I can't wait for what comes first. The claudication and predictable extended support or the wave of malware paralyzing half the world over unsecured devices.
Have to point a dns to the ip, buy a domain, stablish ddns. I don't see it happening often. If you know all that you are ought to know about getting hitm
Bot hits are not a problem for jellyfin. The main problem right now is unauthorized access to endpoints for people who know the hash that is being used in that endpoint.
It's a targeted attack that hampers availability of the services (making it more available than it should be). It doesn't make internet more insecure or anything.
As I said previously I haven't actually known of any of these attacks happening on the wild. As they are kinda hard of pull of. You need to know the precisely hash used for the endpoint, the most normal way of knowing that without being an authorized user is because you used to be an authorized user and you are not anymore. That's weird in jellyfin current ecosystem. People say that the hash could be calculated by a complete outsider, but I have never seen anyone pulling it off on the wild. You need to know a lot of things about the service you are attacking to be able to do it.
So, yes is a security vulnerability, all software have those. But I think it gets blown out of proportion often.
Not techie people are not going to be able to open it for internet access. If you have the knowledge to set a internet available service you should have the knowledge to be able to provide basic security.
Most security issues with jellyfin are an issue only for a specific type of user. The one who is selling access to their server. The worst Jellyfin security issue makes selling access to your server a higher risk situation.
I hope someday those issues would get patched, but I get why there are other priorities for the dev team right now, about issues that bother to a bigger majority of jellyfin users.
Jellyfin dev team is not in charge of your self hosted security though. You know what you are getting, source code available, and it's up to you setting the security.
I know of a guy that went to a shelter for a dog, and they refused because he works with animals, in a farm. And they just hated him for it, excusing the refusal in "he is just going to use the dog as a dog guard", when this is not true at all, he already had a dog who is incredibly well treated and loved. But this shelter just hated farms, even this traditional farm which consisted in a 2-3 cows in a natural pasture, and refused to give this guy a dog.
I tried Warhammer total war thinking I would love it. But the game was just... Not funny to me. I felt like the game was trying to make itself funny too hard. Like I was never able to breathe. Game would be literally spamming armies out of nowhere so I cannot stay a single turn idle, it was always giving me another mission, a new thing to do. Too overwhelming.
I suppose it's specifically engineered with some other public in mind, but certainly it doesn't seems to be me.
For me the mistrust on bluesky started when it was so easily adopted as "twitter" alternative, mastodon being just there struggling for that.
In order to achieve that a lot of money and influence have been moved around. People didn't organically moved, they were influenced to move there. I don't trust that.
I have just set up a normal computer with the specs I wanted, installed debian and docker/podman and I'm golden.