Reading with interest.
Right now, I’m oldschool. My life’s photo collection is on a “good old fashioned hard drive at home” (backed up to iDrive with E2EE, however) under a folder called “Photos” and I’m not sure I’m even ready to bust out the cuppa and the “Change my mind” table about it. It’s nice and simple and I don’t have to fill in a data request to move it elsewhere. The camera roll on my phone is temporary - every so often I group it all into albums and extract it out onto the hard drive. iCloud Photo Library is on but I might knock it off once I have a better transfer system - we don’t have ADP in this country and although I have nothing illegal, I don’t feel it’s anyone’s business to just routinely scan my photos without a warrant.
Said hard drive isn’t even encrypted at all, it’s a USB drive I leave plugged into my Mac Mini which is sort of doubling as a NAS. There’s method in the madness - if something happens to me, my family can unplug the drive, plug it into theirs and enjoy the memories without any encryption hurdles, “legacy contact” systems etc. (I don’t put spicy pics there, I wouldn’t wish that sight on my family, lol).
What software I use boils down to how I want to browse and organise it beyond the filesystem structure, and to introduce some carefully managed remote access.
Weighing up the risks of not having my photo library encrypted at rest in my own home - yes my photos mean a lot and tell a big story… to me and my family. I’m not a person of interest, I’m very boring. If we got burgled, I’d have much bigger worries than someone snooping through my holiday reels and random phone pics. Probably the biggest risk is stealer malware but let’s be honest it’s more likely to target crypto wallets, Discord, etc. And in most scenarios I can think of, by the time you’re into my computer with a good enough stealer you already won the jackpot, got all my local documents etc and if the library were encrypted, the decryption key would be in RAM anyway because I would want to leave it open.
So that brings us to remote access. I just connect in with Tailscale. That is already an encrypted tunnel. (I mean sure, port forwarding in the year 2026 would be begging to have your shit hacked and stolen). The only downside to Tailscale is it knocks VPN off (on iOS anyway), but I can live with that. So I’m thinking that additional E2EE is unnecessary for my use case.
I just installed PhotoPrism a few days ago - so not settled yet - and it’s indexed my existing photos folder. All good aside from how it can’t tell the difference between a dog and a horse, but seeing how they’re handling monetisation has me concerned that they’ll shift more features behind the paywall so that’s got me looking at Immich now so that I don’t have the pain of migration later. I feel that if Immich had been listed on this site, I’d probably have gone for it from the outset rather than possibly wasting time with PhotoPrism.
Buuut that’s my specific setup and threat profile. I can see how it’s hard to recommend to the average Joe who never backs anything up and wouldn’t know WTF a Tailscale is. I wish it were more accessible as I still find it insane that most of the world nowadays uploads their entire lives to the cloud, E2EE or not. I mean there’s the hosting cost as well especially if you like shooting in RAW.