I feel like Cloud means something now, and as part of the general lexicon, it's okay to use it for what it means. At this point, Cloud kind of means that it's a service hosted somewhere on the Internet, that you don't control directly, usually that you pay for. Sounds like they're still doing that.
Changing the name to distance yourself from AWS and Google Cloud is fine, but "Link" doesn't really tell you anything about where it's hosted or that you still have to pay for it. In fact, by announcing this change with the specific goal of distancing yourself from Big Tech it kind of implies that you're no longer a paid service that happens in some remote data center.
But whatevs. Words don't actually mean anything anymore anyway.
Changing the name to distance yourself from AWS and Google Cloud is fine, but "Link" doesn't really tell you anything about where it's hosted or that you still have to pay for it.
But in this case it’s a misnomer. The Home Assistant instance is not in the cloud, but local. The core service of Nabu Casa Cloud is making it remotely accessible. So Link is actually a better name.
> Cloud kind of means that it's a service hosted somewhere on the Internet, that you don't control directly
Isn't that what it always meant? Originating as a cloud symbol on network diagrams, soon expanding into a word when people wanted to talk about said diagrams.
Nabu Kasa keeps ignoring the elephant in the room of security and permissions. They have no native ability to set user groups and permissions. There is no serious RBAC. I guess it doesn't sell cloud subscriptions. I cant keep my children from affecting devices they shouldn't. I ended up replacing my automation with mqtt
I think they're reading their audience and making the correct product choice.
Home Assistant users are the power users of the home automation world, but even among their user base I think the number of users who would use a full set of groups and permissions controls in their home is very small.
This is a feature that would take a lot of engineering effort and only make the product more complicated for most of their users. The part of their user base that did use it would probably never be happy because they wanted something even more specific.
Their basic permissions and control structure covers most of the common use cases. Going further would be 100X more work for something that would only be used by a very small minority of users.
I think a lot of people have a wrong perception of how "complicated" authorization systems need to be, most likely because they've been confrontend with badly built ones their whole career.
These days if you build it with a central policy engine, e.g. on top of Open Policy Agent with Rego as a policy language, and stick to a (actor, object, action) triple system, you can build an extensible and powerful authorization system that usually also is less polluting to the codebase as many other approaches. For HA specifically, where you have a quite low numbers of actors and objects, most of the headaches that could come with such a system in terms of scaling also fall away.
I don’t know, this seems like a pretty basic feature that I would expect all the mainstream smart home ecosystems to support. Do they not? Is it possible with Alexa/Google Home/ etc. for anyone to say “turn off all the lights in the house” into any smart speaker? I’d honestly expect the defaults to only allow commands to apply to the devices in the same room/group as the smart speaker.
Basically the only people I could imagine that'd actually want a complex user permission group is someone with 1 or more Airbnbs that wants to have an overarching view of their properties but also wants to give "guest" access.
What about giving different agents varying sets of tightly scoped permissions? Is there a good way to achieve that today? If not, it might warrant the effort down the road
Is it really an Elephant in the Room situation? Are there upvoted ticket/issues or community threads asking for it? I don't really know, it's an honest question.
As somebody with a pretty extensive Home Assistant based home automation system AND kids, I've never once felt the need for this. I can certainly see the utility of it, but Home Assistant is already complicated enough. I'd prefer effort be spent improving the UX, simplifying the system, improving reliability and adding more (optional) integrations.
I don't understand, why is it a joke? HA permissions are just to lock certain users or groups out of controlling certain things. You wouldn't be randomly giving out accounts to people you don't know or trust. It's the controls to your smarthome after all, not a shell account on an open sign-up server.
Their ethos is that Home Assistant should be deployed in a non-complicated way and that many things that "IT people" want to do with HA are not actually necessary. I can't find the source but I recall frenck (one of the lead devs) explaining that people ask him about stuff like setting up HA using Terraform and he just wonders why someone would want that.
That the default should be non-complicated isn't necessarily in conflict with features for power users, and I feel like in the HA forums it often is portrayed as an unresolvable conflict, when it isn't.
I do think the maintainers are getting better about it. The releases over the past year have reworked a lot of things to be more intuitive for casual users while also being more flexible for power users, but there is still a lot of ground left to cover.
I think with the growing popularity, and expansion of fields of use, this is something they'll ultimately have to reckon with. I've seen quite a few posts on the the HA subreddit, where it's being used for controls in e.g. hotels or other bigger buildings, because it has a great feature set and prevents vendor lock-in. There is no harm in also catering to those people & organizations.
That is something not required in a domestic setting, that is what HomeAssistant is designed for. I don't know why your children needs to have access to HA (or the internet afterall).
