I bought Plex pass years ago for £79. The new price of $749.99 is INSANE.

No wonder all the cool people are using Jellyfin.

  • Lena@gregtech.eu
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 months ago

    Isn’t jellyfin full of security vulnerabilities? (Not to defend Plex, just a thought. This is why I don’t have a video streaming server at all.)

    • dan@upvote.au
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 months ago

      You can avoid most security issues (with any sort of server) by not exposing it publicly. Use a VPN like Tailscale to connect remotely. If you share the server with friends or family, share it with them over Tailscale and use an ACL to configure which services they can access on your server.

        • dan@upvote.au
          link
          fedilink
          English
          arrow-up
          0
          ·
          3 months ago

          It’s a good practice to NOT expose services to the internet unless it’s really needed. If they’re only for your use, then the entire world doesn’t need access. This isn’t specific to Jellyfin.

          All software has the potential to have security issues.

            • frongt@lemmy.zip
              link
              fedilink
              English
              arrow-up
              0
              ·
              3 months ago

              The VPN isn’t “on top of” anything, it’s instead of everything.

            • dan@upvote.au
              link
              fedilink
              English
              arrow-up
              0
              ·
              3 months ago

              If a service is publicly accessible, anyone can access it. Even if it’s secured, there can be security issues in the auth layer of the app, improperly secured endpoints, etc.

              If a service is only available over VPN, nobody can access it unless they’re on the VPN. The service isn’t visible over the public internet and other people won’t even know it exists. You can require two factor auth to connect to the VPN.

              I’m not sure why you seem to think that a private network isn’t more secure than a public network. There’s a reason why practically every company requires people working remotely to connect to a VPN to access company resources.

                • dan@upvote.au
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  edit-2
                  3 months ago

                  I never said anything about using the VPN as an ACL. All I said was to only expose the service over the VPN. That doesn’t necessarily mean that the app doesn’t have authentication or authorization.

                  I’m also only talking about residential use cases, where it’s a common practice (when not using a VPN) to just expose everything via port forwarding. Businesses aren’t setting up Jellyfin on their servers.

                  true, fun fact a VPN is also an application with an auth layer. dun dun dun!

                  Sure, but someone would have to first get on the VPN, and then find vulnerable apps once on the internal network, as opposed to just scanning the internet for public-facing vulnerable systems. Wireguard (and thus Tailscale) doesn’t respond to port scans at all - it only responds to packets that are signed with a known key.

                  Admittedly, networking and network security isn’t my specialty so I’m absolutely sure you’ve got more knowledge in this area.

  • whereitsat@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 months ago

    who is this for?

    those unicorn users who make 150k++ a year and pirate all their media and then wanna share it with their friends that they don’t have?

    • brax@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 months ago

      Wouldn’t they hurt use Jellyfin? Lol The only “value” that Plex seems to have to offer these days are the weird tv services things they keep trying to push

      • u/CaperGrrl79@lemmy.ca
        link
        fedilink
        English
        arrow-up
        0
        ·
        3 months ago

        I know someone with a Plex who won’t switch to Jellyfin because it’s too complicated, but now is looking for other platforms. I hate to tell them… they’re all complicated.

        • brax@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 months ago

          Jellyfin is complicated? It’s easier to get going than Plex IMO. It might be slightly trickier to access it outside of your home network but even that’s not all that hard, just set up tailscale

          • u/CaperGrrl79@lemmy.ca
            link
            fedilink
            English
            arrow-up
            2
            ·
            17 days ago

            Since my last comment (I never realized I had replies to my comments here) they have started to use Jellyfin and are hoping to phase out their Plex.

            • brax@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              1
              ·
              16 days ago

              No worries. Sometimes jumping platforms can seem scary/difficult but really it’s just adapting to the change and having to learn things in a slightly different way.

              I made the jump a few months ago and I’ve never looked back - Jellyfin is all around better for my use-case at least (no plugins, and just streaming from my existing media library).

  • Ghoelian@piefed.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 months ago

    I tried Plex once, before I knew about jellyfin. I just wanted an open-source self-hostable media server with my own media.

    When I tried it, after installing Plex, I was presented with a login for a Plex hosted account. Iirc that was optional and I skipped it, after that came the nags for Plex pass. Piss off. That’s exactly the opposite of what I wanted out of something like jellyfin.

    • Ghoelian@piefed.social
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 months ago

      Oh yeah and apparently you can’t stream remotely without a subscription either? If it were a feature they had to spend time on I’d still not want to use it, but I’d understand at least.

      From the application’s point of view, there is no difference between internet and intranet access. I just saw that downloading the media you already own, using your own infrastructure, requires an even more expensive subscription.

      How tf did people stick around with this shit for so long.

      • makeshift0546@lemmy.today
        link
        fedilink
        English
        arrow-up
        0
        ·
        3 months ago

        The same reason most foss projects are barren. Plex focuses on ease of use and giving people what they want. Users mostly don’t care about the sub. It’s easy to use and works.

        Meanwhile jellyfin doesn’t have a remote first interface that isn’t absolute dog shit and I need to set up a reverse proxy and potentially idp to get the ability for my family to log in.

        This shit isn’t hard. The answer to the community is, make the product better, and start bundling shit in. But I’m sure I’ve already offended some nerd who thinks this is all just so easy and requires no work to tell me I just need to learn Linux better. And that putting in a reverse proxy by default will make maintenance a pain and I just have to put portainer and LE to fix it.

        The shit y’all are bitching about is the problem.

        • Ricaz@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          0
          ·
          3 months ago

          Most FOSS projects are barren? Huh

          I’m here to say it’s all very easy and requires no work.

          Seriously, you literally just install Jellyfin (or run it in Docker), set up nginx with certbot and make a port forward on your router. Zero maintenance at all.

          Any LLM can give you a complete step-by-step guide that takes 10 minutes to follow if you don’t know what you’re doing.

          • frongt@lemmy.zip
            link
            fedilink
            English
            arrow-up
            0
            ·
            3 months ago

            I cannot understate how bad of an idea it is to expose something to the Internet when you don’t know what you’re doing.

            Jellyfin is not designed to be exposed directly. They have a number of outstanding security issues. You should really use a VPN to access your local network instead.

            • makeshift0546@lemmy.today
              link
              fedilink
              English
              arrow-up
              0
              ·
              3 months ago

              ADHD linux zealots will argue anything, no matter how stupid, if you dare hold any comparison to a commercial product. It’s literally built into their ADHD brains need to argue and be right.

              They will sit there and argue insane shit and pretend like most people have a desktop sitting in their living room much less setting up an entire *arr stack with reverse proxy. And then scream at you when you say that sounds like work I don’t have to do for less than a hamburger meal.

              It’s easy bro, just learn docker, get it set up so that services boot at launch, and I’m sure nothing will never break or need to be updated again.