How are y’all handling encryption in Nextcloud?
From my research (and understanding, corrections/nuance appreciated):
• Server side is best for files stored off of your server (to keep them from being leaked from third party services) and if someone gains access to your server, it is trivial to far from impossible to decrypt the data—I’m noticing some discrepancy in descriptions of how this seems to work.
• E2EE offers the most security, but you lose that fun collaborative editing experience.
• OS/disk-level encryption requires someone to put in the password if the server restarts (I’m aware of Yubikeys, but that becomes a physical security issue), otherwise, it might not be much better than server side encryption.
| I have nothing to hide /s | |
| Server side encryption | |
| End-to-end encryption (E2EE) | |
| OS/disk-level encryption | |
| Something else (share in the replies) |


