Comment on What's the security situation when opening a jellyfin server up for casting?
victorz@lemmy.world 1 week agoOkay cool, thanks for that follow-up and confirming my SHH setup seems reasonable. 🙏
There’s one thing I don’t really get though, with the whole reverse proxy thing and how that’s supposedly safer:
putting the resilient software (a good reverse proxy) infront of Jellyfin (or most other software) simply increases your security by having the more safe web server be the one interfacing with end users.
Like, once a user client has contact with the Jellyfin instance, via the reverse proxy, wouldn’t the Jellyfin instance be just as vulnerable as without the reverse proxy? Once a connection is established, or found to be available, you could just start exploiting away in the same way, right? Or wrong? If wrong, how? 😅 Maybe it’s too long for a text reply? Maybe I should watch some helpful video explaining how it works. 😁
dogs0n@sh.itjust.works 1 week ago
No problemo.
Thanks for pointing out the reverse proxy comment. I think I was wrong to say simply putting jellyfin behind a reverse proxy will increase your security.
The benefits may only be minute or non-existent if you don’t use the reverse proxy for handling other stuff like HTTPS (and redirects to https, etc), restricting access or adding extra authentication requirements (mainly https).
It may also be good to note that Jellyfins docs explicitly do not recommend directly exposing jellyfin ports to the internet (a reverse proxy or using a vpn are recommended instead).
Still I will continue to feel safer always using a reverse proxy when I expose to the internet (maybe my misconceptions).
victorz@lemmy.world 1 week ago
Thanks again, mate. So basically, if I’m exposing my junk to the world, and by junk I mean service(s), and by world I mean the open internet, I should do it using a reverse proxy and enable HTTPS, otherwise it’s not really very secure? Would that be a reasonable takeaway?
Yet again, thanks. Especially for pointing out the things you (may) be not so sure about. That’s admirable. 🫡
dogs0n@sh.itjust.works 1 week ago
Hehe yep, that’s a good takeaway and the same as what I think.
Thank you too, i enjoyed this discussion.
victorz@lemmy.world 1 week ago
Awesome, same 😊 All the best to you buddy!