HereIAm

u/HereIAm@lemmy.world
5 posts · 772 comments

Recent posts

Recent comments

INAL and even further away from am American one, but I shall inboke the law of Cunningham . Having the company recognising or just generally being okay with the union formation makes the whole process easier. No hiding your unionisation activities and such. I believe the role of the union-buster is to dissuade the employees from signing up to it, see if there's any dirt on union leaders to have then fired, and to just generally be a royal pain in the arse for everyone.

If I got the story right a bunch of Blizzard developers got fired because they shared company secrets/IP in the same discord server they discussed their unionisation work, so Blizzard's lawyers found an easy way to get rid of them.

I think you've fundamentally misunderstood some of their communication.

There's the issue I described earlier where it is possible to stream files unauthenticated if you know the folder structure on the video. The devs have responded that they won't fix this. Outside of streaming content, there's no other access through this mean. https://github.com/jellyfin/jellyfin/issues/1501

Then there's the release of 10.11.7 that fixed a number of security issues. https://github.com/jellyfin/jellyfin/releases/tag/v10.11.7 with no major security issues since then. And all the issues were privilagr escalation for a normal user account on jellyfin. So the attacker would already needed to have an account on your server, and only the data that jellyfin could see was at risk, nothing escaped contagion so to say.

They also officially support a reverse proxy set up: https://jellyfin.org/docs/general/post-install/networking/reverse-proxy/.

I have no idea where you've got the idea where they themselves claim it's unsecure to open it to the internet. Of course there's always a risk associated with exposing something, but jellyfin doesn't pose any larger risk than anything else you might publish.