• 1 Post
  • 143 Comments
Joined 2 years ago
cake
Cake day: June 12th, 2023

help-circle






  • Funkwhale is the best option for replacing Spotify. It can be private or public and federated so you can follow users who want to share their playlists and such.

    Navidrome is another good option although i don’t use it personally I hear nothing but good things.

    Avoid subsonic directly but youll find funkwhale and other services support it as a protocol very well. Its just the subsonic server software itself and all of the forks seem to basically just be reinventing the same wheel over and over so they can charge for “premium” features.







  • Gravitywell.xYz@sh.itjust.workstoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    edit-2
    1 month ago

    Edit2: here we go

    That makes sense, I appreciate you taking the time. Its certainly not a very big issue for me personally, and i do have other mitigations in place for more general attacks like fail2ban, but not everyone is in the same situation so its a valid concern to mention.

    I do think you’re overestimating the risk, Studios are unlikely to go to such lengths when there are bigger, easier targets. Still, it’s not entirely negligible, even if the exploit seems fairly benign to me personally.

    My thinking as a sysadmin is if someone has security concerns, they wouldnt be JUST with jellyfin in most cases, you’d be securing an entire server (or paying someone else to handle that part), so its issues to keep in mind sure, but the mitigation would be mainly outside of jellyfin specifically anyway, thus why its not really mentioned in jellyfin’s docs or considered a big concern by the devs.

    So I’m not really disagreeing with anything you’ve said, but I you haven’t changed my mind either, I’m still going to recommend jellyfin over plex.


  • Stolen is loaded… XBMC was open source. All the parts that rely on that are available for free.

    Okay so they violated the GPL to produce their product, it started off on good terms and contributing back up stream but then they got greedy and decided to stop giving back, On top of that they also provide nothing upstream to FFMPEG or any other of the open source projects they benefited massively from… basically they are leeches of open source software… but you are technically correct [1] to say its not literally stealing.

    [1] The best kind of correct


  • Well its good to make sure people know about it, but I would think most admins already know and just don’t care. Its certainly not news to me, and doesn’t seem very useful in terms of actually exploiting anything.

    I’m curious what youd think a kind of worst case scenario would be for any of the current jellyfin auth issues. Like what would someone with bad intentions be able to do?

    I think the Plex issue with emails being stolen is a bigger problem because then those emails can get phished for their Plex accounts and possibility more. I still wouldn’t consider it a huge deal though, Plex handled it correctly.

    My real issue with Plex and why I constantly shit on them is that they stole from XBMC and made a business model that monetizes piracy or at least tries to.






  • Okay I don’t drive so im a bit out of the loop on this but last time i rented a car some 15-20 years ago it had GPS built in that didn’t require connecting, it was a tablet sized interface on the console… is that not a thing anymore? Like do cars in 2025 not have functioning GPS without a phone connected to them? Thats wild if so. A 2008 Toyota Prius could have a built in console navigation system, it ran off a DVD or USB key that you got updates for by mail, and here we are in 2025 you need a phone just to power the cars computer for navigation.