12 votes

Plex breach exposes usernames, emails, and encrypted passwords

15 comments

  1. [3]
    Eabryt
    Link
    This is shitty, but also I feel like Plex is handling it pretty well. From what I can tell this email went out within hours of them discovering the breach. I feel like many companies wait much...

    This is shitty, but also I feel like Plex is handling it pretty well.

    1. From what I can tell this email went out within hours of them discovering the breach. I feel like many companies wait much longer.

    2. They're forcing people to change their passwords, not just suggesting. I wasn't even able to log in this morning to reset it, it just automatically had me do it.

    Obviously it's not ideal, but I use a password manager anyway, so that password wouldn't have been in use anywhere else.

    12 votes
    1. autumn
      Link Parent
      This is how I feel about it, too. It’s not a matter of “if” services will get hacked, it’s “when.”

      This is how I feel about it, too. It’s not a matter of “if” services will get hacked, it’s “when.”

      3 votes
    2. JXM
      Link Parent
      This is exactly how something like this should be handled. Don’t try and delay it by doing an analysis that takes months before even notifying people. Let them know right away and require a...

      This is exactly how something like this should be handled. Don’t try and delay it by doing an analysis that takes months before even notifying people. Let them know right away and require a password change at next login.

      2 votes
  2. [3]
    JXM
    Link
    As good a time as any to remind people to use a unique password for every service. Then something like this isn’t catastrophic, merely a minor inconvenience. While you’re at it, you should use a...

    As good a time as any to remind people to use a unique password for every service. Then something like this isn’t catastrophic, merely a minor inconvenience. While you’re at it, you should use a password manager so you don’t have to remember them.

    11 votes
    1. [2]
      lou
      Link Parent
      I switched to Bitwarden when LastPass made mobile features paid. It's pretty good, although a bit slow on mobile. I also have local backups and my main password written on multiple pieces of...

      I switched to Bitwarden when LastPass made mobile features paid. It's pretty good, although a bit slow on mobile.

      I also have local backups and my main password written on multiple pieces of paper. You never know.

      2 votes
      1. JXM
        Link Parent
        I’ve been using 1Password for nearly a decade and, honestly, they’ve got me locked in because I’ve got it set up for all of my family members and have tons of shared passwords.

        I’ve been using 1Password for nearly a decade and, honestly, they’ve got me locked in because I’ve got it set up for all of my family members and have tons of shared passwords.

        6 votes
  3. sleepydave
    Link

    Streaming media platform Plex sent out an email to its customers earlier today notifying them of a security breach that may have compromised account information, including usernames, email addresses and passwords. Although there is no sign that the encrypted passwords were exposed, Plex nevertheless is advising all users to change their passwords immediately.

    3 votes
  4. [8]
    lou
    (edited )
    Link
    Well, shit. You know, I really like Plex, but there's no reason why I should need an online account to access my local files from my TV. I mean, no good reason at least. But Plex is so easy, I...

    Well, shit.

    You know, I really like Plex, but there's no reason why I should need an online account to access my local files from my TV. I mean, no good reason at least. But Plex is so easy, I don't wanna use anything else.

    3 votes
    1. [5]
      zonk
      Link Parent
      Not trying to convert you and probably you've heard of it or even already looked into it, but Jellyfin is a good alternative. It's being actively developed with good community engagement. Big...

      Not trying to convert you and probably you've heard of it or even already looked into it, but Jellyfin is a good alternative. It's being actively developed with good community engagement. Big disclaimer: it's a self-hosted solution. But if you have a server with Docker running, linuxserver.io offers a good Jellyfin container, which is very easy to use. It probably took me a few hours to set up (including skimming the documentation and figuring out transcoding and how to pass through the iGPU) and since then I had basically zero issues whatsoever. And I've been using it for a few years now.

      8 votes
      1. [4]
        lou
        Link Parent
        Yeah, thanks, but that's precisely the kind of thing I don't wanna do. You see, I'm one of the 3 people on Tildes that is not an IT person :P

        . But if you have a server with Docker running...

        Yeah, thanks, but that's precisely the kind of thing I don't wanna do. You see, I'm one of the 3 people on Tildes that is not an IT person :P

        9 votes
        1. [3]
          zonk
          Link Parent
          Totally fine :) I totally get people not wanting to fiddle with that stuff. Here and there it takes a few hours on weekends, not gonna lie! Maybe some other folks here know good hosted solutions.

          Totally fine :) I totally get people not wanting to fiddle with that stuff. Here and there it takes a few hours on weekends, not gonna lie! Maybe some other folks here know good hosted solutions.

          4 votes
          1. [2]
            lou
            Link Parent
            Plex actually creates a a local server on my computer that I can access from the app on my TV, hence why I feel that an online account is not really necessary, but largely a requirement of their...

            Plex actually creates a a local server on my computer that I can access from the app on my TV, hence why I feel that an online account is not really necessary, but largely a requirement of their commercial aspirations.

            1 vote
            1. vord
              Link Parent
              I would note that Jellyfin can do the same, it does have a windows installer which is fairly accessible. The initial setup can be daunting, but once setup I've never needed to fiddle. I agree with...

              I would note that Jellyfin can do the same, it does have a windows installer which is fairly accessible. The initial setup can be daunting, but once setup I've never needed to fiddle.

              I agree with @zonk that Docker is the preferrable method if you're in the Linux ecosystem already, but it's not a hard requirement.

              Sadly 'ease of use' is one of the first things on the chopping block for self hosting stuff. It makes sense, because any setup at all is already harder than 'run installer and create account'.

              3 votes
    2. [2]
      JXM
      Link Parent
      Do you actually need an account just for local streaming? I’ve had my server running forever, so I can’t remember if I had to set up an account just for local streaming or if it was just required...

      Do you actually need an account just for local streaming? I’ve had my server running forever, so I can’t remember if I had to set up an account just for local streaming or if it was just required for connecting outside the home.

      1 vote
      1. lou
        (edited )
        Link Parent
        Here you go.

        You know, I think it is theoretically possible, but it is not trivial and you'll lose some stuff. I mean, not trivial for a regular user.

        Here you go.

        1 vote