Is running your own server actually safe?
Is running your own apps less secure than using a big provider? A straight answer on where you're safer, where you're worse off, and why.
It’s a fair worry, and it deserves a straight answer, not reassurance. Big providers do employ people whose whole job is security, and you’re one person with a weekend. But that comparison assumes both are open to the internet in the same way, and they don’t have to be.
Published, or not
Almost everything you use every day is published. It has a public address, a front door anyone can walk up to, and it’s under constant automated attack. Not because anyone cares about you, but because software scans the whole internet all day looking for doors that happen to open. Think of it as the weather: always there, not personal, something you prepare for.
A published service has to be defended all the time. Fixed the day a flaw is announced, watched, kept up to date. That’s real, costly work, and it’s exactly why big providers hire whole teams to do it.
The other option is not to publish at all.
published to the internet
Anyone can knock
It has a public address, and software checks every address on the internet all day, looking for doors that open.
It must be defended all the time
Fixed the day a flaw is announced, and watched in between.
Every day without a fix counts
Because nobody has to be interested in you for it to be found.
reachable only over a private link
There is no door to knock on
Nothing answers at a public address, because nothing is published at one.
You join the network first
Then everything behind it is open to you, and to nobody else.
Scanning finds nothing
A scanner can't find what was never published.
A service you can only reach over a private, encrypted link has no public front door. There’s nothing at a public address for a scanner to stumble on. As far as the internet is concerned, it doesn’t exist. You get to it by joining the private network first. It’s the same private-tunnel idea as in what a VPN does and doesn’t hide.
Big organisations call this “zero trust”: nothing can be reached just because it’s on the network, and every connection has to prove who it is. At home it’s simpler. One tunnel in, and everything behind it.
Where you come out ahead
You’re a much smaller target. Attacks on big providers are worth huge effort, because one break-in can leak millions of accounts. Your household isn’t worth anyone’s afternoon. Almost all the danger out there is automated and random, and automated tools only find what’s published.
There’s no risk from staff, and not because you’re a saint. There simply are no staff. Nobody has support access, and nobody can be talked into resetting your password. Tricking staff like this (“social engineering”) is one of the most common ways big accounts get broken into, and it needs a person to trick.
When a big service is breached, everyone on it is caught up. You aren’t on it. And a lot of real-world account theft comes through the “forgot my password” process: a stolen phone number, or a support agent talked round. With no one handling password resets, there’s nobody to fool.
Where you come off worse
The updates are your job now. Flaws turn up in software, fixes get released, and someone has to install them. That someone is you, and it’s the biggest single risk of running your own. It’s more about habit than technical skill.
Nobody watches your setup for you at three in the morning. Nothing warns you about odd behaviour. And one careless move can undo everything. Opening something to the internet “just for a minute” so it works from your phone puts you straight back out in the weather, and it’s very easy to leave it like that.
Backups are all on you as well. The most likely way to lose your data at home isn’t an attacker at all. It’s a dead disk and no second copy.
So, is it safe?
Running your own isn’t automatically safer. Running your own without publishing it usually is, because that removes the kind of threat most attacks belong to.
What really happens is that the risks change. You swap “a company I rely on gets breached, or one of its staff is careless” for “I forget an update, or I skip a backup”. The second list is shorter, and it’s in your hands, which is what most people want. But it’s only shorter if you do the boring parts.
Three things cover nearly all of it:
- Don’t publish what doesn’t need publishing. Reach private services through a tunnel. If you take one thing from this, take that.
- Update on a schedule you’ll actually keep. Monthly and done beats weekly and abandoned.
- Keep a backup somewhere else. The disk will fail one day. They all do.
If you’d like to see this set out in practice, here’s how the network here is put together and what it does and doesn’t protect against.