r/torrents 10h ago

Question First time torrenting

A little nervous so I thought I'd share my method in case i need any advice. I'm downloading movies for a jellyfin server (running on linux) and ive never torrented before. I wanted to make sure I do it as safely as possible. Im currently using a separate windows PC that is completely empty of any personal information, aside from it being connected to my home wifi i guess. Im using firefox with u block origin to torrent movies from rutracker. I'm using proton VPN with a kill switch. I'm opening them with qbittorrent. Ive also gone into the advanced options of it and selected network interface to ProtonVPN. I also have malwarebytes. It flagged qbittorrent but i hear thats normal. Im currently downloading a movie uploaded 10 months ago from someone who seeemss reputable? I just allowed access to qbit for the windows firewall. When its done downloading im going to scan the file with malwarebytes.

What do you guys think? Am I missing any important steps? Am i being overly cautious and nervous? Its difficult for me to be confident in this when i admittedly dont completely understand how it works. I just dont want a virus or a letter in the mail :p

13 Upvotes

14 comments sorted by

10

u/nemgrea 10h ago

youve bound your torrent client to your VPN, thats the best thing you can do and the part most people miss, everything with the malwarebytes is pretty overkill IMO...especially on a machine that you can just wipe with no worries...a better option would probably be to just whitelist the types of files you want in qbit, for example only allowing .mkv .mp4 and whatever other movie file extensions you actually get.

this prevents qbit from even downloading .exe or other non movie files that could be potentially harmful.

the next best option after that is to just join trackers that have moderation on their uploads. theres a significantly smaller chance of getting a virus when the people uploading are not just randoms on the internet but actual vetted and monitored uploaders..

2

u/Stubbblly 8h ago

thanks for the info i'll definitely use a whitelist. Wym by join trackers tho? I did check the guy who uploaded it and it said moderator and he had an account that was 17 years old with a bunch of uploads so that did make me feel more safe from viruses lol.

1

u/nemgrea 7h ago edited 7h ago

For ease of explanation by "join trackers" I mean join other websites that host torrent files. It more complicated than that and there's a ton of info in the sidebar over on r/trackers but for now I'm just referring to joining other sites. The best ones are private and require being invited by a current user who you know irl. But there's plenty of good entry level private trackers too, private trackers are the best because they have impeccable selection, rock solid seeders, and bulletproof quality control.

When you see release group names in your movie file names like Framestor, BYNDR, Kitsune, SCOPE, or CINEPHILES, etc. those releases groups put our their torrents onto private trackers first and then those torrents percolate down to public trackers. They get reputations for their work and they don't jeopardize that.

3

u/spoutti 9h ago

From what i understand, playing a video file cant give your pc a virus. You have to "execute" something, like a x.exe file, allowing macros in excel file etc. Video aint a possibility

3

u/EmptyVeterinarian979 8h ago

Very unlikely but it is possible to hide malicious code in a video file. If a certain media player has a bug in their code, that could be exploited by someone through the code in a video file.

1

u/Stubbblly 8h ago

But for the most part, as long as I’m only opening video files I’m good? I always assumed that “executing” in this case meant opening playing a video file.

1

u/EmptyVeterinarian979 8h ago

Yes, you will very very likely be fine. I just responded to this post because it is technically possible for a video file to be malicious even with a video file extension. If you are interested you can look at this article. But you are doing things just fine

https://www.opswat.com/blog/can-malware-be-hidden-in-videos

1

u/default_person_14818 10h ago edited 9h ago

I'd check the r/piracy megathread for the website you got your torrent from. They make safety reports on the largest torrent websites.

For your own opsec you are much safer than a lot of other people already are. If you wanna be completely sure, maybe try to configure the firewall of your home's router to drop all traffic from that torrent machine to any other device on your network so that a piece of malware cannot infect other devices on your LAN.

A tool like wireshark may be useful to detect malicious activity to the public internet but that takes some effort to read into. In all likeliness a virus scanner for anything you torrent will already detect malware decently. 

1

u/RyukPp 9h ago

sound good!

I would recommend excluding certain files so you don’t accidentally download shady stuff.

It’s under the Downloads tab in qBittorrent this is my list.

*.txt

*sample*

*.jpg

*.png

*.zip*

*.rar*

*.exe

*featurette*

*.lnk

*.com

*.bat

1

u/Tigitaal 8h ago

Can you explain why these files are dangerous? I get .exe .bat etc but how can a txt be dangerous or an image?

1

u/RyukPp 7h ago

I don’t want these files, so I exclude them. It’s for convenience and safety. Of course, this is just an example you’re free to do whatever you want.

1

u/elhouso 8h ago

A VPN is seriously all you need lol
A separate computer is smart though. I used to spin up a VM on my server, but I gave up on that. Too much work lol

1

u/chapo1162 2h ago

First click doesn’t always get you there

1

u/71d1 35m ago

I think a better question is how serious are you about this? The setup you described is ok if you don't want to get DCMA notices, but for virus I would instead use a VM not connected to the internet to watch movies sometime ago a group of hackers were able to execute arbitrary code on MKV files running with VLC, thankfully it has been found but there's always a chance of a zero day bug.

https://www.opswat.com/blog/remote-code-execution-vulnerability-in-vlc-detection-remediation-with-opswat

If you want to protect yourself against an investigation, then this setup won't help.

If you intend to download movies and stop seeding this is fine, but if you want to seed stuff then I definitely would advise against your setup.