question: why use Plex over Kodi?
Plex: Important notice of a potential data breach
131–140 of 194 posts
Re: Plex: Important notice of a potential data breach
#132At the time, I could not find the disclosure on their website.
I'm glad they disclosed shortly after discovery, but not publishing it on their site is an odd choice.
Re: Plex: Important notice of a potential data breach
#133Earlier quoted context omitted.
> a hacker could still compromise a system that has the key in memory. Security is about layers. Simply because a hacker “could” do something, does not mean it’s a bad idea. Getting the encryption key when it’s not stored in the database requires the hacker to now have access not to just the database but to another system as well.
Invariably some developer would just store the key in a column next to the email address so they could process any transaction directly in the query. But the hackers would have to know what algorithm was used :) That's a layer, right?
I think that depends on where you work. Process. Code reviews before allowing merge/pull requests can help.
Re: Plex: Important notice of a potential data breach
#134On July 27th, I received ~7 emails, about 10 minutes apart, warning me of a new device logging in my Plex account. It didn't correlate with any activity on my part, and the IPs were all over the place (for context I'm in France). Here is some of the IPs that were used :
- 191.101.41.35 (US)
- 185.199.103.40 (US)
- 103.43.200.58 (India)
- 2001:16a2:def3:200:40cf:530f:ff72:1747 (Saudi Arabia)
Fortunately the password is only used on Plex, and I just generated a new one and signed out my devices, and that was it.Re: Plex: Important notice of a potential data breach
#135It's funny that everyone here is expecting airtight security practices, proper vulnerability disclosure and general trustworthiness from an app that's a tiny step above the likes of BitTorrent and PopcornTime.
That's like saying torrents are only used for piracy, TOR only for buying drugs, and crypto only for laundering money.
Re: Plex: Important notice of a potential data breach
#136I received this email at 10:42pm PST. At the time, I could not find the disclosure on their website. I'm glad they disclosed shortly after discovery, but not publishing it on their site is an odd choice.
Re: Plex: Important notice of a potential data breach
#137It all became clear when I got this email last night. I was suspicious, but now I'm pretty certain that my account was exploited, and my local media was being streamed by a 3rd party.
Re: Plex: Important notice of a potential data breach
#138I like that they're up front about this. Solved the problem in a couple of minutes. I use a password manager with a very long randomly generated password for everything, so a hashed password leaking is essentially meaningless to me. Notifying me immediately so that I can change it ASAP is what matters. The burner e-mail I use for stuff like this is listed in 25 other data breeches, too. I don't really care. Plex is a…
Because most people reuse the same email address and password, and are potentially way more exposed than you are.
Re: Plex: Important notice of a potential data breach
#139I like that they're up front about this. Solved the problem in a couple of minutes. I use a password manager with a very long randomly generated password for everything, so a hashed password leaking is essentially meaningless to me. Notifying me immediately so that I can change it ASAP is what matters. The burner e-mail I use for stuff like this is listed in 25 other data breeches, too. I don't really care. Plex is a…
First I thought of the pants that the crew of the Enterprise wear and second was the diaper thing that the monkey you use to save in Mega Man Legends wears[0].
(As an aside, an image search for "data star trek" will have you believing that he does not wear pants on that show.)
[0] https://duckduckgo.com/?t=ffab&q=data+mega+man+legends&atb=v...
Re: Plex: Important notice of a potential data breach
#140I have a feeling that this breach is older than what they're letting on. On July 27th, I received ~7 emails, about 10 minutes apart, warning me of a new device logging in my Plex account. It didn't correlate with any activity on my part, and the IPs were all over the place (for context I'm in France). Here is some of the IPs that were used : - 191.101.41.35 (US) - 185.199.103.40 (US) - 103.43.200.58 (India) - 2001:16…
> all account passwords that could have been accessed were hashed and secured in accordance with best practices