• 1 Post
  • 348 Comments
Joined 1 year ago
cake
Cake day: July 2nd, 2024

help-circle











  • You’re exactly the kind of Jellyfin user the rest has to thank for the devs lax approach to security. If you actually demanded even basic security, the devs would maybe at least consider it a priority.

    But until it no longer provides an unsecured API, you should maybe think about whether you want to portrait it as secure.


  • MaggiWuerze@feddit.orgtoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    7
    ·
    edit-2
    6 days ago

    Jellyfin holds no sensible data.

    Maybe if you don’t live in a country where piracy is actively prosecuted

    And Plex is not easier to install and secure than Jellyfin.

    You can literally start a Plex server from a exe on desktop windows. Don’t make a fool out of yourself.

    Also it is immensely more secure, unless with “Jellyfin” you actually mean “Jellyfin plus a myriad of convoluted extra steps every user has to take by themselves since the devs can’t be arsed to follow basic standards for web security”


  • MaggiWuerze@feddit.orgtoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    6 days ago

    My comment, that you answered first to, was about the way the Jellyfin devs would not react the same way to a security incidence, since they do not care about it (or at least don’t see it as important).

    Also, the decentralized nature of Jellyfin does not mitigate such attacks, since you don’t need the users credentials to begin with


  • I don’t mean to come across as confrontational, but, maybe stop defending it then? You can keep using and liking the software while still holding the devs accountable for what is basic modern web security.

    If all the Jellyfin users I saw acknowledging the issues actually stopped acting like it was a non issue, maybe the Jellyfin devs would do something about it.



  • MaggiWuerze@feddit.orgtoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    2
    ·
    6 days ago

    Yeah, me as well. I have a Jellyfin configured and ready to go, but since I share my Plex with a lot of users, half of whom would be turned off by the need of a vpn, I won’t switch until they’ve sorted their shit out.

    and more about there being no effort made to make Jellyfin secure.

    That’s exactly it. And I feel the devs found that their users don’t care or will even defend it, so they won’t tackle it and avoid the problems that come with a rewrite of parts of their api. Plex gets flag for not adding quality of life features people want for the media player, but Jellyfin gets a pass for actual security issues.