• 0 Posts
  • 185 Comments
Joined 2 years ago
cake
Cake day: July 2nd, 2024

help-circle
  • Having an https connection doesn’t do shit if the Backend is insecure. The issue with exposing Jellyfin are not man in the middle attacks, but badly managed access controls and unsecured endpoints.

    Thede issues and the unwillingness of the devs to fix them because they are hellbent on keeping a maximum of client compatibility is what makes it hard to trust the overall security of the project.

    That’s why basically everyone, including the devs, says to not do that and instead rely on a vpn to mitigate security risks.
















  • MaggiWuerze@feddit.orgtoSelfhosted@lemmy.worldSelf-Host Weekly (22 May 2026)
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    3
    ·
    4 months ago

    (Assuming you have a Plex pass):

    1. Setup for Plex isn’t just easier, its basically non existent. Run the exe, point to folder, done. HW encoding just works, transcoding just works, metadata gathering just works.

    2. remote streaming. No need to setup an elaborate VPN scheme and install a client for it on every device you want to have remote access. It just works and even punches through CGNAT and the like

    3. Clients. Plex has a client for every system under the sun. No need for sideloading or anything like that, they are everywhere

    4. UI. Plex has a sane and good looking ui for the streaming client and the admin interface.

    Jellyfin is not bad, but its just not a replacement for Plex. And the way the devs are acting, I doubt it ever will be