Yeah, it's definitely not something you want to leave open 24/7 even with a password. If you have a friend who wants to browse your books and maybe grab a few, then do it for that short time when they'll be connecting, and then undo the port forwarding when they're done. It's nice to work through it so you know how to do it and have that option if and when needed.
|