Earlier quoted context omitted.
You're being a bit generous with credit to them. We have no idea how long the malicious actors had access (not do they it seems), nor what depth of access they had. I turned off my server until they have had a chance to verify that no malicious software updates have been pushed. With regard to complex passwords, Plex is one of those accounts that using a random password is quite cumbersome since my kids and I are oft…
I've switched to using jellyfin and i've never looked back.
Plex: Important notice of a potential data breach
171–180 of 194 posts
Re: Plex: Important notice of a potential data breach
#172If true, then this will probably reignite discussions around Plex requiring that you authenticate with their servers when using the service to view content that you're hosting on your own hardware. If anyone is curious, then alternatives like Jellyfin exist. It's a bit different and may not have all the features you need, but it works quite well in my experience.
I just use Universal Media Server now and the built in media-browser on my Samsung TV. It's a bit janky but it works. I've tried using Plex before and while the UI is nice, they don't seem to be able to write a video transcoder that doesn't have massive stuttering in it.
Re: Plex: Important notice of a potential data breach
#173I like that they're up front about this. Solved the problem in a couple of minutes. I use a password manager with a very long randomly generated password for everything, so a hashed password leaking is essentially meaningless to me. Notifying me immediately so that I can change it ASAP is what matters. The burner e-mail I use for stuff like this is listed in 25 other data breeches, too. I don't really care. Plex is a…
> I don't really understand the freak outs here. Because most people reuse the same email address and password, and are potentially way more exposed than you are.
In 2022, your data isn't safe. It's widely known your data isn't safe. You need to take steps to make it matter less when its mishandled.
Don't get me wrong, the Plex infra team should feel bad about themselves, but if this breach in anyway compromises anything else in your life other than your media center -- and if your hashed password gets cracked -- then that's on you in my opinion.
Re: Plex: Important notice of a potential data breach
#174Earlier quoted context omitted.
> a hacker could still compromise a system that has the key in memory. Security is about layers. Simply because a hacker “could” do something, does not mean it’s a bad idea. Getting the encryption key when it’s not stored in the database requires the hacker to now have access not to just the database but to another system as well.
This is an excellent point, but there's nuance to it. This seems like an acceptable solution for email and a lot of other PII. However, if you were to propose the same thing for passwords, with the same argument, I'd be dead against it -- even beyond the total lack of need for the system to ever have the actual password. I'm not quite sure how to explain this, though.
Re: Plex: Important notice of a potential data breach
#175Earlier quoted context omitted.
I've switched to using jellyfin and i've never looked back.
kodi.tv doesn't require any account either. The 2TB SSD I have connected to the RPI hosting it works as a good enough media server for my whole network. I love the unique channels and the ability to stream Newpipe from phone to it. I might try Jellyfin to learn its features.
I purchased a low powered computer with a Celeron N5100 (sorry I might have the model wrong) but I was looking for something that could support and transcode modern video formats in hardware, and connected my external drives too. From there I was able to install Jellyfin, then the Jellyfin clients on all my devices (TV, Phone, iPad etc).
It seems to work really well, espeicaly when exposing the server to the internet using nginx, a SSL certificate, DNS and a dynamic DNS provided by my Asus router. Unsure of the security of this or how to harden it -> VPN might be better for more security conscious people.
You mention you like the unique channels and the Newpipe feature, I don't think any of this is available in Jellyfin, it doesn't seem to be very customisable at all with the exception of a limited list of plugins.
Re: Plex: Important notice of a potential data breach
#176Earlier quoted context omitted.
> I don't really understand the freak outs here. Because most people reuse the same email address and password, and are potentially way more exposed than you are.
I find it hard to believe that most people on HN reuse the same e-mail and password. That practice has always been known to be stupid. There's a whole thing about it in the movie Hackers... from 1995. In 2022, your data isn't safe. It's widely known your data isn't safe. You need to take steps to make it matter less when its mishandled. Don't get me wrong, the Plex infra team should feel bad about themselves, but if…
Temporary email services don't seem helpful either if you need to go through password reset processes or receive emails after the address has been removed.
Do people just use use custom domains with catch all addresses? Is this really the best way?
Re: Plex: Important notice of a potential data breach
#177Earlier quoted context omitted.
I find it hard to believe that most people on HN reuse the same e-mail and password. That practice has always been known to be stupid. There's a whole thing about it in the movie Hackers... from 1995. In 2022, your data isn't safe. It's widely known your data isn't safe. You need to take steps to make it matter less when its mishandled. Don't get me wrong, the Plex infra team should feel bad about themselves, but if…
What's the best way to use unique emails. I get that Apple has the 'Hide my Email' feature but it's not clear to me how to best use it, especially outside of Apple ie. Where do I find a list of emails that it's created for me and what they were used for. Temporary email services don't seem helpful either if you need to go through password reset processes or receive emails after the address has been removed. Do people…
Re: Plex: Important notice of a potential data breach
#178Earlier quoted context omitted.
Jellyfin has an official app for Roku but I am not sure about other platforms like webOS.
No app for webOS (although emby exists). You can, of course, use the Web player over your local network.
Re: Plex: Important notice of a potential data breach
#179Re: Plex: Important notice of a potential data breach
#180Earlier quoted context omitted.
I find it hard to believe that most people on HN reuse the same e-mail and password. That practice has always been known to be stupid. There's a whole thing about it in the movie Hackers... from 1995. In 2022, your data isn't safe. It's widely known your data isn't safe. You need to take steps to make it matter less when its mishandled. Don't get me wrong, the Plex infra team should feel bad about themselves, but if…
What's the best way to use unique emails. I get that Apple has the 'Hide my Email' feature but it's not clear to me how to best use it, especially outside of Apple ie. Where do I find a list of emails that it's created for me and what they were used for. Temporary email services don't seem helpful either if you need to go through password reset processes or receive emails after the address has been removed. Do people…
I used to use a catchall with my domain, but now I use our masked email feature. You need a 1Password account, and for fastmail to be your host.
https://1password.com/fastmail/
Depending on your settings, you can use your own domain (which is portable, but less anonymous) or you can generate *@fastmail.com addresses.