• deafboy@lemmy.world
      link
      fedilink
      English
      arrow-up
      16
      ·
      19 hours ago

      Someone breakes in, then moves laterally to your home assistant running frigate to watch you sleep at night. Then uses your residential uplink as a proxy to resell on an open market.

      After that, the possibilities are practically endless.

      • klankin@piefed.ca
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        12 hours ago

        No reason to connect jellyfin to any sort of local network, router will still hairpin for local connection.

        With that setup its honestly more secure than 99% of IOT devices, and like 50% of routers.

        edit: and if youre running it in the pentagon or something just toss authentication like keycloak in front of it, plus a bit of crowdsec/fail2ban and an IP whitelist, I’d be surprised if you’d even get an attack, much less one violating that strict of a threat models.

          • klankin@piefed.ca
            link
            fedilink
            English
            arrow-up
            1
            ·
            34 minutes ago

            I mean containers make the networking pretty easy, everything beyond that is optional based on your threat model.

            Same as hosting anything networked, you can do it easy or do it safe.

            (but also wireguard is kinda an O(n) problem while exposing to wan is an O(1) problem - at least IT man hours wise)

      • Evotech@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        edit-2
        16 hours ago

        It’s a rootless container. Chances are they are not going to do any of that.

        Things are on the internet all the time.

        • InputZero@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          12 hours ago

          Yeah docker isn’t the isolation sandbox some people make it out to be. It’s not meant for that. You very well may have a setup that’s meant for that but it’s more than I’m willing to expose.

    • InputZero@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      1
      ·
      18 hours ago

      Yup! That’s the worst thing that can happen. Now would you be so be kind as to send us the link to your private unsecured Jellyfin server?

      • Evotech@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        16 hours ago

        I’m tempted to. But I’m not. Just because I dont want to fox my domain here.

        Is running in a rootless podman container. I’m confident