Comment on Jellyfin over the internet
pory@lemmy.world 1 week agoCan “your apps” access it when their device isn’t on your home LAN?
Comment on Jellyfin over the internet
pory@lemmy.world 1 week agoCan “your apps” access it when their device isn’t on your home LAN?
scoobydoo27@lemmy.zip 1 week ago
That was the problem, I couldn’t access anything away from my LAN. I finally figured it out though. I’m using Pangolin to access my services outside of my LAN and by default it adds a SSO option. Once I turned that off, my iPhone app was able to find my server through my domain name just fine. Thanks!
pory@lemmy.world 1 week ago
Do note that without that layer you were using Pangolin for, your system might be compromised by a vulnerability in Jellyfin’s server or a brute force attack on your Jellyfin admin account.
scoobydoo27@lemmy.zip 1 week ago
Understood. I set a strong password and a max login attempt on my account.
If someone does get into my account, wouldn’t they only be able to watch what I have on my server anyway?
pory@lemmy.world 1 week ago
You’re trusting Jellyfin to not have some form of privilege escalation attack available. I’m not saying they do have one or that anyone’s exploiting it in the field, but yeah. Also if your Jellyfin admin account is allowed to download subtitles to content folders, a “just fuck shit up” style vandal-hacker could delete your media probably. If you mount the media read-only that wouldn’t be a concern.