• 0 Posts
  • 39 Comments
Joined 2 years ago
cake
Cake day: August 9th, 2023

help-circle

  • You can look up for:

    • Setting up max authentication attemps per connection -> slows up a lot brute force attacks. If your password is strong enough, that’s already a big step to secure your server.
    • Generate SSH Keys and disable password authentication -> do this only if you’re connecting through the same devices, because you won’t be able to connect from any device that has not being set up. Personally I don’t use this because I want to be able to access my server even if I’m not home and without my laptop
    • Set up Crowdsec -> it’s a local service which scans logs and will block access to any suspicious IPs. It also relies on a crowdsourced list of IPs that are identified as threat and will preventively block them


  • https://www.legifrance.gouv.fr/juri/id/JURITEXT000030635061/

    Case law from the Cour de Cassation, where the defendant was convicted, by Articles 323-1 and 323-5, of having extracted data freely following a proven failure of the protection system.

    The complainant just had to show that the data SHOULD have been inaccessible, by expressing this “with a special warning” :

    "3°) alors qu’en l’absence de dispositif de protection des données, la maître du système doit manifester clairement et expressément manifester, par une mise en garde spéciale, sa volonté d’interdire ou de restreindre l’accès aux données ; qu’en déduisant de la seule présence d’un contrôle d’accès sur la page d’accueil du site de l’ANSES que M. X… s’était irrégulièrement maintenu dans le système contre le gré de son propriétaire, la cour d’appel a violé l’article 323-1 du code pénal ;

    Translated :

    “3°) whereas in the absence of a data protection system, the master of the system must clearly and expressly manifest, by means of a special warning, his intention to prohibit or restrict access to the data; that in deducing from the mere presence of an access control on the home page of the ANSES site that Mr. X… had irregularly maintained himself in the system against the owner’s will, the Court of Appeal violated article 323-1 of the French Penal Code ;

    In my case, the first thing you see when you arrive at my Jellyfin instance is a login form blocking your entry, and you have to go through a backdoor to access my data, so there’s no ambiguity on this point.

    You’re wrong, period. Stop trying to debate laws interpretation of a country you don’t even speak the language of.




  • Keeping that copy on a web accessible platform that is accessible by anyone on the internet(unauthenticated) isn’t covered by your rights at a bare minimum.

    It’s as accessible as my DVD collection in my living room: anyone can get into my home without a key by illegally breaking a window.

    Using a flaw in my Jellyfin to access my content is illegal and can’t be used against me to sue me, period. The idea of rights holders who would hack me to sue me is just plain ridiculous.

    Depending on the content “timing” if they trigger on something that doesn’t have a physical/consumer release yet… or all sorts of other “impossible” conditions. This is obviously reliant on what content you actually have on your server.

    And again, the only proof they would have could not be used in courts.

    For real, you’re just fear-mongering at this point.

    I was sincerely hoping someone would bring some real concerns, like how one of these security breaches listed in the OP could allow privilege escalation or something, but if all you got is “Universal might hire hackers to break through your server and sue you”, you’re comforting me in my idea that I don’t have much to fear



  • My Jellyfin server is behind Cloudflare with IP outside of my country banned.

    I got Crowdsec set up on Cloudflare, Traefik and Debian directly.

    I got Jellyfin up in a docker container behind Traefik, my router opens only 80 and 443 ports and direct them to Traefik.

    Jellyfin has only access to my media files which are just downloaded movies and shows hardlinked by Sonarr/Radarr from my download folder.

    It is publicly exposed to be able to watch it from anywhere, and share it to family and friends.

    So what? They might access the movies, even delete them, I don’t care, I’ll just hardlink them back or re-download them. What harm can they do that would justify locking everything down?





  • I live 2000km from Chernobyl

    Chernobyl is not comparable to a nuclear bomb. Chernobyl is a reactor, made to release a steadily amount of radiations for years to make electricity.

    Chernobyl irradiated a large area because the graphite that was located in the reactor core has burned, and the fumes have been carried by the wind, taking a lot of high-level activity nuclear waste hundred or thousands of kilometers away.

    A bomb is way smaller than a reactor, and is designed to release most of its energy instantly to make the biggest explosion possible. That means a short burst of radioactivity very high level of radioactivity, with a very small half-life.

    A few days after a bomb explodes, most of the radiations would have depleted.






  • That’s not brain drain. Brain drain is when high qualified people leave their country, mostly because of the lack of infrastructures costing them opportunities for studying or working in their respective field.

    What you’re talking about is capital flight. This is an issue that is systematically raised as a counter-argument by liberals in debates on taxation. The problem is that it is seriously overestimated:

    • Leaving a country is a lot more complicated than it sounds: you lose your family, your friends, your culture, your habits. Many millionaires who leave their country end up coming back after a few years.
    • You can’t relocate your real estate investments.
    • Going abroad doesn’t exempt you from paying taxes (especially exit taxes).
    • A country that wishes to do so can prohibit the relocation of a profitable company, or even nationalize it.
    • Many rich people who threaten to leave if taxes are raised end up doing the math: if there’s a profitable business, they’ll stay. And in a country that finances its infrastructure soundly and has a good distribution of wealth, there’s profitable business to be had.

  • Waryle@jlai.lutoTechnology@lemmy.world*Permanently Deleted*
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    8 months ago

    While true, how is that any different to the arguments that were used for TV?

    Television is bad because it is a passive activity, but it is less harmful than the continuous ingestion of micro-videos. But I don’t see what it has to do here.

    Additionally, Lemmy is a social network in the same way that Reddit is. Is this not also dangerous?

    What’s the connection? I didn’t mention Reddit.

    As has been the recommendation for practically everything for the four decades I’ve been on this earth, moderation is key. Instead of hating new media, either regulate it (if the evidence is truly that great) or treat it with healthy moderation.

    This would be to ignore the particularly addictive nature of this kind of content. It would be like comparing apples to Snickers: both are sweet, yes, but one is much more problematic.

    Let’s be blunt here. Most of the people in this thread aren’t worried about health

    That could be a point, but I’m pretty sure that if you ask anybody, the main reason given would be that it makes you stupid. But I can agree that this opinion would not necessarily be based on anything other than the eternal contempt for novelty as video games or manga were, for example, before they became popular.


  • Waryle@jlai.lutoTechnology@lemmy.world*Permanently Deleted*
    link
    fedilink
    English
    arrow-up
    20
    arrow-down
    3
    ·
    8 months ago

    ITT: People in their mid-twenties or later, who feel superior to those that like one form of media over their preferred media.

    You’re just waving away an important fact, which is that shorts and their equivalents are notoriously known for killing attention spans and disrupting the management of dopamine in the brain, causing depression in particular.

    We are no longer simply in the traditional custom of the elderly who despise the activities of the younger generations, we are talking about health.