I bought Plex pass years ago for £79. The new price of $749.99 is INSANE.

No wonder all the cool people are using Jellyfin.

  • jatone@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    2
    ·
    edit-2
    17 hours ago

    thats, like, your opinion man. frankly slapping a VPN on top of everything else doesnt improve your security posture unless you have the skills to manage that system on top of everything, including ongoing validation that its configuration is restricting what you want it to.

    a robust authn/authz at the application layer is what secures your environment. VPNs are just slapping a wall around your network that is trivially penetrated by the browsers (and their extensions) within your network.

    stop spouting dogma seriously doesnt make you look intelligent. personally the only reason I bother with a VPN is so I can leverage my local networks dns to access services anywhere. its not for security.

    • dan@upvote.au
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      16 hours ago

      If a service is publicly accessible, anyone can access it. Even if it’s secured, there can be security issues in the auth layer of the app, improperly secured endpoints, etc.

      If a service is only available over VPN, nobody can access it unless they’re on the VPN. The service isn’t visible over the public internet and other people won’t even know it exists. You can require two factor auth to connect to the VPN.

      I’m not sure why you seem to think that a private network isn’t more secure than a public network. There’s a reason why practically every company requires people working remotely to connect to a VPN to access company resources.

      • jatone@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        edit-2
        14 hours ago

        If a service is publicly accessible, anyone can access it.

        false.

        Even if it’s secured, there can be security issues in the auth layer of the app, improperly secured endpoints, etc.

        true, fun fact a VPN is also an application with an auth layer. dun dun dun!

        If a service is only available over VPN, nobody can access it unless they’re on the VPN.

        which is basically anyone soon as a browser is in the mix. which it is.

        I’m not sure why you seem to think that a private network isn’t more secure than a public network.

        because I’ve done network hardening and know that they are only as secure as the devices and people that are a part of that network. it has nothing to do w/ private vs public and everything to do with what you do while within that network.

        There’s a reason why practically every company requires people working remotely to connect to a VPN to access company resources.

        uh huh. heard of lemmings? appeals to authority? etc, etc, etc. thats you right now. federal agencies guidelines regarding VPNs search terms for you: Federal Zero Trust Strategy (notably via OMB Memo M-22-09). Individuals like yourself are literally the reason they had to release these updated guidelines. because people kept quoting out of date security practices from their old guidelines as ‘good enough for the feds must be best practices’

        like i said you dont know what you’re talking about. historical foot note: when the federal agency updated their recommendations regarding VPNs they were criticized by security experts for taking so fucking long to finally remove the misguided position that VPNs improve security that you hold.

        here is a relevant snippet for everyone:

        Regardless of the approach selected, agencies must move away from the practice of maintaining a broad enterprise-wide network that allows enhanced visibility or access to many distinct applications and enterprise functions. Accordingly, agencies should choose their zero trust approach early enough to permit them to align that approach with their plans for IT investment

        Literally use ‘authn/authz’ and dont rely on VPNs for ACL. Here is another gem from that memo for today’s lucky 10,000:

        Agencies must remove password policies that require special characters and regular password rotation from all systems

        and yet companies still put that nonsense into their security policies.

        • dan@upvote.au
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          6 hours ago

          I never said anything about using the VPN as an ACL. All I said was to only expose the service over the VPN. That doesn’t necessarily mean that the app doesn’t have authentication or authorization.

          I’m also only talking about residential use cases, where it’s a common practice (when not using a VPN) to just expose everything via port forwarding. Businesses aren’t setting up Jellyfin on their servers.

          true, fun fact a VPN is also an application with an auth layer. dun dun dun!

          Sure, but someone would have to first get on the VPN, and then find vulnerable apps once on the internal network, as opposed to just scanning the internet for public-facing vulnerable systems. Wireguard (and thus Tailscale) doesn’t respond to port scans at all - it only responds to packets that are signed with a known key.

          Admittedly, networking and network security isn’t my specialty so I’m absolutely sure you’ve got more knowledge in this area.

    • frongt@lemmy.zip
      link
      fedilink
      English
      arrow-up
      2
      ·
      17 hours ago

      The VPN isn’t “on top of” anything, it’s instead of everything.

      • jatone@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        2
        ·
        edit-2
        17 hours ago

        except its not. VPNs provide no real protection for a network. its literally undercut by any network connection that reaches beyond the wall it provides.

        VPNs are a routing simplification and privacy measure not a security measure. idiots try and use them as a security layer thinking they’re safer.