Collection of potential security issues in Jellyfin This is a non exhaustive list of potential security issues found in Jellyfin. Some of these might cause controversy. Some of these are design fla…

  • Zozano@aussie.zone
    link
    fedilink
    English
    arrow-up
    6
    ·
    2 days ago

    I’m also an absolute dumbfuck. And I can confidently tell you, as a matter of fact, that I don’t know.

    I’m running SWAG reverse proxy, my DNS is not tunneled, I share my Jellyfin with others outside my network.

    My primary concern is my server gets hacked, or I get charged with distributing ‘public domain movies’

    • Flax@feddit.uk
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      Hacking, even on an insecure system, would be illegal. Any copyright troll trying to sue a single user for having a private jellyfin instance which they hacked to find out about would probably have a hard time actually making a case.

      “Yeah, this one guy was distributing films to himself and a few friends. I know because I hacked him” doesn’t seem like a good case.

      • Saik0@lemmy.saik0.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        21 hours ago

        Nothing about this is hacking. They’re not defeating any authentication mechanism to scan your system. That’s the whole problem here. Nothing illegal about running a crawler/scanner service.

        The fact that you have their content publicly accessible is not a “bad case” at all. Open FTP sites were sued plenty. It may be a bit harder to prove distribution intentions… but wouldn’t be hard to make a case that you violated copyright for the content they could enumerate.

        • Flax@feddit.uk
          link
          fedilink
          English
          arrow-up
          1
          ·
          15 hours ago

          It’s not publicly accessible, though. An account is clearly needed.

          • Saik0@lemmy.saik0.com
            link
            fedilink
            English
            arrow-up
            1
            ·
            11 hours ago

            No… that’s the point of this thread. There is no requirement to login in order to manually access endpoints. Up to and including pulling video data.