makeitwonderful

joined 9 months ago

You're correct! One of the devs wrote an article about why they made the change.

[–] makeitwonderful@lemmy.sdf.org 10 points 2 weeks ago

Because the regular cheese was the snacking cheeses and I ate the last of it days ago. Keep forgetting to stop at the store on the way home so now I'm surviving on ingredient cheese.

[–] makeitwonderful@lemmy.sdf.org 27 points 2 weeks ago (5 children)

For breakfast, 1 serving honey from the jar and 1 serving apple butter also from the jar. Lunch will be every pepperoni in the house. Dinner is handfuls of shredded cheese paired with a few bites of a raw carrot and frozen cookie dough for dessert.

Daydreaming about this now.

You can't have a dialogue or discussion with a search engine. Getting an answer is a use for asking a question but not all possible uses.

Maybe the way you feel has about this is because there are countless options for places to leave this advice for other people but you decided to put it in a thread where OP is obviously struggling and already past the point where the advice would apply? Dude is in serious need of some urgent empathy and he gets this this tut-tuting combined with making an example of him for the class or something.

[–] makeitwonderful@lemmy.sdf.org 4 points 1 month ago (1 children)

Your comment got me looking through the jellyfin github issues. Are the bugs listed for unauthenticated endpoints what you're referencing? It looks like the 7 open mention being able to view information about the jellyfin instance or view the media itself. But this is just what was commented as possible, there could be more possibilities especially if combined with other vulnerabilities.

Now realizing there are parts of Jellyfin that are known to be accessible without authentication, I'm thinking Fail2ban is going to do less but unless there are ways to do injection with the known bugs/a new 0day they will still need to brute force a password to be able to make changes. I'm curious if there is anything I'm overlooking.

[–] makeitwonderful@lemmy.sdf.org 18 points 1 month ago (3 children)

It feels like everything is a tradeoff and I think a setup like this reduces the complexity for people you share with.

If you added fail2ban along with alert email/notifications you could have a chance to react if you were ever targeted for a brute force attempt. Jellyfin docs talk about setting this up for anyone interested.

Blocking IP segments based on geography of countries you don't expect connections from adds the cost of a VPN for malicious actors in those areas.

Giving Jellyfin its own VLAN on your network could help limit exposure to your other services and devices if you experience a 0day or are otherwise compromised.

[–] makeitwonderful@lemmy.sdf.org 3 points 1 month ago* (last edited 1 month ago)

Promises and contracts can't be trusted. Language makes a wall of interpretation between every person that can be used to claim the original premise of the agreement was misunderstood.

view more: next ›