• 0 Posts
  • 24 Comments
Joined 2 years ago
cake
Cake day: July 20th, 2023

help-circle

  • thelittleblackbird@lemmy.worldtoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    2
    ·
    13 hours ago

    Well, when I was talking about not techie people I didn’t mean technology analphabets, everybody can open a port in your consumer router with the help of chatgpt, not everybodies is able to realizes they need a reverse proxy with tls and modify the headers for the Auth…

    Being secure in internet is like the herd inmunity for corona times, your system could be fairly secure, but if you are hammered with several bot nets it is going to be a challenge, and there is responsabiity is shipping a product that is easy to be infected.

    And your third paragraph really confirms why this post is necessary


  • thelittleblackbird@lemmy.worldtoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    14 hours ago

    Jellyfinn has a nice record of problems during the authentication and escalating privileges, even the developer team recommends to use it behind a vpn and don’t expose it to internet.

    If course, you can use a reverse proxy with and external Auth framework to mitigate it, pair it with fail2ban, geo restrictions and a second factor, but those things are not in the scope of the regular user.

    Let’s face reality, plex is not such widespread for being the default option in kali Linux…


  • thelittleblackbird@lemmy.worldtoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    2
    ·
    14 hours ago

    Sometimes your data is not important but your computer, nobody wants to be in a netbot.

    Well, perhaps plex is not better in security (we don’t know for sure) but at least they have a cyber team, a monitoring system and in every bodies hope, dedicated developers for these topics.

    Jellyfinn dies not hve a team like this one per se. Could the developers be better fit and knowledged in jellyfinn than plex? Perhaps, but probably the focus is in the features and not in the security



  • thelittleblackbird@lemmy.worldtoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    2
    ·
    17 hours ago

    Good to read you know how to implement some protection layers around your jellyfinn :)

    But most of the people (specially the plex ones) don’t have the technical background to deploy something like you have, and convince those people to do the switch without knowing how to protect themselves is not a wise thing to do. Specially when this time, plex response was perfectly fine :)












  • That the internet is not longer accessible if both are behind a nat.

    And we don’t start speaking about extra latency in the routers for the nat-lookup-table, the problem of the colliding ports, the mesh problem when you have bottlenecks that cannot be circumvent via bgp routing and so on…

    Nat is a disgrace, an affordable one but a disgrace