• 1 Post
  • 432 Comments
Joined 1 year ago
cake
Cake day: April 30th, 2024

help-circle




  • daniskarma@lemmy.dbzer0.comtoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    1
    ·
    5 days ago

    Have to point a dns to the ip, buy a domain, stablish ddns. I don’t see it happening often. If you know all that you are ought to know about getting hitm

    Bot hits are not a problem for jellyfin. The main problem right now is unauthorized access to endpoints for people who know the hash that is being used in that endpoint.

    It’s a targeted attack that hampers availability of the services (making it more available than it should be). It doesn’t make internet more insecure or anything.

    As I said previously I haven’t actually known of any of these attacks happening on the wild. As they are kinda hard of pull of. You need to know the precisely hash used for the endpoint, the most normal way of knowing that without being an authorized user is because you used to be an authorized user and you are not anymore. That’s weird in jellyfin current ecosystem. People say that the hash could be calculated by a complete outsider, but I have never seen anyone pulling it off on the wild. You need to know a lot of things about the service you are attacking to be able to do it.

    So, yes is a security vulnerability, all software have those. But I think it gets blown out of proportion often.


  • daniskarma@lemmy.dbzer0.comtoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    5
    ·
    5 days ago

    Not techie people are not going to be able to open it for internet access. If you have the knowledge to set a internet available service you should have the knowledge to be able to provide basic security.

    Most security issues with jellyfin are an issue only for a specific type of user. The one who is selling access to their server. The worst Jellyfin security issue makes selling access to your server a higher risk situation.

    I hope someday those issues would get patched, but I get why there are other priorities for the dev team right now, about issues that bother to a bigger majority of jellyfin users.



  • While I whish access were secured at some point. I’m still yet to see one of those guessed hash attacks on the wild.

    A good thing about Jellyfin is that we KNOW its insecurities because it’s open source.

    Other software may be insecure like that but you would only know after an incident happens because you cannot audit the source code.










  • Sadly I had to install Windows 10 iot ltsc on a laptop I own.

    I tried to install linux. Several distros. But I always ran into de same issue. I was unable to install nvidia drivers. Which was weird, because that laptop have been on linux a few years prior and I clearly recall installing nvidia drivers without any issues.

    So I dug into the problem. And it seems that some new linux kernel had issues with older nvidia drivers, so most, if not all, distros dropped support for that old driver. Only given solution was to run some old lts distro. But por instance mint lts will end on 2027.

    At the same time everything worked just fine on that version of windows that have support until 2032.

    And, not, the laptop is not that usable with nouveau drivers, as those are incapable of doing hardware acceleration, so everything runs slower, specially games, but it can be noticed even in just the DE.

    So it’s weird. That in order to keep old hardware around I need to use Windows, because linux dropped support for this particular older hardware earlier than windows.

    I know it’s just an exception, and that is mostly Nvidia’s fault. But I had to do what I had to do.

    Still running linux on other of my machines though.




  • Take away chatgpt and insert a videogame, movie o bookthat talk about those same topics.

    There are books that talk much darker about suicide. If the kid were to read those the parents would sue the author of the book?

    There is a whole subgenre of music that is about encouraging people to comit suicide and fall into depression, do we use the “who is going to think about the children” card with thar music and its authors? Because music can really get under you skin and a couple of hours listening to that would nake anyone have weird thoughts.

    The shitty parents blame chatgpt because it told the kid how to make a noose. You can kind that info in “howto” with instructable images. Do we put the UK nanny dictatorship controls on “howto” ? Or it only counts of it’s something that benefits of the butlerian yihad?

    I think is completely irrational to blame a piece of software (or media), as much defective as it is, for a suicide.