It is literally a cloudflare tunnel/ tailscale type thing but contained in the app. The only real difference is that it is bundled in the app, so less setup and in exchange, Plex itself is free to harvest all of your data.
Comment on Improve very slow library scans on Jellyfin 10.11 / 12 on spinning media
fuckwit_mcbumcrumble@lemmy.dbzer0.com 1 day agoThis happens automatically but it does happen
And that’s the key, it happens automatically and it just works. With jellyfin you have to expose the web server to the internet, or point an app to something else exposed on the internet. With plex you don’t. If you don’t want to (or can’t) a direct connection from your server to their servers, then their servers to your device is established. No VPNs, no reverse proxies, no port forwarding, nothing exposed to the rest of the internet.
JustEnoughDucks@feddit.nl 1 day ago
fuckwit_mcbumcrumble@lemmy.dbzer0.com 1 day ago
That’s the key. It just works. No extra setup necessary.
And more importantly, I do t have to have my 60 year old mom do some additional setup in her end. Just install the app, and go.
NewNewAugustEast@lemmy.zip 1 day ago
Well except during the Plex outage today.
And last week.
ragebutt@lemmy.dbzer0.com 1 day ago
They won’t do that because it’s expensive and free software generally doesn’t have the budget to do this
I don’t know why you think the “just works” is any different from tunneling with a service. Your server is still opened to the internet through upnp with direct connections and through a tunnel to plex.tv when a direct connection is not possible. In fact plex is inherently less secure because their infra is both the encryption endpoint (as opposed to your client with Jellyfin and Tailscale or whatever) and their infra has been vulnerable in the past (like the massive breach in 2022).
Jellyfin with something like nginx and a vpn is open to the internet, yes, but a service that tunnels (like wireguard, Tailscale) bypasses this issue and it’s up to you to set it up as to your level of comfort
Plex is just easier but as with all things tech (especially those infected with VC dollars) “ease” translates to less secure and far more likely to exploit your data
I came up with a funny strategy I use to lock it down a bit. What’s exposed to the internet for me is Apache2 reverse proxy. The proxy is locked down to reject all connections EXCEPT for the ones coming from a special subdomain which is something like a 64-character long random string. This prevents pretty any unwanted connections. Obviously the special subdomain must remain as secret as a shared password among the Jellyfin users. It works for trusted users.
What I want ideally is an “authenticated firewall.” OpenWrt rejecting all connections on the open port except for an allowlist of IPs. Then there must be a system where users can authenticate and their IP is added to the allowlist. I haven’t found an off-the-shelf solution like this but I’ll make it some day. Too bad I figured this random string subdomain trick cause it seems good enough for now. :D
left_is_best@feddit.online 1 day ago
A semi-automated whitelist solution would be nice. I’ve settled for Crowdsec with very strict automatic banning behavior.
KairuByte@lemmy.dbzer0.com 1 day ago
How is your DNS set up for that subdomain? Is it on a wildcard DNS record?