The universe is actually expanding at a rate faster than the speed of light. There’s only a finite distance we’d technically be able to travel if we were to leave right now.
- kitnaht@lemmy.world
- Banned
- 0 Posts
- 246 Comments
- kitnaht@lemmy.worldBannedto
Linux@lemmy.ml•I'm committing to Linux, but it's so unstable. Any suggestions?64·2 months agoSomething is awfully weird here, because Linux literally runs the worlds infrastructure for the internet. It is not unstable by any stretch of the imagination. Something you’re doing between all distros has got to be the culprit - something you do differently than other people.
- kitnaht@lemmy.worldBannedto
Selfhosted@lemmy.world•How do I securely host Jellyfin? (Part 2)English2·2 months agoAnd again - if you put those behind a fail2ban; and you 404 5x in an hour, which is likely - you’ve solved that issue. Had my jellyfin instance publicly available for 2 years on its own VM with passthrough GPU, and haven’t had any issues. People poke around quite often, and get blackholed via the firewall for 30d.
It wouldn’t stop a dedicated attacker, but I doubt anyone’s threat model here is that intense. Most compromised servers happen from automated attacks probing for vulnerabilities in order to get RCE; not probing for what movies you have – Because having movies on a media server doesn’t prove that you didn’t rip them all off of blu-ray…it just means you have movies.
You’re not going to have 100% privacy when you put up ANY service on your network. Everything leaves a trace somehow; but I’m starting to think half of you are Chinese spies or something with the amount of paranoia people here show sometimes. :P
- kitnaht@lemmy.worldBannedto
Selfhosted@lemmy.world•How do I securely host Jellyfin? (Part 2)English1·2 months agoHmm, that’s a good point. I just checked my Jellyfin, and I don’t put any of the cert data into its config, I’m using caddy as my reverse proxy to serve it and I didn’t even think about this. No reason it has to be a self-signed cert, it could technically be local only and still be a Let’s Encrypt cert.
- kitnaht@lemmy.worldBannedto
Selfhosted@lemmy.world•How do I securely host Jellyfin? (Part 2)English1·2 months agoIf they need SSL certs, they’ve got to. Jellyfin doesn’t accept self-signed certs, which means DNS entries in a domain, and access from the internet.
Really, honestly - what they need to do is just install Jellyfin on the Raspberry Pi and ditch the encryption requirement altogether. There’s no reason to have it on a LAN-only environment. They aren’t going to need it, nobody is going to MITM their lan environment, and VPNs will regularly allow LAN passthrough.
If ProntonVPNs own client doesn’t allow LAN connections, they either need to swap to the Wireguard vanilla client (if that’s allowed on free tier), or upgrade their VPN service.
OR switch VPNs altogether.
There isn’t a way to do this without breaking one of their requirements
Only options here are to publicly host with real SSL certs, on a domain and tunnel out – Or swap VPN providers/software so that you can achieve LAN access and forego HTTPS altogether.
Edit: And sorry – the previous post is gone regarding their only needing access within the home, there’s no way I could have known that.
There’s a bit of paranoia going on here to begin with - There’s no reason they need this level of “security” within their home network on the LAN side anyhow. They could possibly buy a managed switch and make the jellyfin server only visible to a specific vlan that didn’t include the router, but that doesn’t quite match up with what it sounds like they’re needing.
- kitnaht@lemmy.worldBannedto
Selfhosted@lemmy.world•How do I securely host Jellyfin? (Part 2)English10·2 months agoYeah, this whole thread feels like a “but I can’t do that, work around it for me”
- kitnaht@lemmy.worldBannedto
Selfhosted@lemmy.world•How do I securely host Jellyfin? (Part 2)English7·2 months agoDo. And make sure your logs are piped through fail2ban.
All of these “vulnerabilities”, require already having knowledge of the ItemIDs, and anyone without it poking around will get banned.
The rest of them require a user be authenticated, but allows horizontal information gathering. These are not RCEs or anything serious. The ones which allowed cross-user information editing have been fixed.
- kitnaht@lemmy.worldBannedto
Selfhosted@lemmy.world•How do I securely host Jellyfin? (Part 2)English4·2 months agoTailscale is only for the server/host. You’re not changing all of your VPN services over to this, you’re using it in a ‘reverse’ fashion. You’re VPN-ing the server out to the world so it’s reachable and you have port forwarding options, etc.
From there, it can be reached by any client on the internet as a service. From there though, I don’t know how you’d get to it securely without a domain and SSL (Let’s Encrypt/Caddy) certs.
A domain is only like $16/year. So it’s not prohibitively expensive.
Holy crap this is both so seemingly counter-intuitive, and awesome at the same time.
I drink so much milk constantly throughout the days, almost never anything else, and haven’t had this issue. I think you’ve gotta be predisposed to it as well.
- kitnaht@lemmy.worldBannedto
Relationship Advice@lemmy.world•*Permanently Deleted*English5·2 months agoAnd I’m at the point where ppl think if you don’t have your life together smth is wrong with you
Something is wrong with you then. If you want people to want you, you have to meet societal norms. If you don’t meet them, then it kinda sucks because people aren’t going to give you much of a chance, especially in this high-stakes world.
I’ve got a couple of friends who have been jobless for the 2 years that I’ve known them, and they’re all 35-40. That’s just too long to dick around playing games all day.
You have to have some desirable traits if you want someone to be interested – If you don’t have any desirable traits, you’ve gotta work on yourself and develop some. Everyone has the right to be attracted to what they’re attracted to - so the onus is on you, as much as I’m sure that’s not what you want to be told.
Would YOU date you if the shoes were on the other foot?
Breh.
Removed by mod
Gender Fluid? You mean like the kind you clean up with a mop and bucket?
- kitnaht@lemmy.worldBannedto
Selfhosted@lemmy.world•Tools to migrate from Plex to Jellyfin?English19·2 months agoI sync my watch history with trakt.tv – I believe there are plugins for both Plex and Jellyfin which can transfer those watch histories via that service. I don’t know of any other way.
- kitnaht@lemmy.worldBannedto
Selfhosted@lemmy.world•Discord going public. Plz help a future refugee.English85·3 months agoRevolt is F/OSS
https://github.com/revoltchat/
It’s not just a company with a clone of Discord, all the server back end, etc is open.
And hedgehog means spikepig.
So they’re ocean spike pigs.
- kitnaht@lemmy.worldBannedto
Mildly Infuriating@lemmy.world•Roku TV requires internet connection to EDIT THE HOMEPAGEEnglish9·3 months agoFor those in California, forced arbitration is not enforceable as it’s against the law.
- kitnaht@lemmy.worldBannedto
Mildly Infuriating@lemmy.world•Roku TV requires internet connection to EDIT THE HOMEPAGEEnglish26·3 months agoRoku was the most enshittified ecosystem well before anyone else. They were always the worst.
I just wish that kid wouldn’t have missed.