# Kodi (Home Theater Software)

**URL:** https://discuss.privacyguides.net/t/kodi-home-theater-software/25866
**Category:** Tool Suggestions
**Created:** 2025-03-17T17:20:41Z
**Posts:** 101

## Post 1 by @jonah — 2025-03-17T17:20:41Z

### Check this box to affirm you have no conflict of interest.

on

### Website

> **[Open Source Home Theater Software](https://kodi.tv/)**
>
> Kodi is a free media player that is designed to look great on your big screen TV but is just as at home on a small screen.

### Short description

An open-source home theater interface. You can use it with local media or various plugins.

### Why I think this tool should be added

It would be a privacy-respecting alternative to Fire TV, Apple TV, Roku, etc.

### Section on Privacy Guides

Media Player Software

---

## Post 2 by @jonah — 2025-03-17T17:21:07Z

I’m creating this forum topic to discuss changes being proposed in this PR with the rest of the community, because it is missing a topic here.

[https://github.com/privacyguides/privacyguides.org/pull/2938](https://github.com/privacyguides/privacyguides.org/pull/2938)

---

## Post 3 by @fria — 2025-03-17T17:28:35Z

Kodi’s app lacks the [App Sandbox](https://developer.apple.com/documentation/security/app-sandbox) on macOS as well as [disabling library validation](https://developer.apple.com/documentation/bundleresources/entitlements/com.apple.security.cs.disable-library-validation) which is an important security feature (in Apple’s own words). They offer an official [flatpak](https://flathub.org/apps/tv.kodi.Kodi) which is great to see, but flat hub warns about it being potentially unsafe. Media players are vulnerable to malicious files so it’s important for them to be as secure as possible.

---

## Post 4 by @jonah — 2025-03-17T17:32:50Z

This is also somewhat relevant to the [VLC](https://discuss.privacyguides.net/t/vlc-media-player-software/25865) discussion, but I feel more strongly about listing Kodi and other private Smart TV alternatives than PC media players so I’ll continue it here.

I think playing _untrusted_ media files is actually a _very_ niche use-case in this situation, because this is only used with locally owned media, and isn’t dynamically downloading media (like a web browser) or accepting media from random senders (like an instant messenger).

The privacy benefits of protecting your media watching telemetry from commercial streaming services, Smart TV manufacturers, and other parties like this clearly outweigh these security concerns for most people in my opinion.

---

## Post 5 by @fria — 2025-03-17T17:35:54Z

> [@jonah](#):
>
> I think playing _untrusted_ media files is actually a _very_ niche use-case in this situation

I disagree, people download media off of unsafe torrent sites and play it locally all the time. Your media player is your first line of defense, it should have the maximum protections.

---

## Post 6 by @anon39279085 — 2025-03-17T17:36:42Z

Thank you guys, I was gonna do it later since I was at work but you did it earlier  
anywho I have expressed before

I think kodi does handle the permissions better on the flatpak version so I am kinda opposed to removing it, However what does everyone think

---

## Post 7 by @anon29374801 — 2025-03-17T17:46:01Z

might be off topic but since suggestions for a new section just started popping up I figure maybe its ok…

@jonah Is this section going to be meant for playing your own personal media locally only or would something like [Torbox](https://torbox.app/) be worth considering?

- open source
- accepts XMR
- works fine with VPNs

I understand debrid services are typically associated with piracy but thats not their sole use. Having options to host and download legally obtained media without massive hardware costs might be useful in this type of section.

---

## Post 8 by @jonah — 2025-03-17T17:53:48Z

This section would only be for software, so service providers would be a separate category. You can always open a new suggestion at any time, even for categories that don’t exist yet, but something like that wouldn’t be added in this particular PR.

---

## Post 9 by @jonah — 2025-03-17T17:55:22Z

This seems pretty speculative to me, I totally disagree with the premise that most people with local media obtained it through piracy.

For people who obtain their media via ripping DVDs/CDs/etc that they purchased or obtained from a library or something, this is a risk not really worth worrying about, because commercially available media content is just not going to have this problem.

It is not really our responsibility to cover this either. Whether a media file is trusted or not is at the discretion of the owner of that media, not us…

---

## Post 10 by @anon36940904 — 2025-03-17T17:56:55Z

Pragmatically, it is true that media was acquired through piracy for the most part for the vast vast majority of people.

> [@jonah](#):
>
> It is not really our responsibility to cover this either. Whether a media file is trusted or not is at the discretion of the owner of that media, not us…

Yes this I agree with.

---

## Post 11 by @fria — 2025-03-17T17:59:59Z

I didn’t say that, I said people torrent things [all the time](https://cybernews.com/privacy/american-adults-torrent-movies-tv-shows/). It’s well known.

> [@jonah](#):
>
> It is not really our responsibility to cover this either. Whether a media file is trusted or not is at the discretion of the owner of that media, not us…

As a privacy and security focused website, it’s our job to offer the most private and secure options.

---

## Post 12 by @jonah — 2025-03-17T18:02:22Z

Yes, and for trusted local media content what is the risk of using Kodi?

---

## Post 13 by @fria — 2025-03-17T18:03:50Z

Everyone’s definition of trusted is different. For a large amount of people “trusted” media is something they torrented. The trusted vs untrusted distinction doesn’t really matter, if it wasn’t trusted they wouldn’t play it in the first place. You could make the same argument for software: just run “trusted” software and you’ll never get a virus. No need for sandboxing or any security measures.

---

## Post 14 by @anon36940904 — 2025-03-17T18:07:41Z

> [@fria](#):
>
> if it wasn’t trusted they wouldn’t play it in the first place.

A little pedantic here because people do this with torrented media because they are not evaluating it for if they get a malware or not. They just want the media and watch the movie no matter what. Technically, your point is logically sound but doesn’t work from anecdotal evidence and pragmatically thinking/evaluating it.

---

## Post 15 by @fria — 2025-03-17T18:10:33Z

The way I see it, as soon as you’re relying on humans to manually figure out whether something is malicious or not, you’ve failed. Apps and platforms should be designed to be as secure as possible because people will run malware.

---

## Post 16 by @anon36940904 — 2025-03-17T18:11:07Z

Yes yes - a good point. In a perfect world, I am with you. But we don’t live in it.

