2026-07-23, 10:41 PM
(This post was last modified: 2026-07-23, 10:50 PM by g2ufVmt4. Edited 1 time in total.)
I still remember the day Jellyfin was forked from Emby. I didn't see the point of trying Plex since it went centralized. The whole point of this, for me, was privacy first.
Jellyfin sends your library contents to third-party metadata providers in real time as it's added, or periodically for the rest.
Preventing that requires significant technical effort if you're not willing to disconnect entirely, and isolating outbound traffic well enough to actually stop the leak isn't something most users can pull off, let alone something that should be the bar for "privacy first."
To put it bluntly: I don't see how one prevents the instance being fingerprinted and your habits being monetized by third parties short of that effort.
The project has shifted toward scaling with features and supporting everything, while the backlog of security and privacy issues keeps growing with less attention. I recall a report of media being accessible without authentication around the 10.8.x era that got closed without what looked like an actual fix.
I also want to point out that I'm holding the project to the standard it has shown, and that's why this post exists. Its not meant as criticism, but rather the opposite.
I hope it encourages some talk about whether it's possible to mitigate outgoing connections to some extent. On that note, I'm a bit shocked that the official docs only really flesh out instructions for a single specific third party provider that requires central registration: Tailscale. It's a VPN that itself needs an account with an outside company just to function, which sits strangely next to a project whose whole pitch is privacy first. Why is that the recommended path?
I also welcome thoughts on addressing what I mentioned or if im in the wrong. Hopefully, the gist of my post makes sense.
Appreciated
Jellyfin sends your library contents to third-party metadata providers in real time as it's added, or periodically for the rest.
Preventing that requires significant technical effort if you're not willing to disconnect entirely, and isolating outbound traffic well enough to actually stop the leak isn't something most users can pull off, let alone something that should be the bar for "privacy first."
To put it bluntly: I don't see how one prevents the instance being fingerprinted and your habits being monetized by third parties short of that effort.
The project has shifted toward scaling with features and supporting everything, while the backlog of security and privacy issues keeps growing with less attention. I recall a report of media being accessible without authentication around the 10.8.x era that got closed without what looked like an actual fix.
I also want to point out that I'm holding the project to the standard it has shown, and that's why this post exists. Its not meant as criticism, but rather the opposite.
I hope it encourages some talk about whether it's possible to mitigate outgoing connections to some extent. On that note, I'm a bit shocked that the official docs only really flesh out instructions for a single specific third party provider that requires central registration: Tailscale. It's a VPN that itself needs an account with an outside company just to function, which sits strangely next to a project whose whole pitch is privacy first. Why is that the recommended path?
I also welcome thoughts on addressing what I mentioned or if im in the wrong. Hopefully, the gist of my post makes sense.
Appreciated

