

Having an https connection doesn’t do shit if the Backend is insecure. The issue with exposing Jellyfin are not man in the middle attacks, but badly managed access controls and unsecured endpoints.
Thede issues and the unwillingness of the devs to fix them because they are hellbent on keeping a maximum of client compatibility is what makes it hard to trust the overall security of the project.
That’s why basically everyone, including the devs, says to not do that and instead rely on a vpn to mitigate security risks.


Haben wir noch Pixel da? 2 noch? Keine mehr?!