My understanding is that they usually go for the sites that distribute the content now, rather than individuals. Having an open Jellyfin instance looks like the latter rather than the former.
People exfiltrating movies from your Jellyfin account sounds harmless until you get a knock on the door from the police asking why you're running a piracy sharing site. Depending on the attacker's level of access, they may also wonder why your server is now serving kiddie fiddling videos. Or maybe the attacker just replaces all your movie metadata images with ones from the Bee Movie.
To me at least, DOS and region locking should come after properly locking down public facing services. They aren't 100% reliable at preventing intrusions.
I'd be surprised if there wasn't a large difference between the power usage of a cpu at rest (like most servers will be) and one at full power. Especially if it had a gpu in it. They certainly sound a lot louder in my experience.
You can never be truly sure how bad a compromised system has been compromised, or even easily detect when it has happened. It could be running as part of a botnet, stealing your credentials or probing your local/mesh network.
In my eyes, competent cybersecurity abilities are an important part of selhosting which seems to fall by the wayside. It's important to know exactly what your server is doing, what is running and who has access. If your system is on the public internet, you have a moral obligation to behave and not have it turn into a botnet or spam machine.
I think we should have an AI tag, and "not AI" should be the default (otherwise we add "non-" versions of every tag and post titles are a list of what something isn't instead of what it is).
Imo, a lot of the tools here have a high security requirement. Either because they handle personal/private information and/or are exposed to the public internet. AI use is a red flag to me that the developer hasn't properly considered all the security implications of their product.
One thing that jumps out at me reading the readme is the fact that it has a built in email server. Email is hard to get right, and I'm surprised a relatively young(?) project is working on getting all the moving pieces together rather than declaring it out of scope.
If that's the case, throwing more people, especially juniors, into the team won't make a difference.
By the way, having a team full of people that "don't want to work" is a sign that they lack trust in the project or leadership. Maybe management should work on that rather than spouting right wing linkedinisms. :P
Just 28 versions until it's a nice round number!