view the rest of the comments
Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
Anyone using jellyfin should not be exposing it to the public internet.
Hi, could you tell me why? I mean, I think I understand the basics of the risk of brute force attacks. My mitigation for the admin account is, not to allow login outside the local network. Users are allowed from anywhere, as my family uses the library. Also my service (there are others) are routed through NGINX.
Do you have tips for external users using, for example, a VPN only for specific addresses / IPs? At least that was an idea I had, but didn't got got around to dig for solutions.
Thanks in advance.
VPN is the only way I would ever be doing it.
Why not? Unless you're talking about unauthenticated steaming of media if you reverse engineer a servers folder structure.
It’s not secure. It’s a horrible thing to do
Do you have any proof that it's not secure?
The developers of jellyfin themselves say it’s not.
I think you've fundamentally misunderstood some of their communication.
There's the issue I described earlier where it is possible to stream files unauthenticated if you know the folder structure on the video. The devs have responded that they won't fix this. Outside of streaming content, there's no other access through this mean. https://github.com/jellyfin/jellyfin/issues/1501
Then there's the release of 10.11.7 that fixed a number of security issues. https://github.com/jellyfin/jellyfin/releases/tag/v10.11.7 with no major security issues since then. And all the issues were privilagr escalation for a normal user account on jellyfin. So the attacker would already needed to have an account on your server, and only the data that jellyfin could see was at risk, nothing escaped contagion so to say.
They also officially support a reverse proxy set up: https://jellyfin.org/docs/general/post-install/networking/reverse-proxy/.
I have no idea where you've got the idea where they themselves claim it's unsecure to open it to the internet. Of course there's always a risk associated with exposing something, but jellyfin doesn't pose any larger risk than anything else you might publish.
Accessing files unauthenticated……the devs explicitly say they won’t fix it….. and you think that’s not a huge security hole? Software with something like that marked as “won’t fix” is a giant no-no for me. If they’re ok with that, their software should be nowhere near an internet connection.
The person with a fundamental misunderstanding is you.
I do agree it's an odd choice not to fix it, and I do wish they would. But for now it's a risk I'm fine with taking. If my server gets DOSd in the future from multiple unauthenticated streams I sure will be a grumpy git and complain to them, but in the mean time uuh... sharing is caring? 😅
Just wait til movie studios start fishing for people hosting their movies illegally. With how everyone standardises their media structure and file names these days, finding people hosting your movie would be a cinch.