Live data from Hacker News

Plex: Important notice of a potential data breach

news.ycombinator.com

141–150 of 194 posts

Re: Plex: Important notice of a potential data breach

#141

Earlier quoted context omitted.

That's true, but I hate transcoding anyway so I just get HEVC when possible and play natively on Apple TV and co. (not casting).

Since you have an AppleTV, what is the advantage to you of using Plex instead of just an iTunes instance with Home Sharing turned on? Do you have non-Apple devices you're trying to stream to, or something else? I tried Plex years ago, and it wasn't to my liking because it was philosophically like Windows (Load the filename up with show information and constantly ping the internet for matches) instead of macOS (Metada…

For me, the primary issue is that the Apple TV isn't good enough to be the most-commonly-used device driving the display. FireTV (4K version) wins the battle for the living room display (and it's not even close, with TiVo being 2nd and Apple TV a pretty distant 3rd).

To some extent, it's self-reinforcing. Once the FireTV gets a lead, all it has to do to maintain/extend that lead is reasonably support playback of whatever new format/source and Plex works great on it. If FireTV supported TV as well as TiVo does, it might end up with 100% of the living room display share.

(I also have Plex sharing to devices outside the house, but that's a <1% use case, mostly when it's us traveling somewhere and the kids wanting to watch something that's on Plex.)

Re: Plex: Important notice of a potential data breach

#142

If true, then this will probably reignite discussions around Plex requiring that you authenticate with their servers when using the service to view content that you're hosting on your own hardware. If anyone is curious, then alternatives like Jellyfin exist. It's a bit different and may not have all the features you need, but it works quite well in my experience.

> If anyone is curious, then alternatives like Jellyfin exist. It's a bit different and may not have all the features you need, but it works quite well in my experience.

Jellyfin's DVR service is horrible compared to Plex. Practically unusable. And DVR is the reason I pay for Plex.

Re: Plex: Important notice of a potential data breach

#143
post #138

I like that they're up front about this. Solved the problem in a couple of minutes. I use a password manager with a very long randomly generated password for everything, so a hashed password leaking is essentially meaningless to me. Notifying me immediately so that I can change it ASAP is what matters. The burner e-mail I use for stuff like this is listed in 25 other data breeches, too. I don't really care. Plex is a…

> I don't really understand the freak outs here. Because most people reuse the same email address and password, and are potentially way more exposed than you are.

Yeah the OP reads more like they understands exactly what the freak out is about.

Re: Plex: Important notice of a potential data breach

#144

I like that they're up front about this. Solved the problem in a couple of minutes. I use a password manager with a very long randomly generated password for everything, so a hashed password leaking is essentially meaningless to me. Notifying me immediately so that I can change it ASAP is what matters. The burner e-mail I use for stuff like this is listed in 25 other data breeches, too. I don't really care. Plex is a…

You're being a bit generous with credit to them. We have no idea how long the malicious actors had access (not do they it seems), nor what depth of access they had. I turned off my server until they have had a chance to verify that no malicious software updates have been pushed.

With regard to complex passwords, Plex is one of those accounts that using a random password is quite cumbersome since my kids and I are often connecting new devices that don't access the password manager. We also use it on smart TVs while on vacation. We use a unique, but simple to remember password.

The problem with Plex is that they force you to use cloud auth even if you self-host despite that not being necessary at all for those many of us that self-host. I don't have any other server I host that requires this. The local LAN login they claim works without auth doesn't work for most devices nor across subnets.

It means I cant access Plex when the isp is down and it means Plex sees my library and my kids' activity (which I don't like for privacy reasons), despite having paid for lifetime Plex before this was a requirement.

Think about the Plex as a business that may very likely get acquired one day by a large media corporation. What happens to my data then? Will they ask me to verify my ownership of content I host(ed)? They are already pushing commercial "free"content to my kids, which is exactly what I was trying to get away from.

Re: Plex: Important notice of a potential data breach

#145

Earlier quoted context omitted.

Plex doesn't require account linking IIRC, it's heavily suggested but you can just access Plex locally without an account.[1] But otherwise I've switched to Infuse[2] since then, it indexes sources reliably on its own (no manual editing though) and saves the entire need for a server if you use it with some cloud storage. Basically replaced my Plex server, with the added bonus of out-of-home streaming without needing…

This is not correct. I've tried the LAN no-login settings and it does not work for many devices (Roku/smart tv/phones). They also fail if you're not on the same subnet as Plex. For this infuriating reason, moving off of Plex is on my to-do list.

