.

If you’re running this offline, it might be fine for you. I still run it inside my vpn behind auth but I’m looking to move off.

[–] hendrik@palaver.p3x.de 1 points 5 months ago

Thx very much. That's valuable info. I edited my comment and crossed it off my list of software to evaluate for future projects. I already got the vibe-coding and a bit of sketchiness by scrolling through the latest commits and issue tracker.