Just out of curiosity, why is your network not a trusted party?
You could start with an additional firewall and maybe setting up traffic restrictions on it to mitigate what devices can communicate with each other, in addition to setting up a local VPN.
Yes its possible to spoof mac addresses and such but it really sounds like your concerns could be mitigated by having a more secure network setup.
If your network isn’t a trusted party then you need to start there. Why isn’t it a trusted party and what do you need to do to secure the traffic to/through it.
smiletolerantly@awful.systems 1 week ago
Then honestly, you have other problems than setting up Jellyfin.
For real though, if you think someone is (or might be) listening in on your local network, i.e. have physical access or compromised one of your machines, then the Jellyfin traffic is the least of your problems. Pick your battles. What’s the worst that could happen here - someone gets to know your favorite show?
Ah, I see. On your PC you should just be able to set a static route over the physical interface for 192.168.0.0/24 (or whatever your local network is) which takes precedence over the VPN. For android… Oof, no idea. Probably need root.
Charger8232@lemmy.ml 1 week ago
A bad router + bad ISP combo means I get ratted out for copyrighted material (that I don’t have… I only host creative commons videos on my Jellyfin server, of course…)
smiletolerantly@awful.systems 1 week ago
This isn’t really true. Even IF your router would fail catastrophically in the right way to expose your Server to the internet, or of it actually “ratted your traffic out” to the ISP and the ISP cared (which it does not), it’s not illegal to hist Jellyfin, or put media on it which you own (which is not discernible from just… Media being streamed).
Also your ISP has no part in your local network traffic.
Trainguyrom@reddthat.com 1 week ago
Sounds far more likely that either someone misunderstood that residential IPs change frequently/may be shared by multiple subscribers or the ISP made an error when responding to a subpeana and provided the incorrect IP. Unfortunately both are all too common with privacy enforcement
If you really think the ISP router is snooping and can’t by bypassed you could simply double-NAT your network with a trusted router and call it a day. Much less VPNing and much less unusual decisions of trust and threat model involved then