Collection of potential security issues in Jellyfin This is a non exhaustive list of potential security issues found in Jellyfin. Some of these might cause controversy. Some of these are design fla...

What a load of absolute horseshit.

Because someone has to clean that shit up.
Edit: you said outside of that, so I will amend my comment to fun for someone could be ruining the fun for others who just want to sit and enjoy watching it.

If you're in this situation, you should keep it in the only truly safe location, your mind.

Wow. This is certainly one of the takes of all time.

They get rabies just like anything else. However, their body temp is so low that rabies cannot survive.

#confidentlyincorrect

Does your friend have a static IP? Unlikely considering that you have to pay extra for a static IP.

It isn't randomly generated. If you read through you would have known that.
Also, Rainbow tables.
tldr, Rainbow tables are precomputed lists of hashed values used to crack password hashes quickly. Instead of hashing each password guess on the fly, attackers use these tables to reverse hashes and find the original passwords faster, especially for weak or common ones. They're less effective against hashes protected by a unique salt.

The last set of comments is from 2024. These have not been addressed. The fact that it is possible to stream without auth is just bonkers.
The entirity of jellyfin security is security via obscurity which is zero security at all.
"As a cybersec researcher", the limp wristed, hand wavy approach to security should be sending up alarm bells. The fact that it doesn't, means that likely either, you don't take your research very seriously, or you aren't a "cybersecurity researcher".
"Thank you for this list. We are aware of quite a few, but for reasons of backwards compatibility they've never been fixed. We'd definitely like to but doing so in a non-disruptive way is the hard part."
Is truly one of the statements of all time.

I don't know who needs to hear this, but DO NOT EVER expose Jellyfin to the internet

Samesies. Best decision I ever made.


You should delete this comment.

Let's be honest... Most of these people are so far gone that even mass executions with be normalized.
"He's only.executing the bad ones!“

The difference is that PRESUMABLY you aren't utterly dependent upon it. If vscode utterly fucks your repo with a shit command, you'll not really have any trouble fixing it. That's the huge difference. The point is not that all GUI controls are always bad all of the time, the point is that you need to know what the hell you are doing in git as a basic tenant of developer competency.

I said that you are probably not very good. Your lack of git knowledge and your seeming inability to learn git means that you'll likely never be able to function effectively in a development team and will only succeed in holding everyone back. Your lack of knowledge of version control overall is a massive point against you from the outset.
If you're a solo developer and never need to collaborate with other developers then good for you, but you lack of version control knowledge means that you'll also probably end up being one of the ones crying that you lost 6 months of work because of stupid reason x y or z.
Read up on fallacies, I did not use one. Your pathetic attempt to shoehorn anything that I said into a no true Scotsman fallacy just shows that you also have poor communication skills.
Holy fucking shit. I didn't even catch the bit at the end. You really think that cli arguments are archaic??? I'm going to go ahead and assume that regex has you scared shitless as well. Fuck me, you are not a good developer.
Sidenote, something that will help you understand regex and you can test your strings against it in realtime, look up https://regexr.com/

The fact that you don't already know why and are dependent on GUI tools that you don't fully understand is the reason that you're probably not a very good developer.
Git is incredibly powerful. Knowing why and how is infinitely valuable. Nothing about git cli is archaic or even particularly difficult to understand. Also the man page is very excellent.

Just a heads up, it you don't know how to use cli git in 2025 you're probably a shit developer. There are undoubtedly exceptions, but I would argue not knowing version control intimately makes you a bad developer.

Plant your heel on the floor board. Use your ankle to regulate brake pressure.

Damn, just can't get enough of that earthy leather taste huh?

If you have Plex pass, this does not effect anyone using your server.
It's still a shit asshole move by them, but at least it isn't catastrophic. Hopefully by the time Plex starts to suck jellyfin will not blow chunks.

Let's talk about how we replace Biden
YouTube Video
Click to view this content.

let's talk about foreign policy games and classic games

YouTube Video
Click to view this content.

Biden "running out" of patience with Bibi as Gaza war hits 100 days
As I have repeatedly said... Just because Biden has repeated the US company line of unequivocal support for Israel, etc etc (Because even among democrats it's political suicide to say anything else). That doesn't mean that he hasn't been trying the entire time to get Israel to stop the bullshit. This is more or less a point for point list of a lot of the things that have been tried. It misses quite a few of the more notable ones, but it grabs enough so that you get the idea.

Let's talk about the evolving US position and changing relationships...

YouTube Video
Click to view this content.

Palestinian girl filming Israeli soldiers gets shot at in the West Bank

Watch "Palestinian_girl_filming_Israeli_soldiers_gets_sho_17r6zjd" on Streamable.

