• 0 Posts
  • 2 Comments
Joined 2 years ago
cake
Cake day: August 9th, 2023

help-circle
  • Waryle@jlai.lutoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    3
    ·
    3 days ago

    I already answered your second paragraph: Jellyfin holds no sensible data.

    And there is no central server gathering data from all users, an hacker would need to find and break in multiple Jellyfin instances, to get useless data from 1 to maybe 10 users each time.

    And Plex is not easier to install and secure than Jellyfin.


  • Waryle@jlai.lutoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    11
    arrow-down
    3
    ·
    edit-2
    3 days ago

    My Jellyfin is behind a Crowdsec + Cloudflare proxy with geoblocking and other protections + Reverse Proxy with additional protections, in a rootless Docker container with no access to the Docker socket, and has only access to a mounted folder which contains just downloaded movies and shows. The effort to break in is high, the reward very low.

    But the most important difference between Jellyfin and Plex is that neither Jellyfin devs nor Jellyfin instances have any personal or credit card information from their users, and therefore are way less a problem if hacked into.