I am just taking a more realistic and practical approach to this discussion and thinking behind it.

---

## Post 17 by @jonah — 2025-03-17T18:12:29Z

We can simply define _our_ definition of the word trusted on this page so that readers know what we mean when we say “only use this software with trusted media.”

For the majority of people who are using _my_ definition of trusted and are only playing ripped content…

> [@jonah](#):
>
> The privacy benefits of protecting your media watching telemetry from commercial streaming services, Smart TV manufacturers, and other parties like this clearly outweigh these security concerns

* * *

I don’t think you are really running a proper threat model / cost-benefit analysis here. Malicious media files only really show up in targeted attacks in the real world. There is no doubt that the risk _exists_, but it is **outweighed** by the privacy benefits in this case, so we should lean towards a positive recommendation.

---

## Post 18 by @fria — 2025-03-17T18:18:48Z

> [@jonah](#):
>
> Malicious media files only really show up in targeted attacks in the real world.

They are [exploited](https://securityintelligence.com/killer-music-hackers-exploit-media-player-vulnerabilities/) in non-targeted attacks all the time. This is something that affects a lot of people. I’m not really sure what the privacy benefit is, kodi is just a nice interface to play your media. You can always just plug a computer into your TV and play media that way even if it’s not pretty.

> **[Free file converter malware scam "rampant" claims FBI](https://www.bitdefender.com/en-us/blog/hotforsecurity/free-file-converter-malware-scam-rampant-claims-fbi)**
>
> Whether you're downloading a video from YouTube or converting a Word document into a PDF file, there's a chance that you might be unwittingly handing your personal information straight into the hands of cybercriminals.

Here’s something that’s very common that’s not even related to torrenting.

---

## Post 19 by @anon39279085 — 2025-03-17T18:21:23Z

I feel like honestly what you’re describing reminds me of the Firefox situation  
as @jonah said with this, It is possible and should be cautious but there hasn’t been any real world scenario that has happened when it comes to the files

What I also agree with Jonah is that the files itself is the responsibility of the user and nothing a media player can do to mitigate this. Of course if they’re right on maintained which kodi and VLC are they would have addressed enough of the vulnerabilities if not respond to em but getting files is a whole different story.

As always qe don’t encourage piracy, I really do suggest people own their media (such as buying DVDs) and ripping the media they own rather than pirating but again the way these media files were to get is honestly beyond our control.

---

## Post 20 by @anon39279085 — 2025-03-17T18:22:29Z

Kodi expands beyond this  
it has an interface that is like the steam big picture but for media and games and does natively support controllers, especially IR ones and probably controllers too.  
and with plugin support but as I placed in the cautionary tale but usually they should be just fine.  
You remember these Insecure TV Boxes we used to get that probably came with pirated movies or otherwise can act as a TV but also has the interface? That’s what Kodi is replacing.

---

## Post 21 by @anon39279085 — 2025-03-17T18:27:10Z

the link you shared seems to stem from conversion, not the files itself that someone rips or installs (at their own discretion)

And honestly using to compress and convert files I’ve never honestly had Malware being put to them

Again stems back to the whole “Firefox Insecure” equivalent discussion.

---

## Post 22 by @jonah — 2025-03-17T18:28:01Z

Not only is this example not related to torrenting, but it is not even related to this topic at all?

There are clear benefits to making privacy-respecting behaviors more user-friendly too, UI/UX is a _critical_ component of privacy actually.

---

## Post 23 by @fria — 2025-03-17T18:28:25Z

They’re sites that let you convert file formats or rip from YouTube/Soundcloud etc. The end result is a local media file that you play in your media player which can be malicious. Again this is something people do all the time.

---

## Post 24 by @anon39279085 — 2025-03-17T18:30:11Z

that is true but again it’s not something we can control with recommending media players outside of letting them know things like:

- Using trusted sources
- Ripping the media you buy, not somewhere you find off the internet  
etc.

Basically we encourage the safe practices, but otherwise again this is beyond our control except this.

---

## Post 25 by @jonah — 2025-03-17T18:30:15Z

That is not what the article is discussing. The article is discussing media conversion executables that people **download and run** instead of using ffmpeg or Handbrake.

This article really highlights the need to promote this sort of much safer software, because otherwise people will download untrusted media players.

I _would_ agree that the risk of downloading malware to play/convert media is far greater than the risk of downloading malware-laden media that exploits your otherwise trustworthy media player.

---

## Post 26 by @fria — 2025-03-17T18:32:16Z

I just want Kodi to use the basic security features baked into the operating system, I’m not asking for much. If they did that I’d be fine with it. Part of our evaluation should be security no?

---

## Post 27 by @anon39279085 — 2025-03-17T18:35:37Z

Let’s see  
according to [standard criteria](https://www.privacyguides.org/en/about/criteria/):

> Security: Tools should follow security best practices wherever applicable.

_wherever applicable_

Now this may be just the vague sounding to assumption but if I am correct on this, whenever applicable means that an application shouldn’t be _inherently_ insecure, I don’t think PG wants to do full on security, there needs to be a balance and I feel that Kodi and VLC delivers this balance  
unless I am wrong about the statement, feel free to chime in.

---

## Post 28 by @fria — 2025-03-17T18:36:34Z

Best practices would be enabling the App Sandbox, not disabling other security features etc. It’s a pretty low bar to clear.

---

## Post 29 by @anon39279085 — 2025-03-17T18:39:47Z

honestly it’s why as an author I do encourage people chime in, Most people would much rather have a safe alternative than not and if the votes on  
[Television and Projector Guide](https://discuss.privacyguides.net/t/television-and-projector-guide/23745) is anything to go by I think people are demanding this.  
Now of course i could be wrong which is exactly why I encourage it.

---

## Post 30 by @fria — 2025-03-17T18:40:32Z

> [@jonah](#):
>
> That is not what the article is discussing. The article is discussing media conversion executables that people **download and run** instead of using ffmpeg or Handbrake.

