diegantobass
We must think. Think we must.
- 2 Posts
- 49 Comments
diegantobass@lemmy.worldto
Selfhosted@lemmy.world•What's the security situation when opening a jellyfin server up for casting?English
1·2 months agoThis whole thread (that I shamelessly hijacked) is very informative and allowed me to understand that cybersecurity is in practice a mixture of concrete nerdy log books and vague feeling of being under a threshold of worthiness.
I woke up this morning and there was a faint noise coming from the server: immediately thought “ok that’s it, it’s pawned and become a node in a vast grid of malicious bots”…it was a cron verification of drives
diegantobass@lemmy.worldto
Selfhosted@lemmy.world•What's the security situation when opening a jellyfin server up for casting?English
1·2 months agoLow hanging fruits are, in my personal case, pictures of my cats and public domain cultural artefacts.
Industrializing hacking of random servers sounds like a shitty idea at the end of the day…
diegantobass@lemmy.worldto
Selfhosted@lemmy.world•What's the security situation when opening a jellyfin server up for casting?English
3·2 months agoIgnoring ? Nah someone mentionned my ISP might be protecting me uphill.
diegantobass@lemmy.worldto
Selfhosted@lemmy.world•What's the security situation when opening a jellyfin server up for casting?English
1·2 months agoNon standard port. But aren’t secret chinese hack farm scanning wider than just 22 ? I don’t know and deep down believe that it’s pawned and scrubbing logs.
diegantobass@lemmy.worldto
Selfhosted@lemmy.world•What's the security situation when opening a jellyfin server up for casting?English
1·2 months agoReact2Shell is exactly the shitshow situation yes. Suddenly we are all at risk. But in this case, I’m sorry to say that my cats’ pictures are worthless.
Your point on nginx/wireguard makes me think that it might be better to htaccess through a reverse proxy than relying on a built in login system. For exemple, I should deactivate jellyfin’s login and put it behind an htaccess at the proxy’s level. Is that completely dumb?
Anyway, I clearly need to research “threat models” and cyber/infosec more. Thank you very much!
diegantobass@lemmy.worldto
Selfhosted@lemmy.world•What's the security situation when opening a jellyfin server up for casting?English
2·2 months agoThis is great thanks for this video
diegantobass@lemmy.worldto
Selfhosted@lemmy.world•What's the security situation when opening a jellyfin server up for casting?English
2·2 months agoAren’t zero day very specific? Or maybe it’s become a very generic term.
Anyway, I am under the impression that either it’s suddenly very simple to hack into EVERYONE because someone zero dayed the wireguard protocol and there a major flow in it, it’s a shitshow, for all, for some, just me or nobody, whatever. Or it’s a very targeted attack on me personaly, and that’s a whole other story and the means to protect my pictures of my cats and my cool public domain movies collection are different (think social engineering). Also port 22 being bombarded by brute force attempts so don’t choose a password that’s 6 letters thanks.
I KNOW I am missing many things, but still, I don’t get it.
diegantobass@lemmy.worldto
Selfhosted@lemmy.world•What's the security situation when opening a jellyfin server up for casting?English
2·2 months agoQuick question: If I look through the ssh log and I don’t see the hundred of attempts, what could be going on?..
diegantobass@lemmy.worldto
Selfhosted@lemmy.world•What's the security situation when opening a jellyfin server up for casting?English
2·2 months agoYeah sorry I missed the part where it has no authentification whatsoever, that’s just open bar.
Authentification + monitoring + fail2ban + ip blacklist
diegantobass@lemmy.worldto
Selfhosted@lemmy.world•What's the security situation when opening a jellyfin server up for casting?English
6·2 months agoOkay thanks for mentionning overblown paranoia, that’s what I have.
What kind of exploitable server misconfigurations are we talking about here?? Brute forcing won’t work because fail2ban, right? I’m a noob and deep down I’m convinced that my homeserver is compromised and has beenpart of a bitcoin mining farm for years… Yet, not a single proof…
diegantobass@lemmy.worldto
Selfhosted@lemmy.world•What's the security situation when opening a jellyfin server up for casting?English
186·2 months agoDumb question: why does everyone is so terribly afraid of opening stuff to the internet ? What’s the scenario?
diegantobass@lemmy.worldto
No Stupid Questions@lemmy.world•Is anyone NOT steaming their Music?
3·4 months agoAfter steaming I compress the tracks into a purée with 192 kilograms of olive oil. Good omega-3kHz.
diegantobass@lemmy.worldto
No Stupid Questions@lemmy.world•Is anyone NOT steaming their Music?
32·4 months agoIt’s also the only cooking method that preserves nutrients in the groovy basslines
Speculative fiction, situated feminism, string figure… https://sarahetruman.com/wp-content/uploads/2018/10/SF-Haraway-English-Truman.pdf
diegantobass@lemmy.worldto
Lemmy Shitpost@lemmy.world•US presidents are getting younger over time
15·4 months agoThat’s a major discovery of political sciences through the use of advanced data visualization. I’d aim straight for the American Journal of Political Science. THAT’S SCIENCE RIGHT THERE GENTLEDUDES!
diegantobass@lemmy.worldto
No Stupid Questions@lemmy.world•When will we have reached enough productivity?
111·6 months agoKarl Marx enters the chat
diegantobass@lemmy.worldOPto
Selfhosted@lemmy.world•The hidden cost of self-hostingEnglish
21·7 months agoThat’s the neat part…
diegantobass@lemmy.worldOPto
Selfhosted@lemmy.world•The hidden cost of self-hostingEnglish
51·7 months agoIt looks like we found another person that’s immune! Sample their blood


I suspect it is all a trick to teach people how to use a compressor