Changing the name to distance yourself from AWS and Google Cloud is fine, but "Link" doesn't really tell you anything about where it's hosted or that you still have to pay for it. In fact, by announcing this change with the specific goal of distancing yourself from Big Tech it kind of implies that you're no longer a paid service that happens in some remote data center.
But whatevs. Words don't actually mean anything anymore anyway.
But in this case it’s a misnomer. The Home Assistant instance is not in the cloud, but local. The core service of Nabu Casa Cloud is making it remotely accessible. So Link is actually a better name.
You’re more than welcome to host your own or use a vpn or stick it behind cloudflare.
Cloud does mean something in home automation, and that meaning is generally: you must pay a monthly subscription or the product is degraded or doesn't work at all (looking at you wink). This isn’t that.
They never did.
Well, except in France, they get really mad about that.
Hasn't it meant that for many decades now? Originating as a cloud symbol on network diagrams, but not long after used as a word when people wanted to talk about said diagrams. I certainly remember using it in the 90s, so it has meant that for at least that long. You make it sound like we've only recently come to this determination.
I remember when "cloud computing" was stuff like SETI@Home where a bunch of decentralized, distributed nodes all contributed computing power. But I think that's called the Blockchain now?
I don't know. I usually live under a rock.
"Cloud" today is typically used with a more specific meaning, to refer to services such as IaaS or PaaS, which didn't exist in the 90s.
I don't remember encountering the word "cloud" in the 90s used in the way you describe. The cloud could be a symbol for a telephone network, a packet-switched network (including the internet), a company WAN, etc. Typically you'd refer to whatever the cloud symbol was supposed to represent, it wouldn't be called "the cloud" unless I suppose you were discussing the diagram itself.
Exactly. Hence why services like AWS were said to be cloud services. The details not mattering was the value proposition being sold.
> PaaS, which didn't exist in the 90s.
It did, except we called it time-sharing back then.
> The cloud could be a symbol for a telephone network, a packet-switched network (including the internet), a company WAN, etc.
While you are right that the parent did specifically say internet, I am not sure there is a meaningful distinction anymore. Telephony, packet-switched networks, WANs, etc. are all, for the most part, a part of the internet now. The exceptions are exceptional and thus can be ignored.
Home Assistant users are the power users of the home automation world, but even among their user base I think the number of users who would use a full set of groups and permissions controls in their home is very small.
This is a feature that would take a lot of engineering effort and only make the product more complicated for most of their users. The part of their user base that did use it would probably never be happy because they wanted something even more specific.
Their basic permissions and control structure covers most of the common use cases. Going further would be 100X more work for something that would only be used by a very small minority of users.
These days if you build it with a central policy engine, e.g. on top of Open Policy Agent with Rego as a policy language, and stick to a (actor, object, action) triple system, you can build an extensible and powerful authorization system that usually also is less polluting to the codebase as many other approaches. For HA specifically, where you have a quite low numbers of actors and objects, most of the headaches that could come with such a system in terms of scaling also fall away.
> I think a lot of people have a wrong perception of how "complicated" authorization systems need to be,
To this
> These days if you build it with a central policy engine, e.g. on top of Open Policy Agent with Rego as a policy language, and stick to a (actor, object, action) triple system,
This is the complexity that makes it not worth the effort. That’s a lot to develop, test, document, maintain, create UX for, and continue educating people about for something so few people would ever use.
I’m not saying it can’t be done. I’m saying doing it would be more effort than the upside. It’s into the part of the curve where you’re spending 10X the developer time as other features to cater to 1 in 1000 users who aren’t going to be happy anyway because it’s not exactly what they imagined they wanted.
It depends what the authorization requirements are. For consumer-grade security, you're right. But when you start getting into the requirements of large, security-sensitive organizations, there's a lot of unavoidable complexity.
But those contexts often influence the development of security systems, so some of the complexity you're referring to relate to requirements most users don't have.
Most complexity that usually plagues authorization systems comes from complex authentication requirements, and can thus be largely isolated there. That's also where many (often legacy systems) lay a bad foundation, because they from the get-go tangle authentication & authorization into thing.
In a model as described above, that just turns into a slightly different `actor`. With that you can also handle things like context-aware authorization without littering your codebase.
...and if they forget that, they can just edit the source code in command.com!
In the age of agents everywhere this is no longer true or viable.
It's going to be hard for them to do it, for historic and legacy code reasons. But it's long past being a choice and now becoming a need.
No matter how crazy smart AI gets it's not going to be able to hack my doors, lights or thermostat.