You can choose whether to make a user an admin, and you can specify certain dashboards to be admin only. My wall panels are all logged in with a non-admin user specific to that panel, set to show only what I want anyone to access.
Some of us in the family are logged into dashboards on our phones with different users, which update depending on which room we are in.
If you want to gate access to certain functionality on a dashboard designed for a common area, you would need to route to a different dashboard upon providing some kind of authorisation, e.g. an onscreen PIN pad.
OpenHAB cloud is free, https://www.myopenhab.org/, but I think for most technical people, just reverse proxy what you have (HA, OH, etc...) and put something like vouch proxy or oauth2-proxy in front of the endpoint. I don't want any cloud standing in the way of my door lock opening.
Guys, you don't have to use it. That's the _entire_ point. Every comment in here is some version of "But it's still a cloud". Sure. But if the entire thing can be replaced with a Tailscale free account, or a Cloudflare tunnel, or a port forward at your router (in descending order of "should you do it"), is it really the same thing? Hence the name change.
Link/Cloud gets you some more things than just the Remote Access part.
Nabu Casa also hosts e.g. STT/TTS services for a HA to use. Again this is easy to replace with something else and entirely optional to begin with, but since I trust Nabu Casa more than, say, Google and don't have the hardware for local models I like to use them.
It's not really a cloud service, maybe some of the add on features are but the major feature is the tunnel. I signed up for the trial and it didn't really give me anything I actually needed. The tunnel makes things simpler but I already had tailscale on another box so what's the point? Plus, I so rarely ever need to access my HA dashboard. I don't really want to pickup my phone to turn a light on. The whole point of HA is automation, not bypassing a vendor's app. Once things are operating how I want, I don't need to fiddle with it so why do I need to pay money to fiddle with it remotely?
I'll wait for someone to do a network call audit before I trust something like this
I've been working on a small project running mitmproxy on a lot of 'privacy-focused' baby-tracking apps and only one of the ones I've tested doesn't send back a bevy of analytics data (none of which they openly promise to anonymize)
some of the worst culprits had things like the Facebook SDK and Google Ads installed and sending data in spite of literally promising not to generate an Ad ID and three (Baby+, Nanit, and Pregnancy+) straight up had Microsoft Clarity sending data (ie basically screen recordings and full input logs)
From a pure branding perspective, I think there is something to this. We are building a new "cloud" at exe.dev (everything from racking machines, building a global load balancer, and new APIs onto VMs) and yet it is very hard to bring ourselves to use the word cloud. We don't really want to be associated with the experience or mindset that "cloud" implies. I certainly wish there were a better way to describe this.
Rebranding is the right thing and way over due. I honestly hadn't checked them out before but this has made me read through the site a bit. I am intrigued by their privacy claims. I will definitely be looking into them more if those claims hold up.
Huh? I am using cloud compute for 15 years now, I haven't noticed anything being 'ruined' about it. You pay some people money and they run your workloads, it mostly works, same as with local compute.
Not sure why they dramatise it so much. Want a corporate rebrand, have at it. The like changing things, I get that.
They’re talking about consumer products that are cloud-based. You buy a security camera, for example, and you find out all functionality relies on the cloud and all your data is in the cloud. When the cloud isn’t available, your product doesn’t work. When the cloud is available, it’s spying on you.
We are talking about what the cloud means to an entirely different segment of the population to you and me.
I loved it! 4 years ago I built a platform for robotics and one portion of it was a cloud side, we got into the discussion what kinda name to have, silly names catchy names etc., but eventually after none was selected, I went with the “XYZ link” name, because indeed the actual function was a link between operator and a robot in the field, and I think it also fits home assistant as well. Love HA been using it for around 2years now and integrating everything into it!
Given the predatory pricing model the "cloud" has become, this makes perfect sense.
Azure and AWS have become practically a racket. I haven't seen a single "cloud native" company yet that is not leaking hundreds of thousands of dollars per month to the US digital monopolists.
The post mentions bare metal so it’s possible they found a partner to collocate with in a few of the big regions globally.
Regardless, they also call out that what they offer is only an enhancement and if you use it as the only way to access your smarthome then you are not really using the software as intended.
We will see in 12 months if the migration was worth it. Nabu Casa is starting to push harder into B2C so we shall see if the product can keep up with the demand.
Sadly way overpriced for what you get. You can achieve the same for free with a Cloudflare tunnel. It’s great that this service supports the development of home assistant but the pricing is just silly.
In addition to dedicated support, as part of their free Cloudflare tunnels.
