With the stories about data from period tracking apps being shared with law enforcement, I was wondering if there was a self hosted alternative I could host for my daughter. My searches so far have not returned any good results. Thanks!

  • cooopsspace@infosec.pub
    link
    fedilink
    English
    arrow-up
    9
    ·
    edit-2
    1 year ago

    I’d probably just spin up a calendar such as one on Nextcloud but also change the name of the event to another plausible name such as:

    Pay day.
    Grandma coming to town.
    Grandma leaving town.
    Walk the cat.
    Pick up groceries.
    Collect mail.
    Drop off mail.

    • corroded@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 year ago

      As someone who uses Nextcloud, why do you suggest obfuscating the name of the calendar event? My nextcloud instance is only accessible from outside my LAN via HTTPS, so no concern about someone using a packet sniffer on public WiFi or something of that sort. The server is located on my property, so physical security isn’t a real concern unless someone breaks in with a USB drive or physically removes the server from the rack and steals it. If someone was to gain access to my network remotely, they’d still need login credentials for Nextcloud or for Proxmox in order to clone the VM drive.

      To be clear, I’m not disagreeing with you; I’m wondering if I may be over-estimating data security on my home network. Considering you’re posting from infosec.pub, I’m assuming you know more about this than I do.

      Also, I feel like I need to say that the fact that OP even needs to consider data security for something like really makes me wonder how parts of our society have gone so wrong.

      • SeriousBug@infosec.pub
        link
        fedilink
        English
        arrow-up
        4
        ·
        1 year ago

        The police can confiscate your servers. Considering some states are treating abortion as murder, I don’t think it’s unrealistic to say the police could raid your home and confiscate your devices just on suspicion.

        The only thing safe against that is an encrypted device locked with a password, no biometrics like fingerprints or face ID. As far as I know, you can refuse to give a password under the 5th amendment, but you can’t refuse to unlock a device with a fingerprint reader or face ID.

      • cooopsspace@infosec.pub
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        To tell you the truth - I don’t bleed from my genitals so I don’t have the solution for you.

        Time between periods should be 24-38 days. If you can’t manage that in a calendar, how can an app know?