For instance, I left my garage freezer door open, in summer, once. The loss of food almost made me cry (just from the pure waste of it all). I have temp monitors now (external, with probes into fridges and freezers) as well as door sensors. If I am dumb and leave them open, or if they break I'm going to get a notification.
Windows/doors open, and it starts raining, alert... I have a whole set of alerts on when to open the windows too based on season and inside vs outside temp. I have seen a savings on my bills for heating and cooling.
Reminders of all kinds when it's not optimal to run the oven, or appliances because of power costs.
As somebody with a pretty extensive Home Assistant based home automation system AND kids, I've never once felt the need for this. I can certainly see the utility of it, but Home Assistant is already complicated enough. I'd prefer effort be spent improving the UX, simplifying the system, improving reliability and adding more (optional) integrations.
Many, going back years.
This thread is relevant. Their permissions system is just on entities, and isn't a real EBAC system.
Yes, but only very coarsly granular things.
- Permissions only work with entities. There are about ten different kinds of objects besides entities, that would also benefit a lot from being part of a uniform permission system.
- Permissions can only be defined for groups, not users, which is quite annoying if you want granular permissions
- With permissions only acting on groups, it also isn't possible to base permissions on user attributes. So you ultimately always have to model a permission set as a group, and then essentially have to have a synchronization mechanism that ensures that the right people are in the right groups
- This also makes scoped integration access impossible. You can't grant a third party app access to e.g. only your energy sensor data.
I do think the maintainers are getting better about it. The releases over the past year have reworked a lot of things to be more intuitive for casual users while also being more flexible for power users, but there is still a lot of ground left to cover.
I think with the growing popularity, and expansion of fields of use, this is something they'll ultimately have to reckon with. I've seen quite a few posts on the the HA subreddit, where it's being used for controls in e.g. hotels or other bigger buildings, because it has a great feature set and prevents vendor lock-in. There is no harm in also catering to those people & organizations.
I don't see HA as a consumer established product, as much as Nabu Kasa would like otherwise.
Then again, this is just my guesswork. I have 0 clue the demographics of Home Assistant users
https://www.reddit.com/r/homeassistant/comments/1vxw5pu/acce...
Build that and I'll be interested.
Apparently they're saying this is the wrong way to run a cloud.
Some of us in the family are logged into dashboards on our phones with different users, which update depending on which room we are in.
If you want to gate access to certain functionality on a dashboard designed for a common area, you would need to route to a different dashboard upon providing some kind of authorisation, e.g. an onscreen PIN pad.
Happy to discuss.
We didn't know you'd declared this. I hope there are temporary solutions available while your declaration is communicated to everybody else.
Nabu Casa also hosts e.g. STT/TTS services for a HA to use. Again this is easy to replace with something else and entirely optional to begin with, but since I trust Nabu Casa more than, say, Google and don't have the hardware for local models I like to use them.
I've been working on a small project running mitmproxy on a lot of 'privacy-focused' baby-tracking apps and only one of the ones I've tested doesn't send back a bevy of analytics data (none of which they openly promise to anonymize)
some of the worst culprits had things like the Facebook SDK and Google Ads installed and sending data in spite of literally promising not to generate an Ad ID and three (Baby+, Nanit, and Pregnancy+) straight up had Microsoft Clarity sending data (ie basically screen recordings and full input logs)
Also, surprised with Nanit, Microsoft Clarity was found on the phone app?
With the whole LG fiasco I wouldn't be surprised if the camera itself was doing network fingerprinting and data collection.
and a really obscure and clearly vibe-designed one (that still works fine) that only fired off a single Firebase call noting an install: https://play.google.com/store/apps/details?id=com.mimiapp.mi...
one caveat is that I haven't done anything like longterm use testing - just account setup and a handful of inputs like a specific feed time and amount, etc. if these apps are firing off data with delayed intervals, I wouldn't have captured it
re Nanit, yes, it sent a request to https://r.clarity.ms/collect with a 1.1KB payload after only a few seconds of use. everything I've read about MS Clarity and MS in general around their data practices makes me extremely wary that such a popular app collects this much data
Might as well add 9000 at the end of it.
I don't even think Cloudflare has a name for theirs, I remember hearing it called their developer platform but after checking just now, they seem to mostly just call it "products".
Devtools marketing to consumers feels pretty impossible to me. I think you either need to be absolutely massive and have existing credibility + tons of resources to throw at every possible marketing channel, or figure out how to get people to truly love your product/brand. You're basically selling trust/professional identities in most cases rather than compute or APIs.
If I were to do it again I would either pick a different vertical or put 90% of my effort into community-building, events, PR/tech-influencer stuff, and flashy demos. You only need to fall back to widely known framings like "cloud" when nobody knows about you.
