Yea I haven't tried Pangolin myself - looks a bit bloated for my tastes, but I have tried rinetd across Tailscale and it worked brilliantly (very simple conf file), and I've done reverse ssh before (using autossh) which was a bit fiddly. frp does look promising though, just as a VPS<->home bridge.
droolio
I mean, anything with a web server can have vulnerabilities. Just look at the LastPass breach where hackers got in through an employee's exposed Plex library.
This video addresses many of the concerns of hosting stuff in public, and details a way (and some tools) to do it relatively securely. (There's always a risk there'll be a zero-day vulnerability in a web application like Jellyfin, but you can mitigate against them if you use the right strategies/tools, and you're vigilant enough.)
Since you're on cgnat, you can set up Pangolin on a VPS, or Tailscale-->rinetd-->Tailscale tunnel, also on a VPS. (Apparently frp is another similar solution, with p2p proxying.)
MURDERER!
FXP
Oh wow, there's a name I ain't heard in a while.
Fantastic rebuttal kindergartener, you convinced everyone.
Yes I read it when it first came out, and again after a recent update. It's very opinionated and I remain unconvinced the criticisms amounts to very much. At the least, certainly not to the point where words like nazi and fascist should be thrown around!
For example, I dislike Yarin's and Lunduke's politics but I did at least watched Yarin's interview. (Did you? It was boring, and entirely tech-oriented, nothing controversial at all.) But... trial by association I guess. And anyway, it's not the article itself I have a problem with - it's the borrowing of second-hand opinions as if they should be your own. Sometimes, it's prudent to reserve judgement (until 'verifying every single thing'), or criticise specific ideas, without leaping to ad hominem per consortium.
I find it wild in this day and age how questions like ("why do WE hate" such and such) are being asked in the first place, then answered through one person's opinion piece mindlessly linked from all angles. Please, for gawd sake, stop listening to random fedditors/redditors about what opinions you should adopt!
IMHO (<- there's a novel approach), the criticisms of FUTO are just as biased and political as FUTO themselves, and everyone should be sceptical of bias from all sides. Apparently, focusing on 'privacy, decentralization, and right to repair' - is being too political, and they're not allowed to have a philosophical take on what they imagine successful open source to be. (Incidentally, I'm not necessarily on FUTOs side, just pissed off at the nature of social media to obviate the need of critical thinking and make everything black or white.)
Duplicacy
Have 3x such WD Reds 3TBs with average ~100K hours power on each, 34.77 years total.
Spent most of that time in a HP Microserver N54L Windows 2012 R2 server with DrivePool, Scanner and SnapRAID. Now they're in a custom build Proxmox in RAIDZ1. Have no intention of retiring them. :)
Device Model: WDC WD30EFRX-68AX9N0
ID# ATTRIBUTE_NAME FLAG VALUE WORST THRESH TYPE UPDATED WHEN_FAILED RAW_VALUE
1 Raw_Read_Error_Rate 0x002f 200 200 051 Pre-fail Always - 0
3 Spin_Up_Time 0x0027 179 178 021 Pre-fail Always - 6033
4 Start_Stop_Count 0x0032 098 098 000 Old_age Always - 2163
5 Reallocated_Sector_Ct 0x0033 200 200 140 Pre-fail Always - 0
7 Seek_Error_Rate 0x002e 200 200 000 Old_age Always - 0
9 Power_On_Hours 0x0032 001 001 000 Old_age Always - 110229
10 Spin_Retry_Count 0x0032 100 100 000 Old_age Always - 0
11 Calibration_Retry_Count 0x0032 100 100 000 Old_age Always - 0
12 Power_Cycle_Count 0x0032 100 100 000 Old_age Always - 123
192 Power-Off_Retract_Count 0x0032 200 200 000 Old_age Always - 35
193 Load_Cycle_Count 0x0032 200 200 000 Old_age Always - 2127
194 Temperature_Celsius 0x0022 115 088 000 Old_age Always - 35
196 Reallocated_Event_Count 0x0032 200 200 000 Old_age Always - 0
197 Current_Pending_Sector 0x0032 200 200 000 Old_age Always - 0
198 Offline_Uncorrectable 0x0030 100 253 000 Old_age Offline - 0
199 UDMA_CRC_Error_Count 0x0032 200 200 000 Old_age Always - 0
200 Multi_Zone_Error_Rate 0x0008 200 200 000 Old_age Offline - 0
announced
What announcement? There's been a new Personal Plus plan around for several months already - introduced without much fanfare, and simply brings the user count from 3 to 6 for a fixed small fee. Presumably this is due to feedback from personal users wanting to contribute something other than nothing.
Where do you see the free Personal plan has changed at all?
They opened it to the internet - that's the big difference (and the topic at hand). Security is a multi-layered thing, but if your weakest point is a gaping hole, the rest doesn't mean much. To my point - assuming Jellyfin ain't gonna have vulnerabilities even when you're fully up-to-date, is foolhardy.