I’m currently not logging in while using plex. Just providing that datapoint

edit:

You can also do this: https://support.plex.tv/articles/200890058-authentication-fo...

Re: Plex: Important notice of a potential data breach

#146
post #134

I have a feeling that this breach is older than what they're letting on. On July 27th, I received ~7 emails, about 10 minutes apart, warning me of a new device logging in my Plex account. It didn't correlate with any activity on my part, and the IPs were all over the place (for context I'm in France). Here is some of the IPs that were used : - 191.101.41.35 (US) - 185.199.103.40 (US) - 103.43.200.58 (India) - 2001:16…

In general, corporations will use some weasel words when reporting breaches.

They will say "we have evidence that a subset of x/y/z data was accessed". You might think that means they have evidence that the other data wasn't accessed, but what it means is that they only currently have explicit indicators of certain data being accessed (such as a exported zip file that bad actors forgot to delete, or the log of one sql query, etc). It really means very little, and companies (internally) usually assume everything on the breached server was accessed, even if externally they only report on obvious breadcrumbs.

They also say "We detected access on xyz date and immediately worked to close the vulnerability". You might think this means that they know that this was they have evidence that this was the first access, but it only means this was the first obvious alert they noticed and responded to. There might be earlier accesses (even some they already know about).

They are intentionally vague to limit their legal liability. This is why laws must be passed to compel full disclosure.

Re: Plex: Important notice of a potential data breach

#147
post #130

If true, then this will probably reignite discussions around Plex requiring that you authenticate with their servers when using the service to view content that you're hosting on your own hardware. If anyone is curious, then alternatives like Jellyfin exist. It's a bit different and may not have all the features you need, but it works quite well in my experience.

People on HN always complain about this. But the reality is that the one time payment you (maybe) gave for Plex is not enough to make a viable company. So they have to offer complementary products and for that you need an online account. Normal people also want to have features like remote streaming, subtitles fetching, familly sharing, etc which are hard to do without centralized accounts. Not even mentionning secur…

I run a lot of self-hosted software services, many of which have their own internal account system and auth. None of the features you mentioned require 3rd party cloud based auth.

I did pay for Plex prior to the cloud auth change, so for me it's a bait and switch, but my concerns are much more about privacy.

One day Plex will be bought by a large media company, and my (and my kids') viewing data and library catalogue data will be owned by MGM, Disney, Fox, etc...

Re: Plex: Important notice of a potential data breach

#148

If true, then this will probably reignite discussions around Plex requiring that you authenticate with their servers when using the service to view content that you're hosting on your own hardware. If anyone is curious, then alternatives like Jellyfin exist. It's a bit different and may not have all the features you need, but it works quite well in my experience.

> If anyone is curious, then alternatives like Jellyfin exist. It's a bit different and may not have all the features you need, but it works quite well in my experience. Jellyfin's DVR service is horrible compared to Plex. Practically unusable. And DVR is the reason I pay for Plex.

Check out Channels DVR

Re: Plex: Important notice of a potential data breach

#149

I noticed last week that my plex server was using a lot of CPU when I was not watching plex. Since I almost never use it, I just killed the server process thinking that it was running amok because of some bug. It all became clear when I got this email last night. I was suspicious, but now I'm pretty certain that my account was exploited, and my local media was being streamed by a 3rd party.

My big fear isn't malicious library access, but that the bad actors pushed a malicious update to Plex itself and that my server is now running malicious code doing God knows what on my network.

Re: Plex: Important notice of a potential data breach

#150
post #138

I like that they're up front about this. Solved the problem in a couple of minutes. I use a password manager with a very long randomly generated password for everything, so a hashed password leaking is essentially meaningless to me. Notifying me immediately so that I can change it ASAP is what matters. The burner e-mail I use for stuff like this is listed in 25 other data breeches, too. I don't really care. Plex is a…

> I don't really understand the freak outs here. Because most people reuse the same email address and password, and are potentially way more exposed than you are.

Plus, even if my password isn't exposed, I don't appreciate when my email address is exposed, or I have a username able to be linked to an email address.

Now, should I have been smarter and used a burner email address and username unique to Plex? Definitely. But I signed up with them like 10 years ago.

Post reply on HN