Skip to content

Lost or stolen device

Every device's blast radius, and the door to close first. All actions are web-console; none need the lost device.

Any device — first five minutes

  1. Tailscale admin console → Machines → delete the device. This is the big one: a tailnet device can reach the whole home network.
  2. Find My (Apple) / Find My Device (Windows) → mark lost, wipe if gone for good.
  3. Password manager → check it's locked on that device / revoke its session from the manager's own console.

Then, per device

MacBook

  • Google + Cloudflare + Tailscale sessions: sign out everywhere.
  • Its backup identity can write (not delete history) to the repo — rotate the macbook kopia user password from ops (one command, in the backup section's onboarding page).
  • Nothing on it grants NAS or Proxmox admin without further passwords.

Diagnostic tablet (Windows)

  • Tailscale removal (above) is the critical one — it's the device most likely to travel and least likely to be missed quickly.
  • Rotate its kopia user when Phase 2 brings it online.

Phone

  • From any browser: Google account → sign out all sessions; your password manager's remote-lock; carrier SIM lock.
  • ntfy alerts are read-only noise to a thief; the topic can be rotated later from ops without loss.

What a thief does NOT get

No device stores the kopia repository password (that's the password manager + Break-Glass card only), NAS admin credentials, or Proxmox root. Backup history cannot be deleted from any endpoint — retention and NAS snapshots are server-side.