Honest question, because I know multiple people who are not looking to jump ship since they already have the Plex Pass.

  • douglasg14b@lemmy.world
    link
    fedilink
    English
    arrow-up
    28
    arrow-down
    3
    ·
    edit-2
    1 day ago

    Problem is access outside your home for family and friends.

    There are serious security gaps that make it a non starter to expose to the internet.

    I’ve been using Jellyfin ever since they forked out of Emby, and honestly, it’s the biggest complaint that I have. It is incredibly difficult to make it available to friends and family who are on various devices, networks, so on and so forth.

    Whereas Plex “just works.”

    • hexabs@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      3 days ago

      Wait what? I have been sharing my jellyfin using a cloudflare tunnel to the endpoint.

      Could you elaborate on the security gaps? How can I pen-test myself to see if I’m vulnerable

    • uthredii@programming.dev
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      4
      ·
      3 days ago

      Why not use a zero trust VPN like netbird? It is fully open source.

      You can create a reverse proxy that requires a password to get through to jellyfin. I think there is a limit of like 5 for this though (unless you pay or self host).

      • Nibodhika@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        3 days ago

        Because clients would probably fail if there’s an authentication layer on front that they’re not expecting.

    • karlhungus@lemmy.ca
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      2
      ·
      3 days ago

      What security gaps in particular? I did have to reverse proxy to get it to https, are there additional security issues?

        • karlhungus@lemmy.ca
          link
          fedilink
          English
          arrow-up
          1
          ·
          20 hours ago

          thanks; for anyone looking, the issues have been split out at the bottom, none of them are addressed as of this writing. I don’t know that I feel like they are that serious (most of them allow you to play things if you know an ID), but they are the kind of thing you’d see in a project where there are bigger security issues.