this post was submitted on 19 Jun 2026
303 points (95.2% liked)

Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ

69529 readers
116 users here now

⚓ Dedicated to the discussion of digital piracy, including ethical problems and legal advancements.

Rules • Full Version

1. Posts must be related to the discussion of digital piracy

2. Don't request invites, trade, sell, or self-promote

3. Don't request or link to specific pirated titles, including DMs

4. Don't submit low-quality posts, be entitled, or harass others



Loot, Pillage, & Plunder

We heartily recommend visiting the free port of freemediaheckyeah (aka FMHY) while you sail the high seas, for all the freshest links the ocean has to offer.

📜 c/Piracy Wiki (Community Edition):

🏴‍☠️ Other communities

FUCK ADOBE!

Torrenting/P2P:

Gaming:


💰 Please help cover server costs.

Ko-Fi Liberapay
Ko-fi Liberapay

founded 3 years ago
MODERATORS
 

I bought Plex pass years ago for £79. The new price of $749.99 is INSANE.

No wonder all the cool people are using Jellyfin.

you are viewing a single comment's thread
view the rest of the comments
[–] jatone@lemmy.dbzer0.com 1 points 1 day ago* (last edited 1 day ago)

I never said anything about using the VPN as an ACL.

its literally your entire argument. you may not realize that is what you're saying but it is. 'vpns prevent {insert entity here} from accessing your systems by not publicly exposing them'. ACL -> 'access control list', you need to be on the VPNs list in order to access it which provides control for the network. your router already exposes you to the public internet. using a VPN or not doesnt change this.

in fact:

Sure, but someone would have to first get on the VPN

what do you think the phrase first get on the VPN means? its literally has access via the ACL. more on that paragraph later...

I’m also only talking about residential use cases, where it’s a common practice (when not using a VPN) to just expose everything via port forwarding.

business vs residential doesnt change security properties of approaches.

Businesses aren’t setting up Jellyfin on their servers.

because its literally is not a tool designed for any practical business use case. but that's completely unrelated to its security properties. You're literally just slapping a VPN in front to deal with the broken ACL's that jellyfin provides.

Sure, but someone would have to first get on the VPN, and then find vulnerable apps once on the internal network, as opposed to just scanning the internet for public-facing vulnerable systems.

Doubling up on the authn/authz layers doesnt improve security, it just worsens user experience, which then leads to users taking short cuts for their own convenience undercutting whatever security you're doing.

again as that wonderful federal document discusses VPNs are useful for preventing lateral movement once a device on a network is compromised (see worse user experience). but you literally need multiples of them in order for that to be effective and you need a reason for the segmentation.

Wireguard (and thus Tailscale) doesn’t respond to port scans at all - it only responds to packets that are signed with a known key.

port scanning isnt a vulnerability, its an attack optimization. a discovery mechanism once an attacker already on a network.

it doesnt really even slow attackers down these days. it doesnt take long to just plaster every port with your request for a specific application and when you're attacking a system you essentially already know what vulnerabilities you're going to attack (or you just try all the ones you have). oh no, it took them 30 seconds to compromise the network instead of 3....

you can also achieve similar properties at the application level w/ quic's 0-RT, you send the auth request in the initial packet. so either the authn works or the connection silently hangs just like wireguard.

Nevermind the fact that using something like wireguard gives attackers something to target on your local device. 'oh look, the keys to the kingdom just sitting here... on disk... in a well known directory... so kind of people to just leave these skeleton keys just lying out in the open like this, its a great trick VPNs have pulled teaching everyone they're for security instead of privacy'

Admittedly, networking and network security isn’t my specialty

And I'll refer you back to my original posts about VPNs not being effective security measures and how you should stop quoting dogma.

Its perfectly fine you're using one, just stop spreading misinformation that they're for security in any manner. you're just using it to poorly plug security issues down stream in jellyfin.

fun fact: did you know that the encryption in the bittorrent protocol is basically useless and has major performance impacts when enabled?

also fun fact: did you know most networks get compromised by attacking the router itself first? you know the easiest thing to secure in the first place from a complexity standpoint? making this entire discuss pointless?

in real terms: try retrovibed at some point its still early days for it but its UX is designed around dealing with a lot of these issues.