Not to mention it's a highly unused feature. Most will use HASS on a home LAN in a self-hosted environment with no directly connectivity (unless you're insane), behind a VPN, which is the only correct way to do it.
They tried to solve the problem "How can Paulus keep saying all clouds are bad except ours?", but Nabu Casa remains a Cloud service with different clothes. At least they're doing the right thing by focusing on why Nabu Casa currently champions different ethics.
Not sure why they dramatise it so much. Want a corporate rebrand, have at it. The like changing things, I get that.
We are talking about what the cloud means to an entirely different segment of the population to you and me.
https://safebots.github.io/Safecloud
It has three types of participants:
Drops - this is regular normies opening a tab
Jets - this is people running a node to route requests
Client - this is what's embedded in iframes etc.
Oh, and one more thing. It encrypts everything end-to-end, supports streaming video (!) and lets you share specific intervals or chunks if you want, so that the decryption happens only of those intervals. You can sell content that many people around the world store encrypted, and don't know what they're storing.Here is an article about it in a security magazine: https://www.helpnetsecurity.com/2026/06/19/safecloud-browser...
I get that they are trying to market this but it is a bit disingenuous.
Regardless, they also call out that what they offer is only an enhancement and if you use it as the only way to access your smarthome then you are not really using the software as intended.
We will see in 12 months if the migration was worth it. Nabu Casa is starting to push harder into B2C so we shall see if the product can keep up with the demand.
Link is completely optional and does not affect the functionality of home assistant. You can run completely offline without a subscription of any kind on your own hardware if you so choose.
I find the downvotes without comment fascinating. Everything I posted was relevant and completely factual. I can only assume it’s people that have literally no idea what home automation is and what cloud is in this context. Cloud doesn’t and has never meant hyperscaler, and where it is hosted is completely irrelevant to the discussion.
- Offsite Backups
- Voice control (Alexa & Google Home)
- Voice Processing (STT/TTS)
- Better media streaming (video/audio)
In addition to dedicated support, as part of their free Cloudflare tunnels.
Sorry for being snarky, but given the tone/point of the announcement is anti-big tech it's funny to complain that the pricing is so high compared to big tech.
Taken on its own, for the price of a nice coffee a month you also support Home Assistant development and get something in exchange. Pretty good value.
HA already has many plugins for doing voice processing locally or through other cloud providers (freely or cheaply)
A cloudflare tunnel would also give you direct access to WebRTC streams, just like being at home. HA Cloud just offers relay servers so you don't have to directly connect.
If you want to give HA money, go ahead but there's nothing truly compelling it offers that I couldn't get elsewhere for much less.
Stanley Kubrick must be chortling in his grave.
Azure and AWS have become practically a racket. I haven't seen a single "cloud native" company yet that is not leaking hundreds of thousands of dollars per month to the US digital monopolists.
Cloud capitalism at its finest..
I know I have a few anti-AI haters on HN, but hear me out. I'm currently using Opus 5.5 to create 100% pure-Rust, immediate mode rendering, open source implementations of Adobe's entire suite:
https://github.com/storytold/photocraft (Photoshop)
https://github.com/storytold/vectorcraft (Illustrator)
https://github.com/storytold/filmcraft (Premiere)
https://github.com/storytold/lightcraft (Lightroom)
https://github.com/storytold/printcraft (Acrobat Pro)
https://github.com/storytold/effectcraft (After Effects)
https://github.com/storytold/designcraft (InDesign)
I got bit by the dark pattern "cancellation fee" one too many times.
AI lets us take back tech and set the clock back to the pre-shitty era. But now you can just create 1:1 functional equivalents, clean room, that are highly performant and cross-platform. Nothing is stopping you.
We'll replace Google Search, we'll build our own smartphones, we'll build better infra. We'll remove all the ads and de-enshittify the entire tech world.
Big tech sowed the seeds of their own commodification with AI. It's all going to come down now that we can rebuild everything without toiling for years to even get close to scaling software capability moats.
The internet is going to reset to 1990-2004 (pre-facebook / "web 2.0" era). The indie web era. Everything is going to be reborn as open source.
We're going to own it all.
We don't even own the AI that is building all of this.
That's not too far from owning it.
You can’t install Home Assistant without DockerHub, and it fetches all sorts of stuff from cloud hosters during use.
HA is offline first, but they don’t really take privacy or data hygiene seriously; it shouldn’t talk to the internet at all until and unless you configure it to do something that needs internet. That isn’t the case today, you can’t even install it without internet.