• deafboy@lemmy.world
          link
          fedilink
          English
          arrow-up
          17
          ·
          21 hours ago

          Someone breakes in, then moves laterally to your home assistant running frigate to watch you sleep at night. Then uses your residential uplink as a proxy to resell on an open market.

          After that, the possibilities are practically endless.

          • klankin@piefed.ca
            link
            fedilink
            English
            arrow-up
            4
            arrow-down
            1
            ·
            edit-2
            15 hours ago

            No reason to connect jellyfin to any sort of local network, router will still hairpin for local connection.

            With that setup its honestly more secure than 99% of IOT devices, and like 50% of routers.

            edit: and if youre running it in the pentagon or something just toss authentication like keycloak in front of it, plus a bit of crowdsec/fail2ban and an IP whitelist, I’d be surprised if you’d even get an attack, much less one violating that strict of a threat models.

              • klankin@piefed.ca
                link
                fedilink
                English
                arrow-up
                1
                ·
                3 hours ago

                I mean containers make the networking pretty easy, everything beyond that is optional based on your threat model.

                Same as hosting anything networked, you can do it easy or do it safe.

                (but also wireguard is kinda an O(n) problem while exposing to wan is an O(1) problem - at least IT man hours wise)

          • Evotech@lemmy.world
            link
            fedilink
            English
            arrow-up
            4
            ·
            19 hours ago

            It’s a rootless container. Chances are they are not going to do any of that.

            Things are on the internet all the time.

            • InputZero@lemmy.world
              link
              fedilink
              English
              arrow-up
              3
              ·
              15 hours ago

              Yeah docker isn’t the isolation sandbox some people make it out to be. It’s not meant for that. You very well may have a setup that’s meant for that but it’s more than I’m willing to expose.

        • InputZero@lemmy.world
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          1
          ·
          21 hours ago

          Yup! That’s the worst thing that can happen. Now would you be so be kind as to send us the link to your private unsecured Jellyfin server?

          • Evotech@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            19 hours ago

            I’m tempted to. But I’m not. Just because I dont want to fox my domain here.

            Is running in a rootless podman container. I’m confident