They’re discussing both:

> To conduct this scheme, cyber criminals across the globe are using any type of free document converter or downloader tool. This might be a website claiming to convert one type of file to another, such as a .doc file to a .pdf file. It might also claim to combine files, such as joining multiple .jpg files into one .pdf file. The suspect program might claim to be an MP3 or MP4 downloading tool.  
> [https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam](https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam)

Anyway you’re downloading and running code when you use a website anyway the difference is that a web browser has sandboxing.

---

## Post 31 by @jonah — 2025-03-17T18:42:08Z

> [@fria](#):
>
> Part of our evaluation should be security no?

I think that “part” is the key word, and this particular risk shouldn’t trump everything else about the application. With less likely risks like this we’ve historically just noted them on the page instead of completely rejecting the tools. It is a different situation if there are 1:1 alternatives that are safer.

* * *

Here is an interesting guide we could potentially update and publish to our blog to cover not just Kodi but other macOS apps generically:

> **[Creating a macOS Sandbox to run Kodi | myByways](https://mybyways.com/blog/creating-a-macos-sandbox-to-run-kodi)**
>
> myByways - the road less travelled by C.Y. Wong

There are probably similar methods on other operating systems. I think that noting how to do this on various platforms for the people who evaluate the risks you’ve brought up to be a part of their threat model would be worthwhile.

* * *

> [@fria](#):
>
> You could make the same argument for software: just run “trusted” software and you’ll never get a virus. No need for sandboxing or any security measures.

The reality is that the operating systems people use currently don’t require sandboxing, and this is an OS issue, not _entirely_ an application issue. If we take this argument to its logical conclusion, you would be saying that we shouldn’t recommend _running a computer at all_, because operating systems leave open the possibility of running malware to the user.

The choice to run anything you want on your computer is the same choice you have to play any media you want on your media player. It’s not a choice we make _for_ people, all we can really do is educate them on the risks and consequences of certain choices.

---

## Post 32 by @anon42475305 — 2025-03-17T18:44:16Z

> [@anon39279085](#):
>
> Most people would much rather have a safe alternative than not

I seriously doubt that. Most people want Privacy Guides to uphold their rare integrity. The attitude has always been (from my perspective) that compromising for the sake of making a recommendation is unacceptable and, consequentially, that no recommendation is better than a bad one.

---

## Post 33 by @fria — 2025-03-17T18:44:31Z

> [@jonah](#):
>
> Here is an interesting guide we could potentially update and publish to our blog to cover not just Kodi but other macOS apps generically:

This is using `sandbox-exec` which is deprecated and shouldn’t be used.

> [@jonah](#):
>
> The reality is that the operating systems people use currently don’t require sandboxing, and this is an OS issue, not _entirely_ an application issue. If we take this argument to its logical conclusion, you would be saying that we shouldn’t recommend _running a computer at all_, because operating systems leave open the possibility of running malware to the user.

The fact that it isn’t required is the whole reason we need to highlight apps that _do_ use it. We don’t have to worry about it on iOS since apps are required to be sandboxed anyway. The argument that asking for some basic security measures from app developers means you can’t use a computer at all is an argument ad absurdum and makes no sense. I’m just doing some basic surface-level looks at the app to see some easy features we should expect from any app.

---

## Post 34 by @jonah — 2025-03-17T18:46:09Z

Yes, but in this case my overall point is that most people are **not** making a compromise by using Kodi in the first place.

Edit: And _certainly_ not a compromise compared to other media playing apps like Netflix or other commonly used streaming services.

---

## Post 35 by @anon39279085 — 2025-03-17T18:46:23Z

and personally I feel that with Open source builds being reproducible, I think it adds a layer of trust, abd as you shared in the article, It meams that you could actually implement the sandboxing if you genuinely want to by turning it on  
that ia if savvy enough and for the rest they should have a relatively safe software to run their media on.

And as we said before, we can’t control about the files for the user, other than if fria wanta we can add suggestions towards _safe_ measures of obtaining media which I mentioned a few examples.

Now if I sound like doubling down, that’s fine I totally get it but it’s not without merit and more importantly thete needs to be a balance, which again they do deliver but again it varies and maybe the best we can do is add warnings…

---

## Post 36 by @anon39279085 — 2025-03-17T18:47:53Z

I ask you what compromise if it’s not rude, for security?  
Remember we used to Recommend DivestOS as a harm reduction OS, not a Secure OS like Graphene, I don’t understand the double standard here honestly.

again by all means, express your thoughts, I appreciate it.  
Noy to mention the whole Firefox security discussion, I think this is being similar now but I could be wrong but still.

---

## Post 37 by @anon42475305 — 2025-03-17T18:52:31Z

> [@jonah](#):
>
> The reality is that the operating systems people use currently don’t require sandboxing, and this is an OS issue, not _entirely_ an application issue. If we take this argument to its logical conclusion, you would be saying that we shouldn’t recommend _running a computer at all_, because operating systems leave open the possibility of running malware to the user.

Well, that isn’t entirely true. We here likely have a biased perspective with regard to how much we use desktop operating systems, but the vast majority of people use mobile devices most of the time. Both iOS and Android enforce strong app sandboxes, as do Android TV and tvOS, which are the next most popular platforms for media consumption.

---

## Post 38 by @anon29374801 — 2025-03-17T18:53:42Z

It does feel like this conversation may be pushing the goal post towards a threat model that is seemingly much less common then what I would assume the target audience is for this section.

I think its going to scare away most users from the section if it seems like they need to follow a guide on how to sandbox their media player just to be safe enough to play their burned copy of Diehard on Kodi.

---

## Post 39 by @anon39279085 — 2025-03-17T18:55:42Z

Yup very valid point.

Again we need to agree on some kind of compromise or otherwise  
remember:  
We recommended DivestOS, despite it being a harm reduction OS not a full on Secure and Privacy OS  
We also recommend Firefox, despite many users expressing how “insecure” it is.

---

## Post 40 by @fria — 2025-03-17T18:55:46Z

They don’t need to do anything, a secure media player will be sandboxed OOTB. That’s what I’m pushing for here, a 0 effort media player that’s secure without the user having to think about it.

---

## Post 41 by @anon42475305 — 2025-03-17T18:59:42Z

If it helps, I am quite happy that an even less suitable replacement isn’t listed for harm reduction. DivestOS was a pretty unique case, but I think in that case it at least made some sense because of the monetary cost of buying a new device. If someone had an old device and couldn’t afford a new one, then running DivestOS on it was an improvement in security. In this situation, however, we are evaluating different FOSS. There is no financial barrier preventing someone from using a more secure option if it is recommended instead of Kodi.

