Collection of potential security issues in Jellyfin This is a non exhaustive list of potential security issues found in Jellyfin. Some of these might cause controversy. Some of these are design fla…

  • @[email protected]
    link
    fedilink
    English
    447 days ago

    I’m not sure who needs to hear this, but unless you work as a security engineer or in another security-focused tech field, you really shouldn’t be exposing your homelab to the open internet anyway

    Most people access their homelabs via VPN - i don’t see anything here that’s a problem for that use-case.

      • @[email protected]
        link
        fedilink
        English
        147 days ago

        And I would hope those websites are extremely low-risk and not anywhere near essential infrastructure or data ;)

    • @[email protected]
      link
      fedilink
      English
      47 days ago

      I need to run a VPN already. Fine for desktop, but this isn’t a solution for mobile (where you can’t run two VPNs simultaneously)

      • Hareen
        link
        fedilink
        117 days ago

        @jagged_circle @anarchiddy

        It’s actually possible to run 2 VPNs simultaneously on mobile using RethinkDNS which is an app available on F-Droid. For example I’m currently connected to MullvadVPN and my home network at the same time using two WireGuard configs.

        • @[email protected]
          link
          fedilink
          English
          2
          edit-2
          6 days ago

          Can you order the wireguard connections?

          Eg I want my connections to my home server VPN to first go through my mullvad VPN. Because I dont want any connections coming out of my device that don’t go through a shared VPN or Tor.

          • @[email protected]
            link
            fedilink
            English
            16 days ago

            This may be easier to do on your home network’s router. For instance, mine allows me to set it up as a VPN host, and also to connect to a VPN provider. It has the option to pass all of the connected clients through the connected VPN. So for instance, if I connect my phone to my home VPN, and my home router is connected to Mullvad, my phone’s traffic also gets passed through Mullvad.