• 5 Posts
  • 1.05K Comments
Joined 2 years ago
cake
Cake day: July 2nd, 2024

help-circle




  • Having an https connection doesn’t do shit if the Backend is insecure. The issue with exposing Jellyfin are not man in the middle attacks, but badly managed access controls and unsecured endpoints.

    Thede issues and the unwillingness of the devs to fix them because they are hellbent on keeping a maximum of client compatibility is what makes it hard to trust the overall security of the project.

    That’s why basically everyone, including the devs, says to not do that and instead rely on a vpn to mitigate security risks.