Lost or stolen device¶
Every device's blast radius, and the door to close first. All actions are web-console; none need the lost device.
Any device — first five minutes¶
- Tailscale admin console → Machines → delete the device. This is the big one: a tailnet device can reach the whole home network.
- Find My (Apple) / Find My Device (Windows) → mark lost, wipe if gone for good.
- Password manager → check it's locked on that device / revoke its session from the manager's own console.
Then, per device¶
MacBook¶
- Google + Cloudflare + Tailscale sessions: sign out everywhere.
- Its backup identity can write (not delete history) to the repo — rotate
the
macbookkopia user password from ops (one command, in the backup section's onboarding page). - Nothing on it grants NAS or Proxmox admin without further passwords.
Diagnostic tablet (Windows)¶
- Tailscale removal (above) is the critical one — it's the device most likely to travel and least likely to be missed quickly.
- Rotate its kopia user when Phase 2 brings it online.
Phone¶
- From any browser: Google account → sign out all sessions; your password manager's remote-lock; carrier SIM lock.
- ntfy alerts are read-only noise to a thief; the topic can be rotated later from ops without loss.
What a thief does NOT get¶
No device stores the kopia repository password (that's the password manager + Break-Glass card only), NAS admin credentials, or Proxmox root. Backup history cannot be deleted from any endpoint — retention and NAS snapshots are server-side.