• MaggiWuerze@feddit.org
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    2
    ·
    edit-2
    7 hours ago

    No, the worst is that a company like Sony or their lawyers can find my server and create a list of movies I offer and then sue me over it. I live in a country where lawyers make a living doing nothing but that.

    Besides that, security by obscurity is the worst possible form and barely qualifies as security at all. It’s also another place where the Jellyfin devs leave their users to their own devices when it comes to securing the server against malicious actors.

    And none of this is clearly communicated by the project. The unauthenticated endpoints are not disclosed, the issues with the filepath is not disclosed. Jellyfin fans treat it as a drop in replacement for Plex, but people using it as such basically throw an unauthenticated server onto the open web

    • ShortN0te@lemmy.ml
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 hours ago

      Besides that, security by obscurity is the worst possible form and barely qualifies as security at all.

      In fact security by obscurity is not security at all. In this case it should be authenticated or to the very least to actually use a random string like a uuid. But, changing the root path does prevent it from exploiting. Not perfect but a temporary solution.

      It’s also another place where the Jellyfin devs leave their users to their own devices when it comes to securing the server against malicious actors.

      Another place? What else? You mean setting up you own server? That is in fact your responsibility.

    • exu@feditown.com
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 hours ago

      I live in a country where making copies of movies and having them for private consumption isn’t illegal.

      I wouldn’t blame the Jellyfin devs for this situation, they inherited a lot of bad code from Emby and are still cleaning it up.