you are viewing a single comment's thread
view the rest of the comments
[–] 8 points 4 months ago (3 children)

Are you singling out Jellyfin for a particular reason? Or are also going to advise just never opening ports in general?

  • source
  • parent
  • hideshow 6 child comments
  • [–] 13 points 4 months ago* (3 children)

    jellyfin people just always spout this advice as some sort of copium and i dont even know why. ALL software will have security issues at some point or another. just update and move on with your life.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 5 points 4 months ago (1 child)

    Definitely.

    But I think more than copium it's them understanding their users. It's advice for people that will figure out how to run Jellyfin but won't stay on top of updates, setup a waf, use a firewall/reverseproxy to limit access, etc. There are surely a lot of those that just one clicked an installer etc and for them it's good advice.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 4 months ago (1 child)

    that's fair, does it not have any kind of encryption by default?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 4 months ago (1 child)

    Standard TLS, I think, but what else would you need?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 4 months ago* (last edited 4 months ago) (1 child)

    None really, just wondering what the issue with opening it up is if it has TLS? In 10+ years I've never had my Plex server compromised and it just uses TLS. I do change the default port but that's it.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 4 months ago (1 child)

    Plex logins go through their login server so you'll also have login throttling and probably other bot protections.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 4 months ago

    That's kinda my perspective on it to. I mean, how do they think websites work? Gotta expose ports to make all the internet things happen. Sure commercial stuff will have more devices to protect it, but there are things you can do to mitigate issues at home too.

  • source
  • parent
  • [–] 1 point 4 months ago (1 child)

    There is a new story every week in Steve Gibson's "Security Now" podcast about why you should virtually never open ports. And if you do, you'd better IP restrict. Even, or especially, in commercial products. Cisco has a new CVSS 10.0 every other week just about

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 4 months ago* (last edited 4 months ago) (1 child)

    I run pretty much all my stuff through NPMplus. Then I have a firewall between my public and private networks in case something does get compromised. But I've had Plex exposed (on a non-default port) for literally years and nothing ever happens.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 4 months ago (1 child)

    Why NPMplus and not the default NPM?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 4 months ago* (1 child)