Jump to content

How to prevent remote public internet anonymous access to videos


Recommended Posts

Posted

Hi, it's something we need to address in a future update. It will require changes to a number of apps. Thanks.

magicdelux
Posted

Thanks for the prompt reply.

 

Just to be sure. Currently there is no way of preventing anonymous access to videos on the emby server?

Posted

Well the person would have to know a video id to begin with.

magicdelux
Posted

Sure. But writing a simple script which enumerates the id and tries to download the video should not be difficult to create.

 

At least, this is a simple way for sharing a video by url  ;)

  • Like 3
Posted

Technically it could be done for API keys as well. But that's a lotta enumeration of chars and ints to get one possible, unknown media item.

magicdelux
Posted

Technically it could be done for API keys as well. But that's a lotta enumeration of chars and ints to get one possible, unknown media item.

 

 

Sure. But API keys aren't by default numerical and incremental  ;)

  • Like 1
mastrmind11
Posted

can't you just block unknown ips at the edge of your network.

Gilgamesh_48
Posted

can't you just block unknown ips at the edge of your network.

 

I would think the easiest solution and the one I use is just to turn off remote access. There is no one I like well enough to share my library with. I am sure those feelings are returned by many. As I have aged my crotchety factor has increased dramatically and crotchety is not a good way to enamor others to one.

 

That is that will work unless the above hack works even with remote access off. If that is the case then I guess the problem even impacts me. That would make me sad. ):

Posted

Interesting indeed....  :wacko: 

 

Emby server dashboard doesn't have a clue that anonymous access is taken place, while a big EMBY hole is letting Emby content through.

Even an Emby server setup with Cloudflare managed domain with SSL gets useless now (IF no IP white and/or blacklisting is in place), when Emby content can be accessed WITHOUT authentication :o

 

Shouldn't this be a HIGH priority FIX for the Emby Devs ?!

  • Like 3
Posted

Wowww, things are getting even more interesting......

 

It's even doing transcoding with anonymous access, WITHOUT indicating in dashboard that Emby media is getting transcoded... :blink:

  • Like 3
Posted

We'll close it up for the next release. Thanks.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...