this post was submitted on 01 Apr 2026
696 points (99.0% liked)

Selfhosted

56957 readers
672 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

  7. No low-effort posts. This is subjective and will largely be determined by the community member reports.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] magguzu@lemmy.pt 13 points 3 days ago (1 children)

The worst part of enthusiast threads are the "I am very smart" takes like this

[–] possiblylinux127@lemmy.zip 8 points 3 days ago (1 children)

You objectively shouldn't expose Jellyfin to the internet. It has a rather large attack surface and isn't designed with security in mind.

Pretending everything is fine won't solve the problem

[–] kieron115@startrek.website 3 points 3 days ago* (last edited 3 days ago) (2 children)

Sounds like a great reason to use Plex instead!

edit: to add something constructive to my snarky comment, what kind of attack surface are we talkin here? Multiple ports? Lots of separate services running? No authentication?

[–] mic_check_one_two@lemmy.dbzer0.com 7 points 3 days ago (2 children)

There has been a known “anyone can access your media without authentication” vulnerability for seven years and counting, and the Jellyfin devs have openly stated that they have no intentions of fixing it. Because fixing it would require completely divesting from the Enby branch that the entire program is built upon. And they never plan on refactoring that entire thing, so they never plan on fixing the vulnerabilities.

The “don’t expose it to the internet” people aren’t just screaming at clouds. Jellyfin is objectively insecure, and shouldn’t be exposed.

[–] kieron115@startrek.website 3 points 3 days ago* (last edited 3 days ago) (1 children)

Jeez, so it's meant to be a literal home media server. Able, but not designed, to be used for sharing.

Exactly. And that’s honestly why I doubt it will ever truly contend with Plex. It’s fine for sharing with friends who can figure out how to connect via VPN, but it’ll never be robust enough to share with your tech-illiterate grandparents on the open internet. Plex wins handily in that regard, because their sign in process is basically the same as Netflix, HBO, Hulu, etc…

Plex has problems of its own, but (at least as of me writing this) it doesn’t have any major known security vulnerabilities. They had some level 10.0 vulnerability last year, but they followed standard CVE protocols and patched it before the vulnerability was actually released.

[–] grrgyle@slrpnk.net 2 points 3 days ago

Ahh bummer. It works so well as a home media server... kind of calls out for sharing.

[–] possiblylinux127@lemmy.zip 5 points 3 days ago (1 children)

Plex has its own set of problems

[–] kieron115@startrek.website 1 points 3 days ago* (last edited 3 days ago)

Sure, but being mostly secure by default isn't one of them. One advantage of running a service that offers optional subscription services is that they can offer security features like built-in SSL and AAA that just work. Any average user can install it and have a reasonably secure service running. Hell, until a few months ago you didn't even need to open a port to have remote access to your content, whether you paid or not. Now they've made that a paid feature though.