Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)F
Posts
0
Comments
1620
Joined
1 yr. ago

  • You are welcome to expose it at your own risk. Assess you own tolerance for compromise (personal data compromise, becoming part of a botnet, becoming a host for spam or CSAM) and proceed accordingly.

  • Sure, any project designed to be exposed to the Internet. Web servers would be the most obvious.

  • That first page says exposing it to the Internet is "not recommended". Putting a reverse proxy in front of it does not meaningfully change the security posture. A malicious request to http://jellyfin.homelab.com/exploitable-page will be sent to jellyfin in effectively the same way, whether through a reverse proxy or not. You would need a WAF set up specifically to look for relevant exploit attempts.

    https://github.com/jellyfin/jellyfin/issues/5415

    Those are some outstanding known vulnerabilities, most of them unfixed. They are not particularly severe, but it shows that thorough security is not a priority for the jellyfin devs.

  • There is no safe manner of exposing jellyfin.

  • Or run an internal CA, if you're the only one accessing the services.

  • Probably because they didn't stock very many because it's mostly a joke

  • Are we talking physical servers like Poweredge or Proliant? Those take a long time to boot, especially with lots of RAM. Why can't you use suspend/resume?

    And modern servers don't really consume a lot of power while idle. You can configure them to downclock the CPU and GPU while idle just like a desktop or laptop.

    But if you really wanted it, you could boot an immutable distro and mount user partitions tmpfs. Or use a portable distro and discard the state. Or a filesystem with snapshots and roll back on each shutdown or boot. But none of those are really going to get you instant boot. Linux boots pretty quick, but not instant.

  • You will.

    Anything you expose should be designed for it (e.g. not jellyfin). You should have a WAF configured for the type of service you're hosting. You can't just drop one and have it magically protect you, they take configuration. Same with fail2ban.

    And you should have these services in a DMZ, so that a compromise in one doesn't provide an entry point to other resources on your network.

  • Another problem solved by using subscribed instead of new

  • I guarantee there are sewing and maker/hobbyist communities.

  • I feel like I’m forced into this box that is my subscribed feed or I have to actively search out new communities

    I don't feel that this is a problem. I don't ever use the All feed, because I specifically don't want to see all. There's a lot of garbage I don't care about out there.

    I have been trying to be the change I want to see if you check my profile I regularly post in meme subs non political just funny memes to be like “lmao”

    This is... a weird change you'd want to see. Usually people want to see more signal and less noise.

  • Radio and light are different parts of the EM spectrum

  • It does.

  • Block lemmy.ml if lemmy feels tirening.

    Jump
  • "A few bad apples" is not a defense, it's a condemnation. A few bad apples spoil the bunch.

  • Even the floaty physics are almost gone. The new models and processes are fixing that.

  • What, you think

    I'm gonna stop you right there. No, they don't.

  • Unlikely. Microsoft took away GPO control of taskbar and start menu a while back, and I don't think they restored it. And even if they did, a company would be more likely unpin and block them than to push them.

  • The word ban does not imply any duration on its own.