---

## Post 42 by @anon29374801 — 2025-03-17T19:00:55Z

Then that shifts the conversation more towards what the criteria of this section should be. The disagreement really is you think the software should be sandboxed as a minimum criteria, whereas @jonah does not, if I understand this correctly.

I wouldn’t be against having that conversation, although it probably should be a different thread. It always seemed a bit odd to create a catagory without having a discussion of what the criteria should be first.

---

## Post 43 by @jonah — 2025-03-17T19:08:26Z

This isn’t a Kodi development forum, so pushing for anything related to Kodi development here will make no impact.

It is far more effective for Privacy Guides to use its voice by listing software _that is largely acceptable_ alongside prominent explanations of any shortcomings they may have. This gets people talking about these problems and gets it on the developer’s radar.

Having strict criteria for a category only works as a motivator if there are competing tools that already meet the criteria. There is no better alternative than Kodi in this category that I know of, so we have to work with what we have.

The criteria is primarily meant to exclude new recommendations, and it gets ratcheted up over time as existing recommendations improve or as new software gets launched.

The criteria is not simply a list of _wishes_ that we have. If we only recommended perfect software we would recommend nothing at all, and Privacy Guides would just be a list of things we think developers should add to their apps. There is no category on the site where the criteria is that the app’s security is perfectly implemented, and I don’t see why this category will be any different.

* * *

The only reason to _not add a category at all_ is if the shortcomings of all available tools are massively substantial and would place people in a _worse_ position than not doing anything, which again really doesn’t seem to be the case here.

> [@anon42475305](#):
>
> There is no financial barrier preventing someone from using a more secure option if it is recommended instead of Kodi.

Obviously this is true, and if there is a more secure option then we should recommend it instead. This statement hinges on the assumption that a more secure option _exists_, which is not the case to my knowledge.

---

## Post 44 by @fria — 2025-03-17T19:17:28Z

> [@jonah](#):
>
> This isn’t a Kodi development forum, so pushing for anything related to Kodi development here will make no impact.

Right now I’m trying to stop what I view as an insecure app being recommended to a lot of people. I’ll gladly request that they make these improvements, but I don’t want it listed unless they make said improvements.

> [@jonah](#):
>
> It is far more effective for Privacy Guides to use its voice by listing software _that is largely acceptable_ alongside prominent explanations of any shortcomings they may have. This gets people talking about these problems and gets it on the developer’s radar.

Like you said this isn’t the Kodi development forums, lets get people talking on their own forum/github so the developers can actually fix it.

> [@jonah](#):
>
> Having strict criteria for a category only works as a motivator if there are competing tools that already meet the criteria. There is no better alternative than Kodi in this category that I know of, so we have to work with what we have.

Every operating system already has a default media player built in. We also don’t need to rush these recommendations either, it should be carefully considered.

> [@jonah](#):
>
> The criteria is primarily meant to exclude new recommendations, and it gets ratcheted up over time as existing recommendations improve or as new software gets launched.

I don’t see why we can’t have high standards out of the gate. Some fancy smart TV software isn’t a necessity, we can wait until they’re better.

> [@jonah](#):
>
> The only reason to _not add a category at all_ is if the shortcomings of all available tools are massively substantial and would place people in a _worse_ position than not doing anything, which again really doesn’t seem to be the case here.

The problem with this is there’s infinite possible categories of software. We should be strict about all new software in general, otherwise the site will turn into a bloated mess of a million random bits of software, some of which will be actively dangerous. The idea that we should start at basically no criteria if there’s not some other competing software is ridiculous to me. I _thought_ the point of the general criteria was for exactly this reason.

---

## Post 45 by @any1 — 2025-03-17T19:21:46Z

Security should only be weakened if it would provide a substantial privacy benefit, e.g., using Firefox-based browsers instead of Chromium. Kodi not using the app sandbox is just security negligence, in my opinion.

---

## Post 46 by @anon39279085 — 2025-03-17T19:24:25Z

Then again what about Firefox  
it is deemed insecure to around half of the users yet we recommend it  
with that logic why doesn’t kodi and VLC get the same treatment

---

## Post 47 by @jonah — 2025-03-17T19:24:54Z

> [@fria](#):
>
> The idea that we should start at basically no criteria if there’s not some other competing software is ridiculous to me.

That is not what I said. I will just repeat what I said here:

> [@jonah](#):
>
> The only reason to _not add a category at all_ is if the shortcomings of all available tools are massively substantial and would place people in a _worse_ position than not doing anything, which again really doesn’t seem to be the case here.

This statement is tailored to this specific case of media software. I have made no statement whatsoever about allowing any recommendations without any criteria at all. People _are_ better off using Kodi than the non-private alternatives out there.

---

## Post 48 by @anon39279085 — 2025-03-17T19:25:40Z

But kodi does provide substantial privacy over say the smart TVs that’s where I’m confused here.

---

## Post 49 by @dogeyes — 2025-03-17T19:28:40Z

Honest question: do people really use Kodi as expected? Most of the online tutorials I see are designed to access content that might be considered either prohibited or illegal in some jurisdictions.

Personally, I just connect a laptop to a TV, which I believe is what most people do when they want more functionality from their TVs (based on my experience, of course).

I might be a little bit off-topic now that I think about it…

---

## Post 50 by @anon39279085 — 2025-03-17T19:32:06Z

that is a good question  
I do find it’s UI and Hardware Support fitting for big screen/TV replacement  
at this point it’s about replacing the privacy invading smart tvs  
that is if the user wants to connect it to the internet  
but of course when it comes to that it can be important to assess the risks but again it’s a weird double standard discussion imo.

Tbh I was also geniunely considering of this setup where my ripped media would go to hogh capacity sd card loaded onto kodi onto a raspberry pi but yeah

---

## Post 51 by @jonah — 2025-03-17T19:36:28Z

I think there certainly is a use-case for people who want a family-friendly, private media solution.

