If I self-host https dav, do I really need to use E2EE?

Operating system

Linux

Joplin version

13.5.3

Sync target

WebDAV

Editor

Rich Text Editor

What issue do you have?

I can see how E2EE is useful for people who are on OneDrive or another cloud service where you may have ‘snoopers’. If I have my own https server with https WebDAV and sync only to that target, do I need to have E2EE? Persona preference at that point? I assume if I enabled E2EE then this would disable someone from reading my notes if they gained access to my WebDAV server..

Where is the server located? E2EE gives you another layer of security but it's indeed less necessary if for example the server is located in your house and you only connect to it over VPN

Server is home but I also connect to it while outside of home network via https WebDAV but with no vpn (over isp). What do you think?

Personally I would activate it because it doesn't cost much to do so in terms of performance or space, and it's an extra layer of security. It would protect your data for example if someone hacks into your server.

But it is indeed less important than when the data is hosted on a third-party server, because in this case someone else has access to the data too.

1 Like