Usually a lurker.
Maybe I should’ve just shut up and thought for a bit longer before writing that comment…

If you want to talk to me elsewhere, you know how to reach me.

  • 0 Posts
  • 10 Comments
Joined 3 years ago
cake
Cake day: July 1st, 2023

help-circle


  • I was hoping to be proven wrong on the claim that jellyfin is insecure.

    The constant argument being parotted (IMO a bit extra overblown) that you can read files by knowing the file path and being able to access the stream urls without authentication.

    So if I know
    /data/media/movie/A Super Secret Movie [2026] (not unlikely due to assumed default paths with docker installations)
    and
    https://jellyfin.example.local/
    I can supposedly guess that the URL is https://jellyfin.example.local/video/source=?1029rifos0xomsoc93 and access the stream.

    Is it an issue? Yes, you are bypassing active authentication
    What is the actual security problem? You can be ddosed by being streames to death? Oh no, what will I do /s

    If anyone else can give a more grave exampe why it’s worse than the above example: Please do. I don’t see the issue besides bypassing authentication.








  • Today I wrote an offer (1st time for that kind) for our customer and took about 30 minutes with all infos already know.
    I cross checked the whole offer 3 times to be perfectly identical and all is fine.
    God I hate myself for that. Meanwhile my (by time) junior colleague creates offers like it’s nothing and my (by time) senior creates >10k offers.
    I feel rrally inferior at times due to that.