Sorry for being snarky, but given the tone/point of the announcement is anti-big tech it's funny to complain that the pricing is so high compared to big tech.
Taken on its own, for the price of a nice coffee a month you also support Home Assistant development and get something in exchange. Pretty good value.
You’re missing the point entirely. Some other home automation platforms require a cloud/subscription to function at all. It has nothing to do with running on AWS or Azure or insert hyperscaler.
Link is completely optional and does not affect the functionality of home assistant. You can run completely offline without a subscription of any kind on your own hardware if you so choose.
I find the downvotes without comment fascinating. Everything I posted was relevant and completely factual. I can only assume it’s people that have literally no idea what home automation is and what cloud is in this context. Cloud doesn’t and has never meant hyperscaler, and where it is hosted is completely irrelevant to the discussion.
We're going to take back the internet and own tech forever.
I know I have a few anti-AI haters on HN, but hear me out. I'm currently using Opus 5.5 to create 100% pure-Rust, immediate mode rendering, open source implementations of Adobe's entire suite:
I got bit by the dark pattern "cancellation fee" one too many times.
AI lets us take back tech and set the clock back to the pre-shitty era. But now you can just create 1:1 functional equivalents, clean room, that are highly performant and cross-platform. Nothing is stopping you.
We'll replace Google Search, we'll build our own smartphones, we'll build better infra. We'll remove all the ads and de-enshittify the entire tech world.
Big tech sowed the seeds of their own commodification with AI. It's all going to come down now that we can rebuild everything without toiling for years to even get close to scaling software capability moats.
The internet is going to reset to 1990-2004 (pre-facebook / "web 2.0" era). The indie web era. Everything is going to be reborn as open source.
> For example, there were times when Paulus, founder of Home Assistant and President of the Open Home Foundation, was on stage saying “don’t buy products that require the cloud to work,” then in the next breath having to explain how Home Assistant Cloud is different, despite the name. That created unnecessary friction.
You can’t install Home Assistant without DockerHub, and it fetches all sorts of stuff from cloud hosters during use.
HA is offline first, but they don’t really take privacy or data hygiene seriously; it shouldn’t talk to the internet at all until and unless you configure it to do something that needs internet. That isn’t the case today, you can’t even install it without internet.
Changing the name to distance yourself from AWS and Google Cloud is fine, but "Link" doesn't really tell you anything about where it's hosted or that you still have to pay for it. In fact, by announcing this change with the specific goal of distancing yourself from Big Tech it kind of implies that you're no longer a paid service that happens in some remote data center.
But whatevs. Words don't actually mean anything anymore anyway.
But in this case it’s a misnomer. The Home Assistant instance is not in the cloud, but local. The core service of Nabu Casa Cloud is making it remotely accessible. So Link is actually a better name.
Isn't that what it always meant? Originating as a cloud symbol on network diagrams, soon expanding into a word when people wanted to talk about said diagrams.
They never did.
Well, except in France, they get really mad about that.
Home Assistant users are the power users of the home automation world, but even among their user base I think the number of users who would use a full set of groups and permissions controls in their home is very small.
This is a feature that would take a lot of engineering effort and only make the product more complicated for most of their users. The part of their user base that did use it would probably never be happy because they wanted something even more specific.
Their basic permissions and control structure covers most of the common use cases. Going further would be 100X more work for something that would only be used by a very small minority of users.
These days if you build it with a central policy engine, e.g. on top of Open Policy Agent with Rego as a policy language, and stick to a (actor, object, action) triple system, you can build an extensible and powerful authorization system that usually also is less polluting to the codebase as many other approaches. For HA specifically, where you have a quite low numbers of actors and objects, most of the headaches that could come with such a system in terms of scaling also fall away.
As somebody with a pretty extensive Home Assistant based home automation system AND kids, I've never once felt the need for this. I can certainly see the utility of it, but Home Assistant is already complicated enough. I'd prefer effort be spent improving the UX, simplifying the system, improving reliability and adding more (optional) integrations.
Many, going back years.
This thread is relevant. Their permissions system is just on entities, and isn't a real EBAC system.
https://www.reddit.com/r/homeassistant/comments/1vxw5pu/acce...
I do think the maintainers are getting better about it. The releases over the past year have reworked a lot of things to be more intuitive for casual users while also being more flexible for power users, but there is still a lot of ground left to cover.
I think with the growing popularity, and expansion of fields of use, this is something they'll ultimately have to reckon with. I've seen quite a few posts on the the HA subreddit, where it's being used for controls in e.g. hotels or other bigger buildings, because it has a great feature set and prevents vendor lock-in. There is no harm in also catering to those people & organizations.