So let me refer to my "stop using antisemitic words" chart...
The Little Girl "Hamas Militant" was Filming "Threatening with a deadly weapon" Israeli soldiers from the safety of her own Home "Hamas Base".


Watch "CS2: Twerk into accidental tk headshot" on Streamable.

Was funny as hell


According to Speaker McCarthy, the impeachment inquiry of President Biden is "completely devoid of any merit or legitimacy." That's how he described an impeachment inquiry without a House vote—like the one we have today.

Top youtube comment: "This lady just slices, dices, and makes julienne fries out of republicans. "

Rep. Crockett: GOP is blind to Trump keeping documents 'in the shitter'

Rep. Jasmine Crockett, D-Texas, criticized Republicans for pursuing an impeachment inquiry against President Biden while claiming they were turning a blind eye to former President Trump's handling of classified documents at Mar-a-Lago. » Subscribe to NBC News: http://nbcnews.to/SubscribeToNBC » Wat...

2 Minutes of Rep. Crockett dressing down republicans and their pathetic attempt to use smoke and mirrors in order to impeach Biden, you love to see it.

Does anyone know of a trustworthy and curated list of qanon sites that I can use for my pihole(s)?
So, until recently, I have been using https://github.com/rimu/no-qanon/blob/master/hosts.txt
However, as some issues that I have opened have shown, there are a bunch of left wing and progressive sites on this list ( https://github.com/rimu/no-qanon/issues ). I no longer think that it is trustworthy. Especially after reading some of the repo owners replies. Intentionally added was t.me which is a generic url for any telegram group. Discordapp.com was on it at one point.
Oy Vey. It's clear to me that the owner of this repo is not actually spending much time actually curating this list and instead it's just a shotgun approach. Does anyone know of a good alternative?

Climate Protesters blockade the road to burning man, stranding miles of cars in the middle of nowhere in the heat of the desert endangering lives, Indian Reservation Rangers ram blockade

YouTube Video
Click to view this content.

Jessica Watkins (mtf) sentenced to 8 years in a men's prison for Jan 6 involvement

YouTube Video
Click to view this content.

LMG are some Shady ass motherfuckers. Look at this shit...


You know, this is some shit that I expect when dealing with some shady asshole on ebay, but LMG?
Bro... Are you ok?
I always wondered if Linus was actually a slimy POS, but this Billet Labs situation has cemented it for me. If you haven't watched the Gamers Nexus followup video, definitely watch it.

The Problem with LMG

YouTube Video
Click to view this content.
My personal thoughts
At first it came off a bit whiney, but I watched the entire thing and I'm glad I did. It shows a pattern of carelessness and in some cases complete douchebaggery of LMG.
What they did to Billet Labs is absolutely un-fucking excusable. LMG and Linus, in particular, needs to be mercilessly shamed for that until Billet Labs gets a clear and unequivocal apology and paid restitution for damages. Fucking shameful. What a bunch of pricks.
Video Description
This video is not monetized. This video covers our serious concerns regarding the data accuracy of Linus Media Group, including Linus Tech Tips, ShortCircuit, and TechQuickie, particularly as it relates to rushing content out the door to favor -- by staff's own admission -- quantity over quality. As the company continues to expand into its LTT Labs direction, the importance of accurate data increases; however, even as 'only' entertainment, there are still certain responsibilities to the consumer and the manufa

The Insane Plot Armor of Cats

YouTube Video
Click to view this content.
I love this video so much 😂


Support via Patreon: https://www.patreon.com/beautfc The Roads with Beau: https://www.youtube.com/channel/UC_x7nc3Vi4BPgmNnMsz774A Check out the store. Stickers, mugs, hoodies, shirts, etc. https://teespring.com/stores/beau-of-the-fifth-column Check out the podcast: https://anchor.fm/beau-of-the-...

Beau of the Fifth Column discusses Trump's truth social post, the DOJ's response, and more...

Mark Rober vs Thea Ulrich's Glitter Bomb Puzzle

Will @MarkRober as in, the internet's most FAMOUS glitter bomber figure out my puzzle?? Or....will he finally get glitter bombed himself?? I hand deliver a huge glitter bomb puzzle to Mark Rober and PUT HIM TO THE TEST. CONNECT WITH ME ON IG: @theaulrich MY INSANELY SKILLED TEAM: Mechatronic...

Thea Ulrich made a glitter bomb puzzle for former NASA engineer and glitter enthusiast Mark Rober to solve with hilarious results

Minneapolis police federal probe reveals that police have been doing exactly what minorities accuse them of doing

YouTube Video
Click to view this content.