When I see this sort of thing, and other people are trying to do it, a reverse proxy or vpn is always mentioned. Heres my question:

How Dangerous is it to just open the port for it on my router and access it like that?

Lets say i want to access jellyfin from Kodi on my xbox or something outside my network, the vpn solution wouldnt work for this i would think.

My issue with reverse proxies, and why im asking, is it seems less secure? I mean Im well aware that an IP is easy to get, i guess. But how likely is someone to look for something on my network specifically? With reverse proxies it seems like i would be broadcasting my server to the internet in a way its easier to happen across, than someone being interested in a random residential IP.

I run a minecraft server for friends on my main computer anyway, and i know tons of people do that, theoretically thats the same level of danger as opening my network for jellyfin specifically.

VPN isnt an option because of this xbox stuff i mentioned and people in my family who have 0 chance of understanding it regardless.

So what is the better option, going through this reverse proxy ( which im actually also unsure would work with kodi) or rawdog the server on my network. I guess leaving the server exposed? or every device even.

  • Frylock@sh.itjust.worksOP
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 year ago

    Okay, so can people just find that shit on google? And also what are the odds of certain companies and agencies being perturbed by me essentially broadcasting copyrighted content? Even if i own it. I shpuldnt expect FBI or worse, Viacom hitmen right? Especially of the content is behond a log in?

    • Mike@lemmy.remotelab.uk
      link
      fedilink
      English
      arrow-up
      9
      ·
      1 year ago

      Take a look at shodan to see just how much everyone knows about what’s open on the internet.

      As for DMCA they don’t know what you have behind your login. Make sure you reverse proxy over SSL and you’ll be ok…ish.

    • deafboy@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 year ago

      Not only are people doing regular scans, there are companies with dedicated infrastructure to do the scans for them, and making result easily searchable.

      Check out https://www.shodan.io . Put your (or any other) IP address in the search bar and I guarantee the most of the services running there are already scraped, indexed and categorized. Sometimes it will even recognize a specific app or framework it’s build upon.

      Not only you can search for a specific IPs, but can easily look for, let’s say all jellyfin instances in a certain country.

      I used to search for open tvheadend instances to watch certain TV channels for free. There was a guy who not only published his tvheadend on the internet, but there was an active VNC server on his mediacenter, running kodi. Controllable by anyone without a password.