Comment on Jellyfin over the internet
pory@lemmy.world 2 months agoDo note that without that layer you were using Pangolin for, your system might be compromised by a vulnerability in Jellyfin’s server or a brute force attack on your Jellyfin admin account.
scoobydoo27@lemmy.zip 2 months ago
Understood. I set a strong password and a max login attempt on my account.
If someone does get into my account, wouldn’t they only be able to watch what I have on my server anyway?
pory@lemmy.world 2 months ago
You’re trusting Jellyfin to not have some form of privilege escalation attack available. I’m not saying they do have one or that anyone’s exploiting it in the field, but yeah. Also if your Jellyfin admin account is allowed to download subtitles to content folders, a “just fuck shit up” style vandal-hacker could delete your media probably. If you mount the media read-only that wouldn’t be a concern.
scoobydoo27@lemmy.zip 2 months ago
Gotcha. Jellyfin is my backup server behind plex so I’ll just keep it shut off unless I’m using it and set all security things I can within jellyfin when I am using it.
How likely is it someone even finds my server and domain?
pory@lemmy.world 2 months ago
you’re not particularly worried about “someone”, you’re worried about bots that are scanning IP ranges and especially default ports. A lot of people will install a program, not really understand what it does, and forward a port because the setup told them to. Then proceed to never update the program (or it’s a poorly secured program in the first place).