A large part of more _technical_ privacy-friendly tools like Kodi or [Jellyfin](https://discuss.privacyguides.net/t/jellyfin-media-management/25867) is making it easier to _share_ private solutions with less technical people. Therefore the goal of this section isn’t _solely_ to cover personal usage, but to cover private media solutions that are applicable to indirect users as well.

* * *

You can’t take merely the amount of guides on piracy very seriously, because they are inherently more advanced topics. There is no need for a large amount of guides on how to use Kodi normally, because the normal way to use it is quite simple.

I think that _assuming_ that most people are pirating/torrenting content or most people are doing weird things with Kodi doesn’t actually work, because those situations are merely the most vocal/obvious use-cases on the internet, _not necessarily the most common use-cases_.

---

## Post 52 by @any1 — 2025-03-17T19:40:11Z

A compromise could be to recommend it for its privacy benefits but list the security considerations.

---

## Post 53 by @anon39279085 — 2025-03-17T19:41:29Z

I would love to do that if it means most of us agree. With some suggestion but other than that yeah.

---

## Post 54 by @any1 — 2025-03-17T19:46:46Z

If I am understanding it correctly, the recommendation would be to use media deemed ‘secure’ and not to recommend using it for piracy?

---

## Post 55 by @jonah — 2025-03-17T19:50:25Z

I think a reasonable recommendation would be to say that Kodi is a good way to privately browse and play your local media collection, with a note/warning that your local media collection could place you at risk if you obtained that media via third-party sources.

---

## Post 56 by @anon63378630 — 2025-03-17T19:53:11Z

Why exactly are there so many comments in this thread?

Kodi is like 20+ years old, there is no better FOSS option in its class for the 10ft experience.

The only real concern that needs to be clearly stated is to avoid plugins, just as you would for a browser or an IDE.

---

## Post 57 by @dogeyes — 2025-03-17T19:55:07Z

> [@any1](#):
>
> A compromise could be to recommend it for its privacy benefits but list the security considerations

That opens the door to recommending an endless list of software as long as appropriate security warnings are provided, which in many cases could be quite extensive. I believe that security warnings should be reserved for software that offers a near net gain in privacy. Is this the case for Kodi?

---

## Post 58 by @anon39279085 — 2025-03-17T19:56:50Z

thank you very much for your expressing your opinion on this  
as for the real concern I have added the following:

> (…) and you can use add-ons1. to extend the experience. Kodi is compatible with most operating systems and hardware, including Raspberry Pi, Linux, and Android, see the requirements here for running Kodi.
> 
> Kodi has an add-ons store to extend the out-of-the-box experience, but keep in mind that add-ons are made by the community and the company itself, so be careful what you install, luckily most software add-ons are also FOSS, meaning the code on them can be inspected, but in general be careful what you install, see the addons site for more.

Would that be satisfactory?  
Not to mention we had to add the following which is unfortunate but who to blame is a whole different story:

> Also, we advise against using it for Apple devices (outside of MacOS) as it requires jailbreaking them and jailbreaking reduces the security of the device, we recommend you have a Linux or an Android device for it instead if possible.

---

## Post 59 by @anon63378630 — 2025-03-17T19:59:55Z

> [@anon39279085](#):
>
> luckily most software add-ons are also FOSS, meaning the code on them can be inspected, but in general be careful what you install

I don’t agree with this.  
I like my FOSS, but people will just see a plugin on GitHub and think it is safe.  
There are many malicious Kodi plugins.  
I reaffirm that _all_ non-default plugins should be avoided.

---

## Post 60 by @anon36940904 — 2025-03-17T20:02:10Z

> [@anon63378630](#):
>
> I reaffirm that _all_ non-default plugins should be avoided.

Unless you make one yourself and know what it’s doing and why and how.

---

## Post 61 by @anon39279085 — 2025-03-17T20:03:04Z

hmm, again in my experience looking at the add-ons store, most are made by team kodi and I wouldn’t trust anyone that either doesnt properly list their repo and code or doesn;t have one all together.  
It’s why I generally say it’s fine but the user should still be very much careful and I made it abudantly clear that they should be I think but what do you think.  
Honestly add-ons is like I think the only way the experience can be expanded upon but yeah.  
`But In general be careful what you install` ← Quote

---

## Post 62 by @bitsondatadev — 2025-03-17T20:14:34Z

> [@jonah](#):
>
> It is far more effective for Privacy Guides to use its voice by listing software _that is largely acceptable_ alongside prominent explanations of any shortcomings they may have. This gets people talking about these problems and gets it on the developer’s radar.

I see both sides of the argument. I think Kodi offers a much needed much better alternative to phone home solutions and adding it has a lot of value.

But @fria’s point is quite valid. Many people own VHS copies and have no way to “rip” that licensed material, so they torrent it. Also people absolutely will download material illegally and if they get bit, they will judge PG for not warning them.

> [@fria](#):
>
> They don’t need to do anything, a secure media player will be sandboxed OOTB. That’s what I’m pushing for here, a 0 effort media player that’s secure without the user having to think about it.

This is also a high bar IMO.

> [@any1](#):
>
> A compromise could be to recommend it for its privacy benefits but list the security considerations

This is the way. Just move forward with adding it, but maybe add another article (happy to work on it with @fria) and then we add the warning with a link about the risks of torrented files. That in itself is valuable.

---

## Post 63 by @jonah — 2025-03-17T20:15:47Z

> [@anon63378630](#):
>
> Why exactly are there so many comments in this thread?

If this question is not rhetorical, the TL;DR is that @fria (and others) think that utilizing OS sandboxing (and perhaps other security improvements?) should be a prerequisite to recommending Kodi, and I (and others) think that the risk of it being unsandboxed does not warrant us not recommending it at all, and that it would be perfectly safe to recommend alongside some security education (such as the notes you mentioned).

(I think this is a fair assessment of the thread thus far)

---

## Post 64 by @anon63378630 — 2025-03-17T20:17:14Z

> [@bitsondatadev](#):
>
> download material illegally and if they get bit

they’re far more likely to get malware via an executable that they blindly run since some operating systems hide file extensions than they are from a video player/codec zero day

---

## Post 65 by @any1 — 2025-03-17T20:17:49Z

> I believe that security warnings should be reserved for software that offers a near net gain in privacy

I agree.

