I bought Plex pass years ago for £79. The new price of $749.99 is INSANE.
No wonder all the cool people are using Jellyfin.
I bought Plex pass years ago for £79. The new price of $749.99 is INSANE.
No wonder all the cool people are using Jellyfin.

Isn’t jellyfin full of security vulnerabilities? (Not to defend Plex, just a thought. This is why I don’t have a video streaming server at all.)

You can avoid most security issues (with any sort of server) by not exposing it publicly. Use a VPN like Tailscale to connect remotely. If you share the server with friends or family, share it with them over Tailscale and use an ACL to configure which services they can access on your server.

It’s a good practice to NOT expose services to the internet unless it’s really needed. If they’re only for your use, then the entire world doesn’t need access. This isn’t specific to Jellyfin.
All software has the potential to have security issues.

If a service is publicly accessible, anyone can access it. Even if it’s secured, there can be security issues in the auth layer of the app, improperly secured endpoints, etc.
If a service is only available over VPN, nobody can access it unless they’re on the VPN. The service isn’t visible over the public internet and other people won’t even know it exists. You can require two factor auth to connect to the VPN.
I’m not sure why you seem to think that a private network isn’t more secure than a public network. There’s a reason why practically every company requires people working remotely to connect to a VPN to access company resources.

I never said anything about using the VPN as an ACL. All I said was to only expose the service over the VPN. That doesn’t necessarily mean that the app doesn’t have authentication or authorization.
I’m also only talking about residential use cases, where it’s a common practice (when not using a VPN) to just expose everything via port forwarding. Businesses aren’t setting up Jellyfin on their servers.
true, fun fact a VPN is also an application with an auth layer. dun dun dun!
Sure, but someone would have to first get on the VPN, and then find vulnerable apps once on the internal network, as opposed to just scanning the internet for public-facing vulnerable systems. Wireguard (and thus Tailscale) doesn’t respond to port scans at all - it only responds to packets that are signed with a known key.
Admittedly, networking and network security isn’t my specialty so I’m absolutely sure you’ve got more knowledge in this area.
Was any justification provided for a nearly 10x price increase!?
Glad I started with Jellyfin

It’s because lifetime licenses aren’t sustainable. I’m surprised they still offer it.
Plex is an actual company that has an office and employees, so they have recurring costs every month. A lot of people already have lifetime licenses that they’re not likely to receive any more revenue from. It’s likely they’re increasing the price to help recoup costs or convince people to subscribe to a monthly subscription rather than get a lifetime license.
I tried Plex once, before I knew about jellyfin. I just wanted an open-source self-hostable media server with my own media.
When I tried it, after installing Plex, I was presented with a login for a Plex hosted account. Iirc that was optional and I skipped it, after that came the nags for Plex pass. Piss off. That’s exactly the opposite of what I wanted out of something like jellyfin.
Oh yeah and apparently you can’t stream remotely without a subscription either? If it were a feature they had to spend time on I’d still not want to use it, but I’d understand at least.
From the application’s point of view, there is no difference between internet and intranet access. I just saw that downloading the media you already own, using your own infrastructure, requires an even more expensive subscription.
How tf did people stick around with this shit for so long.
The same reason most foss projects are barren. Plex focuses on ease of use and giving people what they want. Users mostly don’t care about the sub. It’s easy to use and works.
Meanwhile jellyfin doesn’t have a remote first interface that isn’t absolute dog shit and I need to set up a reverse proxy and potentially idp to get the ability for my family to log in.
This shit isn’t hard. The answer to the community is, make the product better, and start bundling shit in. But I’m sure I’ve already offended some nerd who thinks this is all just so easy and requires no work to tell me I just need to learn Linux better. And that putting in a reverse proxy by default will make maintenance a pain and I just have to put portainer and LE to fix it.
The shit y’all are bitching about is the problem.
Most FOSS projects are barren? Huh
I’m here to say it’s all very easy and requires no work.
Seriously, you literally just install Jellyfin (or run it in Docker), set up nginx with certbot and make a port forward on your router. Zero maintenance at all.
Any LLM can give you a complete step-by-step guide that takes 10 minutes to follow if you don’t know what you’re doing.
I cannot understate how bad of an idea it is to expose something to the Internet when you don’t know what you’re doing.
Jellyfin is not designed to be exposed directly. They have a number of outstanding security issues. You should really use a VPN to access your local network instead.
ADHD linux zealots will argue anything, no matter how stupid, if you dare hold any comparison to a commercial product. It’s literally built into their ADHD brains need to argue and be right.
They will sit there and argue insane shit and pretend like most people have a desktop sitting in their living room much less setting up an entire *arr stack with reverse proxy. And then scream at you when you say that sounds like work I don’t have to do for less than a hamburger meal.
It’s easy bro, just learn docker, get it set up so that services boot at launch, and I’m sure nothing will never break or need to be updated again.