• 1 Post
  • 297 Comments
Joined 1 year ago
cake
Cake day: July 2nd, 2024

help-circle












  • MaggiWuerze@feddit.orgtoSelfhosted@lemmy.worldImportant Notice of Security Incident
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    5
    ·
    edit-2
    8 days ago

    No, the worst is that a company like Sony or their lawyers can find my server and create a list of movies I offer and then sue me over it. I live in a country where lawyers make a living doing nothing but that.

    Besides that, security by obscurity is the worst possible form and barely qualifies as security at all. It’s also another place where the Jellyfin devs leave their users to their own devices when it comes to securing the server against malicious actors.

    And none of this is clearly communicated by the project. The unauthenticated endpoints are not disclosed, the issues with the filepath is not disclosed. Jellyfin fans treat it as a drop in replacement for Plex, but people using it as such basically throw an unauthenticated server onto the open web







  • MaggiWuerze@feddit.orgtoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    9 days ago

    You’re exactly the kind of Jellyfin user the rest has to thank for the devs lax approach to security. If you actually demanded even basic security, the devs would maybe at least consider it a priority.

    But until it no longer provides an unsecured API, you should maybe think about whether you want to portrait it as secure.


  • MaggiWuerze@feddit.orgtoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    1
    ·
    edit-2
    9 days ago

    Jellyfin holds no sensible data.

    Maybe if you don’t live in a country where piracy is actively prosecuted

    And Plex is not easier to install and secure than Jellyfin.

    You can literally start a Plex server from a exe on desktop windows. Don’t make a fool out of yourself.

    Also it is immensely more secure, unless with “Jellyfin” you actually mean “Jellyfin plus a myriad of convoluted extra steps every user has to take by themselves since the devs can’t be arsed to follow basic standards for web security”