• 0 Posts
  • 127 Comments
Joined 3 years ago
cake
Cake day: November 16th, 2023

help-circle
  • I feel like you’re overestimating the number of people who buy a Google or Samsung device because they want to install third party apps. A lot of them buy an Android device because they just don’t like Apple. Most folks don’t install anything from anywhere other than the Play Store because they don’t even know there are other choices.

    In general, people’s preferences are most often born from whatever their first device was, and nothing more, with little interest in what they can do with it other than what’s required of them.


  • Like a well oiled machine by the end of it. You’d submit some information; likes, interests, hobbies, etc. and then you’d be paired with another participant based on a random draw with some selection restrictions (i.e. national vs international). You had roughly a month from being matched with someone to get a gift shipped out.

    It was particularly fun to get to know the person both through their suggested interests but also to take a peek at the communities they participated in. You could post gifts you received to a gallery (which I wish they archived), confirming receipt and letting the sender know your appreciation.

    Some people sucked, and wouldn’t deliver on their end, so there was a volunteer “elf” system that would let folks become secret santas for any recipient that was let down by their own santas. Not sending something generally got you banned from future participation, and filling the elf role would gain you general reputation within the program






  • I’d be trading one smart mess for another, and paying more money to do it. My TV is from 2018, and when it’s hit 10 years old maybe I’ll think about it. But right now, there’s no reason for me to rush out and find something else when I know the Roku can’t phone home and Jellyfin works like I want it to. Besides, whether an account is required or not, I wouldn’t trust Google any more than Roku/Fox. I don’t know what I’ll buy next, but I’m not prepared to think about it right now.


  • It saddens me, as I liked Roku for being the least ad-ridden option of the bunch. The apps don’t advertise to me as I hover over them, and a DNS change renders the single poster-style advert on the screen inert.

    I’ve got a couple Roku devices that realistically I’ll continue to use unless I manage to find a hospitality TV or something to replace my TCL with. I’d just use my PS5 if it weren’t for the fact Sony won’t approve Jellyfin’s app


  • Some clickbait nonsense. Genuinely.

    This isn’t anything like what its trying to spark fear over. it requires a credential stuffing attack that needs the following:

    1. A management interface exposed to the internet
    2. A lack of controls related to who can log in and where from
    3. The use of SSLVPN that does not utilize SAML or another form of OAuth

    After all of that, and presuming they have a set of working credentials that have not been changed after the credentials were exposed in a breach, can they perform an attack.

    Like with anything, working admin credentials will get you to a CLI, and from there you can do a lot. Protect your management interfaces. Do the bare minimum.






  • I don’t feel bad for Microsoft, but responsible disclosure is about more than that.

    It’s ethical. It gives the developer time to correct an error before it has the potential to affect anyone using their products. When you don’t follow that process, whether one set out by the developer, or a best effort on your part, you are now contributing to the potential harm caused by that vulnerability.

    This isn’t universal, and I have no doubt that Microsoft is also partly to blame, but there’s a significant element of attention seeking in the mix here. They could have reached out to other security researchers, validated the findings in private and found another channel to work through. Maybe he tried, but largely it seems like his actions are retaliatory and broadly harmful to anyone who has to administer these products.

    I have a lot of respect for security researchers. My job relies on the work they do and the skill it takes to do it. But part of that relies on doing things in a way that minimizes potential harm.


  • I was mostly making the comment in jest. I do rename, but my folder structures, as someone who downloads everything manually based on what I want to watch rather than doing the automated *arr stuff leaves it in directories only I consider sensible.

    I have Jellyfin behind a reverse proxy that lives in a DMZ and a WAF to go with it. I’m sure there’s still room for watching an unauthenticated stream because I forgot to rename a folder somewhere, but it’s not exactly an attack vector I care about. I’m more concerned about DDoS or impersonation attacks, which I also attempt to mitigate via an LDAP implementation behind the scenes.

    It’s not perfect, but it’s the best effort I can make at the moment.





  • The trouble for me in this sense is that I have an AVR, I’d like CEC to work and I’d like an interface that was actually designed for a remote.

    I’ve done this before, and frankly it’s just not as good. It works reasonably well, but an HTPC has never served as well as a purpose built piece of hardware or software, even if that’s the TV itself.

    If I really wanted, I could buy a hospitality TV and use the RS232 to control it from the PC but I’m tired thinking about the ways that’s likely to fail.