• magguzu@lemmy.pt
      link
      fedilink
      English
      arrow-up
      15
      arrow-down
      4
      ·
      21 hours ago

      The worst part of enthusiast threads are the “I am very smart” takes like this

      • Possibly linux@lemmy.zip
        link
        fedilink
        English
        arrow-up
        12
        arrow-down
        3
        ·
        20 hours ago

        You objectively shouldn’t expose Jellyfin to the internet. It has a rather large attack surface and isn’t designed with security in mind.

        Pretending everything is fine won’t solve the problem

        • kieron115@startrek.website
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          1
          ·
          20 hours ago

          Sounds like a great reason to use Plex instead!

          edit: to add something constructive to my snarky comment, what kind of attack surface are we talkin here? Multiple ports? Lots of separate services running? No authentication?

          • mic_check_one_two@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            7
            ·
            16 hours ago

            There has been a known “anyone can access your media without authentication” vulnerability for seven years and counting, and the Jellyfin devs have openly stated that they have no intentions of fixing it. Because fixing it would require completely divesting from the Enby branch that the entire program is built upon. And they never plan on refactoring that entire thing, so they never plan on fixing the vulnerabilities.

            The “don’t expose it to the internet” people aren’t just screaming at clouds. Jellyfin is objectively insecure, and shouldn’t be exposed.

            • grrgyle@slrpnk.net
              link
              fedilink
              English
              arrow-up
              2
              ·
              13 hours ago

              Ahh bummer. It works so well as a home media server… kind of calls out for sharing.

            • kieron115@startrek.website
              link
              fedilink
              English
              arrow-up
              2
              ·
              edit-2
              14 hours ago

              Jeez, so it’s meant to be a literal home media server. Able, but not designed, to be used for sharing.

              • mic_check_one_two@lemmy.dbzer0.com
                link
                fedilink
                English
                arrow-up
                5
                ·
                14 hours ago

                Exactly. And that’s honestly why I doubt it will ever truly contend with Plex. It’s fine for sharing with friends who can figure out how to connect via VPN, but it’ll never be robust enough to share with your tech-illiterate grandparents on the open internet. Plex wins handily in that regard, because their sign in process is basically the same as Netflix, HBO, Hulu, etc…

                Plex has problems of its own, but (at least as of me writing this) it doesn’t have any major known security vulnerabilities. They had some level 10.0 vulnerability last year, but they followed standard CVE protocols and patched it before the vulnerability was actually released.

            • kieron115@startrek.website
              link
              fedilink
              English
              arrow-up
              2
              arrow-down
              1
              ·
              20 hours ago

              Sure, but being mostly secure by default isn’t one of them. One advantage of running a service that offers optional subscription services is that they can offer security features like built-in SSL and AAA that just work. Any average user can install it and have a reasonably secure service running. Hell, until a few months ago you didn’t even need to open a port to have remote access to your content, whether you paid or not. Now they’ve made that a paid feature though.

    • kieron115@startrek.website
      link
      fedilink
      English
      arrow-up
      20
      ·
      edit-2
      20 hours ago

      yeah okay let me just connect grandma’s tv to a vpn.

      edit: gas is $5/gal ya’ll, I’m not driving to a different state each time a new family member wants to watch something from my server!

      • Possibly linux@lemmy.zip
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        20 hours ago

        There are plenty of ways around this

        A cheap thin client minipc is only like 20-40 USD and would solve the problem overnight

          • Possibly linux@lemmy.zip
            link
            fedilink
            English
            arrow-up
            6
            ·
            20 hours ago

            The average user isn’t using Jellyfin

            All you need is a little Linux knowledge in order to setup Netbird with Caddy

            • kieron115@startrek.website
              link
              fedilink
              English
              arrow-up
              1
              ·
              20 hours ago

              I’m talking average enough to see an article, or hear about it from a friend/coworker, then follow the insanely easy setup directions for Windows. I know plenty of people who aren’t really “computer people” but know enough to open a port because they had to to get a game working at some point or another. Those people probably wouldnt notice “hey this thing is going to http maybe i should rethink this…”

              • Shnog@lemmy.world
                link
                fedilink
                English
                arrow-up
                2
                ·
                19 hours ago

                These are going to be the people who think it’s smart to just open up RDP and SSH to the wide web though…they shouldn’t be forwarding ports…they should use a VPN.

                • kieron115@startrek.website
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  19 hours ago

                  I had to explain to one of them why RDP is a bad idea lol. Thats kind of my point - average people tend to only know enough to be dangerous, not to do things safely. Or as Shakespeare said - "The fool doth think he is wise, but the wise man knows himself to be a fool.”

                  • Shnog@lemmy.world
                    link
                    fedilink
                    English
                    arrow-up
                    4
                    ·
                    19 hours ago

                    Yeah. This is why you don’t encourage normies to port forward…they make everyone a domain admin and open up RDP…

        • kieron115@startrek.website
          link
          fedilink
          English
          arrow-up
          5
          ·
          20 hours ago

          I think you’re missing the point - that’s neither simple nor easy for most people. I’m a network engineer and I don’t wanna deal with setting up and (being responsible for troubleshooting) a bunch of VPNs! Nevermind the additional power/CPU usage from the tunnels. My parents just got fiber and they don’t even have a public address (ipv4 or v6) which just adds another layer of headache. thanks west virginia…

          • Seefra 1@lemmy.zip
            link
            fedilink
            English
            arrow-up
            1
            ·
            15 hours ago

            If you have the skills to setup a Jellyfin server you also have the skills to setup wireguard.

            My parents just got fiber and they don’t even have a public address (ipv4 or v6) which just adds another layer of headache. thanks west virginia…

            That’s a very specific use case.

          • Shnog@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            arrow-down
            1
            ·
            19 hours ago

            I’d much rather deal with setting up a few VPN gateways which is trivial at most…than securing a public web service. I deal with that crap enough at work.

            There are a lot less variables to contend with with a single VPN endpoint which undergoes considerably more security auditing than N public web services. Many of which I don’t have the time to review myself and mitigate if they decide to suck at coding.

            Edit: I share my services with less than 5 households though.

            Edit2: I’m not sure what public ipv4 or ipv6 has to do with this. My remote sites use starlink ipv4. I haven’t setup ipv6 on those internally at all. They all tunnel via wireguard to my homesite.

            • kieron115@startrek.website
              link
              fedilink
              English
              arrow-up
              4
              ·
              19 hours ago

              When I set up wireguard it was just more complicated when one side didn’t have a public IP. Whyyyy can’t we adopt ipv6 already.

            • kieron115@startrek.website
              link
              fedilink
              English
              arrow-up
              2
              ·
              19 hours ago

              also fyi starlink has public ipv6 available if you DO wan’t to set it up. been hosting a minecraft server off a starlink connection lol.

              • Shnog@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                ·
                19 hours ago

                At my remote site it has little value. At my home I have IPv6 setup on Starlink as my secondary backup internet. I use Fiber as the primary that has a public IPv4 and IPv6.

                Could just use a VPS though I guess if you want.

    • JigglySackles@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      ·
      1 day ago

      Are you singling out Jellyfin for a particular reason? Or are also going to advise just never opening ports in general?