• deafboy@lemmy.world
        link
        fedilink
        English
        arrow-up
        17
        arrow-down
        1
        ·
        23 hours ago

        Someone breakes in, then moves laterally to your home assistant running frigate to watch you sleep at night. Then uses your residential uplink as a proxy to resell on an open market.

        After that, the possibilities are practically endless.

        • klankin@piefed.ca
          link
          fedilink
          English
          arrow-up
          4
          arrow-down
          1
          ·
          edit-2
          17 hours ago

          No reason to connect jellyfin to any sort of local network, router will still hairpin for local connection.

          With that setup its honestly more secure than 99% of IOT devices, and like 50% of routers.

          edit: and if youre running it in the pentagon or something just toss authentication like keycloak in front of it, plus a bit of crowdsec/fail2ban and an IP whitelist, I’d be surprised if you’d even get an attack, much less one violating that strict of a threat models.

            • klankin@piefed.ca
              link
              fedilink
              English
              arrow-up
              1
              ·
              5 hours ago

              I mean containers make the networking pretty easy, everything beyond that is optional based on your threat model.

              Same as hosting anything networked, you can do it easy or do it safe.

              (but also wireguard is kinda an O(n) problem while exposing to wan is an O(1) problem - at least IT man hours wise)

        • Evotech@lemmy.world
          link
          fedilink
          English
          arrow-up
          5
          ·
          edit-2
          20 hours ago

          It’s a rootless container. Chances are they are not going to do any of that.

          Things are on the internet all the time.

          • InputZero@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            arrow-down
            1
            ·
            16 hours ago

            Yeah docker isn’t the isolation sandbox some people make it out to be. It’s not meant for that. You very well may have a setup that’s meant for that but it’s more than I’m willing to expose.

      • InputZero@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        2
        ·
        23 hours ago

        Yup! That’s the worst thing that can happen. Now would you be so be kind as to send us the link to your private unsecured Jellyfin server?

        • Evotech@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          20 hours ago

          I’m tempted to. But I’m not. Just because I dont want to fox my domain here.

          Is running in a rootless podman container. I’m confident