> Is this the case for Kodi?

Compared to some of the smart TVs on the market, it is worth it; compared to Apple TV, it is debatable.

---

## Post 66 by @anon63378630 — 2025-03-17T20:19:14Z

> [@any1](#):
>
> compared to Apple TV, it is debatable

oh yes, a proprietary black box with mandatory accounts and effectively mandatory subscriptions is a great idea.  
death by 1000 cuts

---

## Post 67 by @anon63378630 — 2025-03-17T20:39:46Z

re sandbox: you’ve been able to sandbox Kodi on Linux via firejail for nearly 8 years since I added it: [Add a profile for Kodi · netblue30/firejail@d3c16bb · GitHub](https://github.com/netblue30/firejail/commit/d3c16bbaf2d912a057778b70595bb42a7f038553)

---

## Post 68 by @fria — 2025-03-17T20:45:16Z

Isn’t bubblewrap better? Also I expect them to enable basic security features on all operating systems.

---

## Post 69 by @anon39279085 — 2025-03-17T20:51:47Z

I was gonna say isn’t there now a better more modern sandbox? I forgot it’s name  
or was it bubblewrap? hmm, maybe I’m just having a deja vu alright

---

## Post 70 by @anon63378630 — 2025-03-17T21:21:09Z

> [@fria](#):
>
> bubblewrap better

bubblewrap can’t really be directly used on its own, it needs eg. flatpak to interface with it

but my point was moreso how people are just complaining in this thread as opposed to actually trying to do something to improve the situation

---

## Post 71 by @anon39279085 — 2025-03-17T21:26:23Z

what honestly is the problem Isn’t the Discussion of it’s insecurities but rather the double standard thing (Firefox and DivestOS gets away with it, especially Firefox but no Kodi or VLC of Jellyfin, like eh?).  
Like if we genuinely cared about well done security, wouldn’t we have removed Firefox and some linux distros at this point? Like I think you get my problem

As an author, BY ALL MEANS discuss your problems with the recommendation but I would also love to see how it can be solved or at least what can be done about it. Again I don’t want this to turn into a whole liberal thing (and that would honestly be a problem if it did), I do want to make sure everyone or most can be onboard which is why we’re holding back right now and even then till we come to an agreement.  
Of course jonah could very well just merge it any second but I do hope that he also understands to hold back to where everyone/most agrees.

---

## Post 72 by @fria — 2025-03-17T21:33:57Z

> [@anon39279085](#):
>
> Like if we genuinely cared about well done security, wouldn’t we have removed Firefox and some linux distros at this point?

I mean I’m down. Firefox is a little more nebulous, I hear about their sandboxing not being as good as chromium but it’s harder for me to see it vs this is very easy to check and has very big security implications.

---

## Post 73 by @anon63378630 — 2025-03-17T21:37:32Z

> [@fria](#):
>
> Firefox is a little more nebulous

We have thousands of known companies whose sole purpose is to track, profile, and sell our data.  
A _user agent_ capable of strong privacy protections is imo more beneficial for the majority of users.  
But this veers even more offtopic.

edit: Chrome is about to be antitrusted out of existence and I am hopeful whatever working group or standardization body takes it over (instead of a company like Microsoft) lets it flourish and actually become competitive again as a user agent.

---

## Post 74 by @anon39279085 — 2025-03-17T21:39:40Z

Lol  
I mean, that only enforces my point.

Do keep in mind that in the standard criteria _wherever applicable_ is here for a reason and I think I understand why Jonah and others have it.

However I do have to preface that with that, We don’t want things be fully insecure but we also in this case of media players and streaming devices, I don’t think we necessarily want the _full security_  
Now of course we should likely point out security flaws if necessary and someone understanding of their threat model can decide from here.

I think you get the point, like Firefox we would want something in the middle ground where it’s not insecure at least in a manner of targeting even the lowest threat model very easily but can also recommend ways to protect the privacy of others from the likes of smart tvs

I think considering this whole discussion there’s no really middle ground outside of making a guide to make up for it and we can lead them there.

But I do stand firmly that we shouldn’t merge this tools recommendations until we can come to an agreement

---

## Post 75 by @xe3 — 2025-03-17T21:46:46Z

_edit: just to clarify, this comment it isn’t intended to be for or against the inclusion of Kodi, I’m agnostic about that._

> [@anon39279085](#):
>
> Remember we used to Recommend DivestOS as a harm reduction OS,.. I don’t understand the double standard here honestly.

In the case of DivestOS, the harm reduction is taking something bad wrt privacy (proprietary stock android) and replacing it with something less bad/more good (DivestOS).

A prerequisite for calling something _harm reduction_ is demonstrating what harm it reduces relative to the status quo, and why better solutions aren’t feasible/practical. (e.g. not taking drugs from unknown parties is safer than taking those drugs, but prohibition doesn’t work, therefore harm reduction approach focuses on making drug use safer. Similarly DivestOS reduces harm on hardware where better solutions are not possible).

In the case of Kodi (a project that I really appreciate and like), what harm is being reduced? what existing badness does it uniquely eliminate?

> But kodi does provide substantial privacy over say the smart TVs that’s where I’m confused here.

Kodi is very cool, but I don’t see it as a replacement for or comparable to a smart TV. It’s a nice UI for organizing, accessing, and playing your local media, and some other things, but it doesn’t really serve the same set of purposes as a smart tv.

* * *

> **digression re: 'ripped' or 'burned' media vs filesharing**
>
> > [@Many people ITT](#):
> >
> > Burned copies […] ripped copies […] DVDs […] CDs
> 
> WIth respect, I feel like the above is mostly a reference to a different era. I think that those of you premising your perspective on the idea that (in the mid 2020s) there is still a large group of people who rip or burn physical media exclusively (or even primarily), have more to prove than those arguing torrenting is more common.
> 
> Ripping owned media may have been common in the early 2Ks when it was common to buy _and own_ your own media, but it doesn’t seem very common these days, mainstream users use paid/proprietary streaming services, non-mainstream users who use Jellyfin, Kodi, etc largely overlap with those using bittorrent, usenet, etc. I personally think it’s unrealistic to assume that most people interested in Kodi, Jellyfin, etc, aren’t sourcing media from bittorrent or usenet for at least some portion of their library.

