• bridgeenjoyer@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    25
    arrow-down
    13
    ·
    14 hours ago

    Meanwhile I made a post asking if plex is bad now and most people on it said “no it’s great I paid for my lifetime pass years ago and its been the best!” Yeah, we know the truth now.

    Jellyfin all the way.

    • FreedomAdvocate@lemmy.net.au
      link
      fedilink
      English
      arrow-up
      3
      ·
      51 minutes ago

      Plex followed best practices and made sure that in the event of a data breach your accounts were safe, and alerted us promptly to the breach and reassured us that nothing private/of value was compromised.

      JellyFin knowingly leaves multiple API endpoints with zero authentication.

      I know which one I prefer, and it’s not the one with gaping security holes marked as “won’t fix”.

    • TrickDacy@lemmy.world
      link
      fedilink
      English
      arrow-up
      21
      arrow-down
      2
      ·
      13 hours ago

      Seems unlikely that this happened. Most people on Lemmy despise Plex and forgive all the shortcomings of Jellyfin

    • AmbiguousProps@lemmy.today
      link
      fedilink
      English
      arrow-up
      16
      arrow-down
      3
      ·
      edit-2
      14 hours ago

      I’d love to switch. I would do it right now, but the problem is that Jellyfin’s security isn’t better if you open it up to the internet. For example, I’d have to set up a VPN for my remote users for proper security, and most of my users are in other states, not technically inclined, and watch on their TVs. I’d have to at least support a raspberry pi for them, or some sort of site to site VPN, and if it goes down, I’ll be expected to fix it. On top of that, if I do a simple raspberry pi based VPN, it would be made even more complicated since they’d want it to work with their smart TVs.

      Again, I really want to switch. But Jellyfin needs to fix their security issues before I can. I’m also happy with the way Plex is reporting this, it’s above the standard “your data is lost” notifications.

      Edit: here’s a link to the related GitHub issue I’ve been following: https://github.com/jellyfin/jellyfin/issues/5415

      And @Saik0Shinigami@lemmy.saik0.com has a great thread explaining more: https://lemmy.today/comment/18923504

      • exu@feditown.com
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        1
        ·
        10 hours ago

        Most of these require some form of random id to exploit, which leaves you either brute forcing ids or brute forcing a user account

        • AmbiguousProps@lemmy.today
          link
          fedilink
          English
          arrow-up
          3
          ·
          10 hours ago

          I mean, that’s fine, but it’s still an issue and a risk that would cause me to want to use VPN for remote viewing. It doesn’t seem like security is Jellyfin’s priority at the moment, not that it’s Plex’s either, but it’s not to a place where it’s worth it to switch from a security standpoint, personally.

      • binarytobis@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        11 hours ago

        My big complaint with Jellyfin is that their documentation showed a “fast forward” hotkey that convinced me to switch from Plex, and when I started it up it was a misnamed “jump forward five seconds” button instead.

        It’s still better for my needs, but I remain angry.

      • bread@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        5
        ·
        12 hours ago

        Jellyfin is great… As long as you’re the only one who needs to access the server. I’ve switched to using Jellyfin myself, but I still run Plex for others to access.

        I’ve found that I get a smoother playback experience on Jellyfin, but even outside of potential security issues, there are a still couple of features I miss from Plex.

      • atomicbocks@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        ·
        12 hours ago

        This is the same reason I haven’t switched. My parents use it to watch the local OTA channels and I have zero intention of supporting a site to site VPN on their home network and multiple mobile devices.

      • TrickDacy@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        13 hours ago

        Thank you for that issues link. I keep trying jellyfin every now and then and I run into issues with general bugginess so I haven’t been able to switch. Seeing that it’s kinda full of security holes makes me even more reticent.