I just validated that the latest version of the LDAP privilege escalation issue is not an issue anymore. The curl script is in the ticket.
This was the one where a standard user could get plugin credentials, such as the LDAP bind user, and change the LDAP endpoint. I.E., bad.
I chose this one because after going through all of them, it was the only one that allowed access to something that wasn't just data in Jellyfin.
So for me, security is less of an issue knowing that, as only family use the service, and the remaining issues all require a logged in user (hit admin endpoint with user token).
Plus, I tried a few of those and they were also fixed, just not documented yet. I didn't add to those tickets because I was not as formal with my testing.
Make a dummy Google Account, and log into it when on the VPN. Having an ad history avoids the blocks usually. (Note: only do this if your browsing is not activist related/etc)
Also, if it's image captchas that never end, switch to the accessibility option for the captcha.
I used to do all the things mentioned here. Now, I just use Wireguard. If a family member wants to use a service, they need Wireguard. If they don't want to install it, they dont get the service.
There is outdoor laser tag now. I also haven't tried this, but apparently with a couple of Quest headsets you can play laser tag in VR in a large enough space.
Agreed, and unfortunately articles like this are food for CEOs to do more under the guise of AI. "See, it works!"