Comment on What's the security situation when opening a jellyfin server up for casting?

<- View Parent
victorz@lemmy.world ⁨1⁩ ⁨week⁩ ago

Okay cool, thanks for that follow-up and confirming my SHH setup seems reasonable. 🙏

There’s one thing I don’t really get though, with the whole reverse proxy thing and how that’s supposedly safer:

putting the resilient software (a good reverse proxy) infront of Jellyfin (or most other software) simply increases your security by having the more safe web server be the one interfacing with end users.

Like, once a user client has contact with the Jellyfin instance, via the reverse proxy, wouldn’t the Jellyfin instance be just as vulnerable as without the reverse proxy? Once a connection is established, or found to be available, you could just start exploiting away in the same way, right? Or wrong? If wrong, how? 😅 Maybe it’s too long for a text reply? Maybe I should watch some helpful video explaining how it works. 😁

source
Sort:hotnewtop