> our only security advantage is being a small target
1. If a 3-letter agency requests access to your on-prem data you'll know about the request and know which data is compromised.
2. You now have to trust your hosting provider. This is almost the same as being a small target, but not quite because you need to worry about all of their employees AND all of your own. There are 1k+ employees to attempt to compromise at Gitlab, and you have no control over or contracts with any of them.
3. Expanding on 2, given the disconnect between Gitlab and your own organization you open yourself up to new kinds of attacks like social engineering an account takeover, or expanding an email breach to a source code breach.
I don't think any of that matters for most people, but your attack surface area is increased with current cloud tech.
1. If a 3-letter agency requests access to your on-prem data you'll know about the request and know which data is compromised.
2. You now have to trust your hosting provider. This is almost the same as being a small target, but not quite because you need to worry about all of their employees AND all of your own. There are 1k+ employees to attempt to compromise at Gitlab, and you have no control over or contracts with any of them.
3. Expanding on 2, given the disconnect between Gitlab and your own organization you open yourself up to new kinds of attacks like social engineering an account takeover, or expanding an email breach to a source code breach.
I don't think any of that matters for most people, but your attack surface area is increased with current cloud tech.