What’s your go too (secure) method for casting over the internet with a Jellyfin server.

I’m wondering what to use and I’m pretty beginner at this

  • rumba@lemmy.zip
    link
    fedilink
    English
    arrow-up
    1
    ·
    12 hours ago

    unless there are ways to do injection with the known bugs/a new 0day

    TBH, that should be enough right here. That is a JUICY target for hacking.

    You can tell outside that someone is running JF.

    You know what packages are used.

    You have full access to the source.

    You know what endpoints are exposed and available.

    All you need is a whole in ffmpeg, a codec, a scaler, or something in libAV. There are a hundred different projects in there from everyone and their brother. And all somebody with experience needs is one of them to have an exploit in a spot where you can send it a payload through an endpoint that doesn’t require authentication.

    We need something to gatekeep. Some form of firewall knocking, or VPN. We don’t need JF to be as publicly accessible as Netflix; we just need a way for our friends and family to get in, prove they’re who they are, and reject all anonymous traffic.