• 0 Posts
  • 664 Comments
Joined 2 years ago
cake
Cake day: November 14th, 2023

help-circle





  • Can’t remember any acts of kindness towards me. Only shit I do myself on a daily basis unto others, like oh I dunno, signal my turns, hold doors for people, say hello to someone who looks like they might need some human interaction. Stuff that should be commonplace, but people live in their asshat bubbles thinking about their own asshat lives instead of being just a little bit decent toward the rest of us asshats.

    Goddammit. It’s not hard.













  • Okay cool, thanks for that follow-up and confirming my SHH setup seems reasonable. 🙏

    There’s one thing I don’t really get though, with the whole reverse proxy thing and how that’s supposedly safer:

    putting the resilient software (a good reverse proxy) infront of Jellyfin (or most other software) simply increases your security by having the more safe web server be the one interfacing with end users.

    Like, once a user client has contact with the Jellyfin instance, via the reverse proxy, wouldn’t the Jellyfin instance be just as vulnerable as without the reverse proxy? Once a connection is established, or found to be available, you could just start exploiting away in the same way, right? Or wrong? If wrong, how? 😅 Maybe it’s too long for a text reply? Maybe I should watch some helpful video explaining how it works. 😁



  • Could you explain a bit more?

    Like, right now, I have two machines on my local network. Both are running sshd on port 22.

    In my router, I’ve set the port forwarding to be some high port number in the 19000’s to forward to port 22 on the first machine, and then the same high port number incremented by one (1) to forward to port 22 on the second machine.

    Also key based login only of course.

    Is this insecure in some way?

    Would a VPN make connecting to my computers more secure somehow? I’m not sure I understand how if so.


    What I meant with the Jellyfin question was kind of, how is having it exposed via a reverse proxy different from exposing its port right away? Is it because the only allowed connection would be HTTPS/encrypted etc, maybe?

    I’ve never set up a home network apart from physical cables and using routers and switches before, no advanced site/network configuring. Definitely interested to learn more though for when I want to serve a real media center using a NAS and like a Pi.