Ok, I’m gonna need an explanation for this one. What happens after he used the scale function?
MaggiWuerze
- 0 Posts
- 180 Comments
MaggiWuerze@feddit.orgto Selfhosted@lemmy.world•Nextcloud (Docker) calendar sent email reminders for a few days, then stopped. Cron job is working, test emails also workEnglish6·7 days agoif your mail server blocks them they won’t show up there I think. It just refuses to accept the mail. Maybe check Nexxtcloud logs to see what happens when it tries to send the mail
MaggiWuerze@feddit.orgto Selfhosted@lemmy.world•Nextcloud (Docker) calendar sent email reminders for a few days, then stopped. Cron job is working, test emails also workEnglish4·7 days agodo they not get sent or do you just not receive them (eg because your mail server blocks them as spam)?
Do both come from the same address?
Can you try to format the testmail the same way to see if they still arrive?
MaggiWuerze@feddit.orgto Selfhosted@lemmy.world•Important Notice of Security IncidentEnglish42·8 days agoStill better to have a team to react to this incident than just have them shrug and ignore it for 5 years
MaggiWuerze@feddit.orgto Selfhosted@lemmy.world•Important Notice of Security IncidentEnglish65·8 days agoNo, the worst is that a company like Sony or their lawyers can find my server and create a list of movies I offer and then sue me over it. I live in a country where lawyers make a living doing nothing but that.
Besides that, security by obscurity is the worst possible form and barely qualifies as security at all. It’s also another place where the Jellyfin devs leave their users to their own devices when it comes to securing the server against malicious actors.
And none of this is clearly communicated by the project. The unauthenticated endpoints are not disclosed, the issues with the filepath is not disclosed. Jellyfin fans treat it as a drop in replacement for Plex, but people using it as such basically throw an unauthenticated server onto the open web
MaggiWuerze@feddit.orgto Selfhosted@lemmy.world•Important Notice of Security IncidentEnglish2·8 days agoThat’s simply not true. You can just set your local ip range as unauthenticated and use it to your hearts content without an internet connection.
MaggiWuerze@feddit.orgto Selfhosted@lemmy.world•Important Notice of Security IncidentEnglish21·8 days agoYou can access it through your local network without authentication. Add a vpn and you got the same setup Jellyfin fans will praise
MaggiWuerze@feddit.orgto Selfhosted@lemmy.world•Important Notice of Security IncidentEnglish4·8 days agoPlex has a whole team dedicated to security. It’s obviously not perfect and it is a larger attack surface than Jellyfin, but I’ll take that any day over devs who treat security as an afterthought
MaggiWuerze@feddit.orgto Selfhosted@lemmy.world•Important Notice of Security IncidentEnglish63·8 days agoAgain, its not random. It’s not a UUID. Its an md5 hash of the filepath. Which is easily guessable since most people have a very similar if not identical folder structure, especially since a lot have it managed by the *arr suite. take that plus the publicly available release names for movies and you’re done
MaggiWuerze@feddit.orgto Showerthoughts@lemmy.world•Google should have called it JIF, not WebP2·9 days agoI hate how fluently I could read that
Lidl sells these breaded camembert. You stick them in the oven until their top lifts, then you eat them with red whortleberry jam. Its basically half a kilo of molten cheese and jam, but it’s great
MaggiWuerze@feddit.orgto Ask Lemmy@lemmy.world•ill be at your house in 10 minutes. how will you entertain me?3·16 days agoIf Greg say he wants to be an alligator, all I can do is support him
MaggiWuerze@feddit.orgto Ask Lemmy@lemmy.world•ill be at your house in 10 minutes. how will you entertain me?4·16 days agoThats not me, thats my pet alligator
MaggiWuerze@feddit.orgto Ask Lemmy@lemmy.world•ill be at your house in 10 minutes. how will you entertain me?18·17 days agoamateur, I’m just not home
MaggiWuerze@feddit.orgto Ask Lemmy@lemmy.world•What's the worst change made in a movie adaptation of a book?1·23 days agoTIL, that Green Mile and Shawshank were based on Stephen King books.
MaggiWuerze@feddit.orgto Selfhosted@lemmy.world•Your fav guide/method for securing Jellyfin?English31·26 days agoThe general jist is, do not expose Jellyfin to the internet. Neither via a port nor through a reverse proxy. Its simply not build secure enough for that.
Use docker to make the setup easier, then use tailscale or whatever VPN solution to allow users from outside your network to access it.
All of the additional authentication solutions mentioned break client compatibility. Then you could only watch through a browser.
Install docker, deploy Jellyfin to it, test it. They both have good guides on their respective websites.
MaggiWuerze@feddit.orgto Selfhosted@lemmy.world•Your fav guide/method for securing Jellyfin?English1·26 days agoThat doesn’t solve the glaring security issues Jellyfin has. It just changes the computer through which they are accessed
MaggiWuerze@feddit.orgto Selfhosted@lemmy.world•Your fav guide/method for securing Jellyfin?English1·26 days agoYeah and that kills Jellyfin as a drop in replacement for Plex. I would’ve deployed it years ago with a subdomain and given it to friends if it was as easily shareable as Plex
MaggiWuerze@feddit.orgto Selfhosted@lemmy.world•Your fav guide/method for securing Jellyfin?English8·26 days agoWhich breaks basically every client, since none of them can deal with basic auth getting in the way
Aaaah, didn’t see that text