---

## Post 76 by @jonah — 2025-03-17T21:51:21Z

> [@xe3](#):
>
> It’s a nice UI for organizing, accessing, and playing your local media, and some other things, but it doesn’t really serve the same set of purposes as a smart tv.

What else do people want a Smart TV to do…?

---

## Post 77 by @anon39279085 — 2025-03-17T21:58:13Z

> [@xe3](#):
>
> Kodi is very cool, but I don’t see it as a replacement for or comparable to a smart TV. It’s a nice UI for organizing, accessing, and playing your local media, and some other things, but it doesn’t really serve the same set of purposes as a smart tv.

but it does, outside of I guess some streaming services but I think someone trying to protect privacy generally wouldn’t use something like Netflix and stuff but I digress.  
It does cover TV, Local Media but also DRM-Free streaming like SoundCloud, YouTube, Twitch, Vimeo etc. (etc for if I missed something). Ironically but More importantly it does also cover [LBRY](https://kodi.tv/addons/omega/plugin.video.lbry) and [Peertube](https://kodi.tv/addons/omega/plugin.video.pt/) too which is nice, it seems invidious is here too: [Invidious](https://kodi.tv/addons/omega/plugin.video.invidious/)  
_Now I must remind the warning about add-ons and doing your own due diligence but yeah_

Now thay I see it I should definitely fork, learn kodi add-on development and start maintaining the invidious one as it seems abandoned, as for the lbry also that but I do hope there’s anyone else, it goes to show how reliant the community can be in contributing to the kodi ecosystem and they can get burnt out [or maybe there was genuinely no need for change? but there should be]

---

## Post 78 by @anon39279085 — 2025-03-17T21:58:23Z

exactly.

---

## Post 79 by @xe3 — 2025-03-17T22:10:02Z

> [@jonah](#):
>
> What else do people want a Smart TV to do…?

In my experience, the most common reason people use Smart TV’s is easy access to the streaming services (Netflix, HBO Max, etc) they use (and youtube) and for some people legacy cable.

I know nobody (in my personal) life who uses a SmartTV to consume their own local content, and a SmartTV wouldn’t be strictly necessary if this was their sole priority (Kodi (xbmc) began well before the SmartTV era)

> outside of I guess some streaming services

That is in my opinion and experience the single largest reason people buy Smart TVs and streaming devices. In my experience, consuming owned local content was _more common_ in the pre-smart-TV era.

> generally wouldn’t use something like Netflix

I think that is a flawed assumption. Most of us recognize Youtube is privacy hostile (and bad in many other ways) but most of us here do still use it begrudingly.

Compared to Youtube, Netflix is very far down the list of services I spend time worrying about. That doesn’t mean I’m totally comfortable with it, but I’m not overly stressed about it either relative to the other privacy concerns I have.

---

## Post 80 by @anon39279085 — 2025-03-17T22:14:03Z

that is honestly a different argument and tbh replacements like Kodi are mostly meant for those who do care about privacy yet they want to get away with smart tvs and their biggest privacy problems  
Kodi does have YouTube and many others but especially drm-free covered but of course for Netflix and other streaming services that is a whole different spectrum  
Generally we recommend just buying Physical media and playing them there (ripping them and putting them into a jellyfin or frick, rip them and put them into Kodi ready to play or even buying a dvd/bd player abd playing them there works too) anyways. Not only do you own the content this way but it is far more private than the traditional streaming services and stuff.  
I ask you this, why would I want to pay monthly not to own my content and get tracked by Netflix and others about what I’m watching when I could do this instead, I think you get the point of what we’re trying to protect from and it why we’re accomodating these tools with a guide to make up for it.

This post is totally not sponsored by my favourite physics media enjoyer, AustralianPods ([https://inv.nadeko.net/watch?v=8POqpsnq-OY](https://inv.nadeko.net/watch?v=8POqpsnq-OY)), speaking of, if DankPods enjoys having physical media, how couldn’t others, especially if transitioning away from Netflix and stuff I feel like taking the steps to advocate and afford for physical media goes a long way. And as DankPods once said, the Purchases of these will be the receipts.

And I mean, I do genuinely want to start buying my anime shows especially starting with ones I do want to support and enjoyed and putting them to something like jellyfin so I can stream them here whenever I wanna watch them and it’s a pretty good market imo.

---

## Post 81 by @ph00lt0 — 2025-03-17T22:35:41Z

I skimmed through this busy thread quickly. Must say I have similar doubts like @fria on including this. I myself have also ran Kodi before, but it comes across as not a very well built system (i am trying to be nice here). I see no real privacy benefits over using an AppleTV tbh or plugging your laptop in with a cable…

---

## Post 82 by @anon39279085 — 2025-03-17T22:45:45Z

Maybe it’s because that’s not what you’re into and that’s fine  
I would be into it though.

---

## Post 83 by @xe3 — 2025-03-17T22:48:58Z

> [@anon39279085](#):
>
> Kodi are mostly meant for those who do care about privacy yet they want to get away with smart tvs

I agree. And I fit that description.

Where I disagree is the presumption that most of us (even in the privacy community) will give up streaming services considering almost none of us are willing to fully give up Youtube (which I think we can agree is a larger privacy violator).

> I ask you this, why would I want to pay monthly not to own my content

I don’t want to talk you out of anything, do what works for you, (and as mentioned I actually like Kodi, and have self-hosted Emby, and Plex in the past, and plan to self-host Jellyfin in the future).

I just want us to acknowledge that what Kodi offers does not replace most of the primary value most people get from using a SmartTV (including many privacy conscious people), and framing it as a SmartTV replacement will likely lead to flawed expectations and disappointment. There is no shortage of ways to consume local media, Kodi is a great option, but people are not using streaming services due to lack of availability of local media options.

It also partially confuses what Kodi actually _is_ considering that Kodi is installable on many Smart TV’s and streaming boxes as well as a range of different platforms. It is an application, not an OS or device. As I see it, Kodi and SmartTVs are not really competing or mutually exclusive things in my opinion, they are overlapping but distinct types of thing.

