• Login
  • Register
  • Login Register
    Login
    Username/Email:
    Password:
    Or login with a social network below
  • Forum
  • Website
  • GitHub
  • Status
  • Translation
  • Features
  • Team
  • Rules
  • Help
  • Feeds
User Links
  • Login
  • Register
  • Login Register
    Login
    Username/Email:
    Password:
    Or login with a social network below

    Useful Links Forum Website GitHub Status Translation Features Team Rules Help Feeds
    Jellyfin Forum Off Topic Self-hosting & Homelabs Best Security Practices?

     
    • 0 Vote(s) - 0 Average

    Best Security Practices?

    TheDreadPirate
    Offline

    Community Moderator

    Posts: 15,374
    Threads: 10
    Joined: 2023 Jun
    Reputation: 460
    Country:United States
    #9
    2025-01-28, 05:33 PM (This post was last modified: 2025-01-28, 05:33 PM by TheDreadPirate.)
    We discourage directly exposing Jellyfin to the Internet without a reverse proxy in the middle. Jellyfin is not hardened and makes no claims to being hardened. Having Nginx handle connections significantly reduces the potential for an exploitable vulnerability that would grant unauthenticated access.

    It is unlikely that you would be targeted in this manner, but not having Jellyfin directly exposed to the Internet without Nginx (or whatever your preferred reverse proxy is) further reduces risk.

    Internet security is all about reducing risk to the point that the amount of effort required for an attacker to gain access is higher than the perceived reward for their effort. For schmucks like us, the reward is pretty low to nothing so the amount of effort someone is willing to expend is also low. So we are just trying to prevent low effort script kiddies and bots from exploiting already known flaws or using common attacks.

    So we reduce that attack surface area by using a hardened application, like Nginx, to handle external connections.

    Keep your stuff up-to-date.
    Use good security best practices.
    Jellyfin 10.10.7 (Docker)
    Ubuntu 24.04.2 LTS w/HWE
    Intel i3 12100
    Intel Arc A380
    OS drive - SK Hynix P41 1TB
    Storage
        4x WD Red Pro 6TB CMR in RAIDZ1
    [Image: GitHub%20Sponsors-grey?logo=github]
    « Next Oldest | Next Newest »

    Users browsing this thread: 1 Guest(s)


    Messages In This Thread
    Best Security Practices? - by 4r5hw45twh - 2025-01-26, 03:46 PM
    RE: Best Security Practices? - by TheDreadPirate - 2025-01-26, 04:50 PM
    RE: Best Security Practices? - by 4r5hw45twh - 2025-01-28, 01:12 AM
    RE: Best Security Practices? - by Host-in-the-Shell - 2025-01-26, 05:05 PM
    RE: Best Security Practices? - by TheDreadPirate - 2025-01-28, 02:41 PM
    RE: Best Security Practices? - by 4r5hw45twh - 2025-01-28, 03:25 PM
    RE: Best Security Practices? - by TheDreadPirate - 2025-01-28, 04:16 PM
    RE: Best Security Practices? - by 4r5hw45twh - 2025-01-28, 05:01 PM
    RE: Best Security Practices? - by TheDreadPirate - 2025-01-28, 05:33 PM
    RE: Best Security Practices? - by bjd223 - 2025-02-21, 12:04 AM
    RE: Best Security Practices? - by TheDreadPirate - 2025-02-21, 01:29 PM

    • View a Printable Version
    • Subscribe to this thread
    Forum Jump:

    Home · Team · Help · Contact
    © Designed by D&D - Powered by MyBB
    L


    Jellyfin

    The Free Software Media System

    Linear Mode
    Threaded Mode