Comment on What's the security situation when opening a jellyfin server up for casting?
diegantobass@lemmy.world 5 days agoThis whole thread (that I shamelessly hijacked) is very informative and allowed me to understand that cybersecurity is in practice a mixture of concrete nerdy log books and vague feeling of being under a threshold of worthiness.
I woke up this morning and there was a faint noise coming from the server: immediately thought “ok that’s it, it’s pawned and become a node in a vast grid of malicious bots”…it was a cron verification of drives
teawrecks@sopuli.xyz 5 days ago
Hah yeah, I’ve definitely pulled the plug on my router before because I wasn’t sure what I was seeing.
I mean, cybersecurity I would consider to be a research field. In practice, yeah, it’s a bunch of people just doing their best.
I tend to keep everything inside my network and only expose what I need visible on non standard ports, one of those being a VPN. It’s not that I couldn’t run these services public facing, it’s that the people taking the time to constantly update, configure, and auditing everything full time to head off red team are being paid. I don’t need to deal with an attack surface any larger than it needs to be, ain’t nobody got time for that.