We have recently experienced a security incident that may potentially involve your Plex account information. We believe the actual impact of this incident is limited; however, action is required from you to ensure your account remains secure.

  • maxprime@lemmy.ml
    link
    fedilink
    English
    arrow-up
    21
    ·
    5 days ago

    I’m no Plex fanboy but from what I’ve read Jellyfin auth leaves a lot to be desired from a security standpoint, particularly if you are opening it to the web. And chances are if your jellyfin server was breached, you wouldn’t get an email about it.

    • sanpo@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      16
      arrow-down
      2
      ·
      5 days ago

      It’s simple, don’t open it to the web directly.

      If you have the ability to make your server public you also have the ability to put Wireguard on it, and after initial setup it’s trivial to use it.

      You shouldn’t really host publicly any service that you won’t be monitoring regularly for security incidents.