Apparently they're saying this is the wrong way to run a cloud.
Some of us in the family are logged into dashboards on our phones with different users, which update depending on which room we are in.
If you want to gate access to certain functionality on a dashboard designed for a common area, you would need to route to a different dashboard upon providing some kind of authorisation, e.g. an onscreen PIN pad.
Happy to discuss.
We didn't know you'd declared this. I hope there are temporary solutions available while your declaration is communicated to everybody else.
Nabu Casa also hosts e.g. STT/TTS services for a HA to use. Again this is easy to replace with something else and entirely optional to begin with, but since I trust Nabu Casa more than, say, Google and don't have the hardware for local models I like to use them.
I've been working on a small project running mitmproxy on a lot of 'privacy-focused' baby-tracking apps and only one of the ones I've tested doesn't send back a bevy of analytics data (none of which they openly promise to anonymize)
some of the worst culprits had things like the Facebook SDK and Google Ads installed and sending data in spite of literally promising not to generate an Ad ID and three (Baby+, Nanit, and Pregnancy+) straight up had Microsoft Clarity sending data (ie basically screen recordings and full input logs)
Also, surprised with Nanit, Microsoft Clarity was found on the phone app?
With the whole LG fiasco I wouldn't be surprised if the camera itself was doing network fingerprinting and data collection.
Might as well add 9000 at the end of it.
Not sure why they dramatise it so much. Want a corporate rebrand, have at it. The like changing things, I get that.
We are talking about what the cloud means to an entirely different segment of the population to you and me.
Stanley Kubrick must be chortling in his grave.
Azure and AWS have become practically a racket. I haven't seen a single "cloud native" company yet that is not leaking hundreds of thousands of dollars per month to the US digital monopolists.
Cloud capitalism at its finest..
I get that they are trying to market this but it is a bit disingenuous.
Regardless, they also call out that what they offer is only an enhancement and if you use it as the only way to access your smarthome then you are not really using the software as intended.
We will see in 12 months if the migration was worth it. Nabu Casa is starting to push harder into B2C so we shall see if the product can keep up with the demand.
- Offsite Backups
- Voice control (Alexa & Google Home)
- Voice Processing (STT/TTS)
- Better media streaming (video/audio)
In addition to dedicated support, as part of their free Cloudflare tunnels.
Sorry for being snarky, but given the tone/point of the announcement is anti-big tech it's funny to complain that the pricing is so high compared to big tech.
Taken on its own, for the price of a nice coffee a month you also support Home Assistant development and get something in exchange. Pretty good value.
Link is completely optional and does not affect the functionality of home assistant. You can run completely offline without a subscription of any kind on your own hardware if you so choose.
I find the downvotes without comment fascinating. Everything I posted was relevant and completely factual. I can only assume it’s people that have literally no idea what home automation is and what cloud is in this context. Cloud doesn’t and has never meant hyperscaler, and where it is hosted is completely irrelevant to the discussion.
I know I have a few anti-AI haters on HN, but hear me out. I'm currently using Opus 5.5 to create 100% pure-Rust, immediate mode rendering, open source implementations of Adobe's entire suite:
https://github.com/storytold/photocraft (Photoshop)
https://github.com/storytold/vectorcraft (Illustrator)
https://github.com/storytold/filmcraft (Premiere)
https://github.com/storytold/lightcraft (Lightroom)
https://github.com/storytold/printcraft (Acrobat Pro)
https://github.com/storytold/effectcraft (After Effects)
https://github.com/storytold/designcraft (InDesign)
I got bit by the dark pattern "cancellation fee" one too many times.
AI lets us take back tech and set the clock back to the pre-shitty era. But now you can just create 1:1 functional equivalents, clean room, that are highly performant and cross-platform. Nothing is stopping you.
We'll replace Google Search, we'll build our own smartphones, we'll build better infra. We'll remove all the ads and de-enshittify the entire tech world.
Big tech sowed the seeds of their own commodification with AI. It's all going to come down now that we can rebuild everything without toiling for years to even get close to scaling software capability moats.
The internet is going to reset to 1990-2004 (pre-facebook / "web 2.0" era). The indie web era. Everything is going to be reborn as open source.
We're going to own it all.
We don't even own the AI that is building all of this.
That's not too far from owning it.
You can’t install Home Assistant without DockerHub, and it fetches all sorts of stuff from cloud hosters during use.
HA is offline first, but they don’t really take privacy or data hygiene seriously; it shouldn’t talk to the internet at all until and unless you configure it to do something that needs internet. That isn’t the case today, you can’t even install it without internet.