> I ask you this, why would I want to pay monthly not to own my content

That is a good but separate question (The reason I think most people would give is cost, convenience, and content discovery). The counter-argument is you own nothing, and have very little control. I say it is separate because local content can be consumed with or without Kodi, and streaming services can be used with or without a Smart TV.

---

## Post 84 by @anon39279085 — 2025-03-17T22:49:16Z

also for apple tv:

> [@anon63378630](#):
>
> oh yes, a proprietary black box with mandatory accounts and effectively mandatory subscriptions is a great idea.  
> death by 1000 cuts

---

## Post 85 by @ph00lt0 — 2025-03-17T22:55:30Z

We should not forget that this website is read by many who just need things to work. I want PG to be recommending accessible things that everyone can use not only if you happen to be a engineer with some networking skills and a home automation hobby.

Earlier we established that for more things in this area of hobby projects should be kept on the forum cuz that’s where it probably gets more traction amongst you more invested peeps :smiley:

---

## Post 86 by @jonah — 2025-03-17T23:01:07Z

I think there can be a distinction between things that are easy to install and things that are easy to _use_.

I alluded to this earlier, but I think there is a space for tools that are easy for anyone to use, even if they are _not_ easy for anyone to install:

> [@jonah](#):
>
> I think there certainly is a use-case for people who want a family-friendly, private media solution.
> 
> A large part of more _technical_ privacy-friendly tools like Kodi or [Jellyfin](https://discuss.privacyguides.net/t/jellyfin-media-management/25867) is making it easier to _share_ private solutions with less technical people. Therefore the goal of this section isn’t _solely_ to cover personal usage, but to cover private media solutions that are applicable to indirect users as well.

Part of this is certainly related to the yet-unresolved discussion: [Does Privacy Guides have a stance on self-hosting?](https://discuss.privacyguides.net/t/does-privacy-guides-have-a-stance-on-self-hosting/10997)

---

## Post 87 by @ph00lt0 — 2025-03-17T23:05:35Z

I am not sure if you tried Kodi but i don’t find it that easy to use even myself XD. The ui is rather awful. But generally I would agree with the statement otherwise.

Let alone that I do think we should not recommend things that are hard to install, unless we can provide detailed help with it somehow.

---

## Post 88 by @anon39279085 — 2025-03-17T23:06:25Z

Yeah I should definitely get the hang of it first  
but Honestly looking at all images, I don’t see how this is hard to use, unless I’m missing something of course :thinking:

I could understand for something like jellyfin, it’s not perfect but kodi like hmmm?

---

## Post 89 by @ph00lt0 — 2025-03-17T23:11:45Z

Well as I learned in UX design it should pass the “grandma test”. I am sure a grandma can watch TV with but can they navigate Kodi?

---

## Post 90 by @anon39279085 — 2025-03-17T23:12:58Z

Sure I understand your point if that’s the case  
but a little counter argument, if grandma can navigate apple tv, how could grandma not use Kodi?

I think you kind of get the point here.

actually my grandparents would love this alternative as they actually are already tired of their TV being a “smart tv” soo yeah

---

## Post 91 by @jonah — 2025-03-17T23:13:41Z

Given the atrocity of UI/UX design in embedded devices like smart TVs and automotive interfaces, which many grandmas _do_ regularly use, I am fairly confident that Kodi would pass this test actually.

---

## Post 92 by @ph00lt0 — 2025-03-17T23:14:00Z

Well imho AppleTV is far far better designed and easier to navigate and therefore more accessible for a grandma.

---

## Post 93 by @anon39279085 — 2025-03-17T23:15:09Z

this exactly and my real life point of them at that  
Could’ve proposed it but I haven’t thought about it and I didn’t wanna make it sound complicated I guess.

---

## Post 94 by @overdrawn98901 — 2025-03-18T00:26:20Z

> [@ph00lt0](#):
>
> Let alone that I do think we should not recommend things that are hard to install, unless we can provide detailed help with it somehow.

Hmmmm, Pi-Hole is recommended as a self hosted service without detailed help to install it. Also photo-prism. Is Kodi really that much harder to install?

---

## Post 95 by @anon39279085 — 2025-03-18T00:34:06Z

honestly outside of Apple iOS and TvOS it really isn’t hard to install it (Though as I said before I did advice against it due to it requiring jailbreaking for iOS and TvOS)

---

## Post 96 by @anon29374801 — 2025-03-18T01:16:05Z

> [@overdrawn98901](#):
>
> Hmmmm, Pi-Hole is recommended as a self hosted service

This doesn’t seem fair, pi-hole can literally be installed in one step.

* * *

Just to keep my comment semi on-topic, I think Kodi is fine for the audience this section would serve. I tend to see this type of category filling a similar need as front ends in that these are solutions that make an area that just does not have great privacy options a bit better.

---

## Post 97 by @anon63378630 — 2025-03-18T01:31:51Z

> [@ph00lt0](#):
>
> sure a grandma can watch TV with but can they navigate Kodi

the Kodi UI is actually genuinely the most awful and confusing media player UI in existence.

You have to consult this giant table to know what each key does: [https://kodi.wiki/view/Keyboard\_controls#Default\_keyboard\_controls](https://kodi.wiki/view/Keyboard_controls#Default_keyboard_controls)

Using the Kodi Remote app or a game controller does make it viable, but then hard to type/search

---

## Post 98 by @jonah — 2025-03-18T01:35:48Z

I would _imagine_ most people would use this with a remote if it’s on their TV.

---

## Post 99 by @bitsondatadev — 2025-03-18T01:48:30Z

Alright, looks like we need to all repurpose our old RPis and give them to our grandmas and observe them use it for a weekend and we’ll consolidate the data to see if Kodi passes the test.

:old_woman: - “Yeah Mildred you can come over but you should know my weird grandson is running another one of his science experiments just staring at us while we use his Computer TV Box”

---

## Post 100 by @anon39279085 — 2025-03-18T10:59:35Z

Is it just me or are you taking “grandma” test too literally?  
If I’m being honest I’d much rather teach them using Kodi than getting frustrated by a smart TV, just my 5 cents

---

## Post 101 by @bitsondatadev — 2025-03-18T12:30:42Z

Ignore me I’m just being a :clown_face::winking_face_with_tongue:
