What I haven’t found is a way to restrict access to known devices, such as MAC address, so that big companies don’t sue me to death. Yes, I know Jellyfin has a login prompt, but I would prefer better security beyond Jellyfin as a just in case.
What I haven’t found is a way to restrict access to known devices, such as MAC address, so that big companies don’t sue me to death. Yes, I know Jellyfin has a login prompt, but I would prefer better security beyond Jellyfin as a just in case.
I use Wireguard for my private online stuff, that works nicely. Expose Jellyfin only on the loopback address and use Nginx to forward your domain to it, then setup your DNS entry to be the VPN address of your server. Just be aware that if you have your own local DNS server then you might need to configure it to allow serving up DNS entries with private network addresses in them, as these are often blocked for security reasons; or else just modify your /etc/hosts equivalent to manually add the mapping.
Does it require you to run a VPN app on your phone constantly and does that cause troubles?
It's not ideal, since the password's obviously saved in any user's browser history, but it's less of a pain than dealing with a VPN, especially since I let friends use the server, and it's secure enough for my threat model.
Hopefully you at least have something like fail2ban installed?
My threat model does not include someone using an nginx zero-day to find out what movies I'm watching.
If you don't have the confidence to open up port 443, that's fine of course, but I have the confidence in my abilities and setup to open up 443 and know that it's secure enough for my threat model.
Like, the nginx config is a single location block with a 30-character-plus random string in the path as the password, it's running on nixos with an automated `nix flake update` bot that updates and redeploys the server every week so nginx and linux get updated over time, I get an email if the `nixos-rebuild build` fails after the automated update so I know to fix it.
I'm not particular worried about automated scanners.
It's super simple to set up, you can do it in 15 minutes. Install Tailscale on your Jellyfin server and on your personal devices, create a tailnet and connect them to it. That's it, you're done. You can now access Jellyfin from any of the devices using the Tailscale IP or hostname of the Jellyfin server.
Unfortunately, oauth doesn't work since the jellyfin clients (like the android tv client, iOS client, etc) don't understand oauth.
Using VPNs is annoying if you want to share it with a friend, or you want to use it on a random third-party device, like a TV in a hotel or something.
I think all Jellyfin clients all support appending a path to the URL, so adding a password in the form of a long random path works pretty well in my opinion, i.e.
https://my-jellyfin-server.com/ahY9eig3/
And you can then just have the server return 404 or such to all other requests, you can send the link like normal to friends, and you can manually type it in if you need to.That should be enough to avoid some random copyright scanner.