Earlier quoted context omitted.
What about it is insecure with regards to exposing it to the internet?
https://github.com/jellyfin/jellyfin/issues/5415 A lot of Jellyfin's API doesn't require any authentication at all, as an example.
> Is this a massive red-flag security risk that actively exposes your data to the Internet? No.
>
> At this point, this over-4-year-old issue has gotten posted to HackerNews more than enough times and gotten quite enough unhelpful peanut-gallery comments like those above..