• WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      5
      ·
      4 days ago

      much of the internet is run on simpler software or by full time employees tasked to deal with all this. but sure, ignorance is bliss, what you don’t see does not exist, etc etc, keep running your Jellyfin exposed to the internet. you wouldnt even get to know when your system is compromised. but you know what? you could even remove your password for extra convenience. who would want to log in to a random jellyfin account anyway! surely no one! just don’t recommend these practices to anyone, because you are putting them at risk.

            • WhyJiffie@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              3
              ·
              4 days ago

              wow not just totally unprofessional, but even downvoting the calling out the lack of credible security! you can be ashamed of yourself, and hope that your clients never find out you are a contrarian

              I really doubt your work has anything to do with computers

              • Damarus@feddit.org
                link
                fedilink
                English
                arrow-up
                2
                ·
                4 days ago

                You’re hilarious. I haven’t downvoted you, others are reading these threads as well.

                Talking about security… Have you heard of intrusion detection, process isolation, or principle of least privilege?

                • WhyJiffie@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  7 hours ago

                  Talking about security… Have you heard of intrusion detection, process isolation, or principle of least privilege?

                  are you aware that the very popular official docker image for jellyfin still runs the jellyfin process as root? or that most people just mount their media libraries as a read-write volume because they don’t know better?

                  I would also be very interested about statistics on how many jellyfin admins run intrusion detection software on their system, if you have any.

                  • Damarus@feddit.org
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    ·
                    7 hours ago

                    I’m not running my stuff as root if I don’t have to. You’re moving goalposts