this post was submitted on 22 May 2026
210 points (97.7% liked)
Selfhosted
60253 readers
868 users here now
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
There's still a bunch of outstanding API security issues last I checked, so it's not secure enough for me to open to the web.
Teaching friends and family to use it with a VPN is a whole another can. Also, you'll have to make sure the VPN is secure and users don't have access to the rest of your network...
and then you'll have to deal with client apps/access for mobile, android boxes, TVs, and Chromecasts...
I got lucky with the Plex Pass too so I can only ride this out to the end until Jellyfin catches up. (also, I'm not good to contribute code)
Any particular API security issues? Never considered exposing Jellyfin, but can certainly understand how it simplifies access.
This was the security report from awhile back:
https://github.com/jellyfin/jellyfin/issues/5415
Lot's of things have been fixed but theres still much to do. The issue was broken down to smaller issues for tracking and I check back every once in a while.
Even if there were no security issues, exposing jellyfin is also another can... choice of:
Don’t you have to open a port for Plex remote access?
You do not but you'll be severely bandwidth limited. It'll go through their servers if a port can't be opened.
Oh I forgot about that option
That sounds like you do have to open one then? Otherwise you are "severely bandwidth limited" and who wants that?
I think the difference is Plex offers a web address you can use for logging into Plex and for sharing it with others. So, you get a friendly admin interface with oauth for logging in from other popular services as the Plex user getting setup.
https://sh.itjust.works/comment/25489149