We have recently experienced a security incident that may potentially involve your Plex account information. We believe the actual impact of this incident is limited; however, action is required from you to ensure your account remains secure.

      • maxprime@lemmy.ml
        link
        fedilink
        English
        arrow-up
        21
        ·
        5 days ago

        I’m no Plex fanboy but from what I’ve read Jellyfin auth leaves a lot to be desired from a security standpoint, particularly if you are opening it to the web. And chances are if your jellyfin server was breached, you wouldn’t get an email about it.

        • sanpo@sopuli.xyz
          link
          fedilink
          English
          arrow-up
          16
          arrow-down
          2
          ·
          5 days ago

          It’s simple, don’t open it to the web directly.

          If you have the ability to make your server public you also have the ability to put Wireguard on it, and after initial setup it’s trivial to use it.

          You shouldn’t really host publicly any service that you won’t be monitoring regularly for security incidents.

      • akilou@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        14
        ·
        5 days ago

        Until you try to share your library with someone and have to parse terms like reverse proxy or figure out how your mom can install a vpn on her Roku

        • Nora@lemmy.ml
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          1
          ·
          4 days ago

          If you can set up Jellyfin, you can set up a reverse proxy using Caddy. It’s dead easy.

        • AtariDump@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          4 days ago

          It amazes me how many people jump immediately to Jellyfin and A. Skip over Emby and B. Never ask what someone’s use case it.

  • rouxdoo@lemmy.world
    link
    fedilink
    English
    arrow-up
    16
    ·
    5 days ago

    I’m less fussed about a data breach that might require a password change than I am that 3rd parties have access to internal databases. Play history and library contents could be a lot of trouble for folks if that data is ever breached (assuming it is even kept by PleX which I hope it isn’t).

  • CodingCarpenter@lemmy.ml
    link
    fedilink
    English
    arrow-up
    11
    arrow-down
    2
    ·
    4 days ago

    I really don’t understand all the hate. It’s like this weird echo chamber where everybody’s like fuck it I’m gone! Like you’re all just waiting for a fucking reason to switch if you want to switch switch. Personally for people like me without the time or inclination Plex is a fucking godsend. So I have to change my password big deal.

  • UltraMagnus0001@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    4 days ago

    It’s unfurtunate that Jellifin or Emby is not available on as much smart TV platforms as Plex. I tried Emby years ago and it was close to Plex ease of use, but it was still fairly new and not quite there and hopefully a lot better now.

  • apfelwoiSchoppen@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    4 days ago

    When this happens, I always forget to change the password through the server/localhost URL. Always gets confusing when I don’t.

    • AtariDump@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      4 days ago

      What are you using in its place?

      Jellyfin isn’t any better once you share off your own network.

    • pageflight@piefed.social
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      3
      ·
      5 days ago

      Should’ve done that. Their password reset link did not work, had to sign in and find the password change settings myself. And now they require special character / caps / etc.