Live data from Hacker News

Plex: Important notice of a potential data breach

news.ycombinator.com

171–180 of 194 posts

Re: Plex: Important notice of a potential data breach

#171

Earlier quoted context omitted.

You're being a bit generous with credit to them. We have no idea how long the malicious actors had access (not do they it seems), nor what depth of access they had. I turned off my server until they have had a chance to verify that no malicious software updates have been pushed. With regard to complex passwords, Plex is one of those accounts that using a random password is quite cumbersome since my kids and I are oft…

I've switched to using jellyfin and i've never looked back.

kodi.tv doesn't require any account either. The 2TB SSD I have connected to the RPI hosting it works as a good enough media server for my whole network. I love the unique channels and the ability to stream Newpipe from phone to it. I might try Jellyfin to learn its features.

Re: Plex: Important notice of a potential data breach

#172
post #89

If true, then this will probably reignite discussions around Plex requiring that you authenticate with their servers when using the service to view content that you're hosting on your own hardware. If anyone is curious, then alternatives like Jellyfin exist. It's a bit different and may not have all the features you need, but it works quite well in my experience.

I just use Universal Media Server now and the built in media-browser on my Samsung TV. It's a bit janky but it works. I've tried using Plex before and while the UI is nice, they don't seem to be able to write a video transcoder that doesn't have massive stuttering in it.

It's using ffmpeg. It's limited by the CPU/GPU on the server. You can adjust the options to have it encode faster or higher quality.

Re: Plex: Important notice of a potential data breach

#173
post #138

I like that they're up front about this. Solved the problem in a couple of minutes. I use a password manager with a very long randomly generated password for everything, so a hashed password leaking is essentially meaningless to me. Notifying me immediately so that I can change it ASAP is what matters. The burner e-mail I use for stuff like this is listed in 25 other data breeches, too. I don't really care. Plex is a…

> I don't really understand the freak outs here. Because most people reuse the same email address and password, and are potentially way more exposed than you are.

I find it hard to believe that most people on HN reuse the same e-mail and password. That practice has always been known to be stupid. There's a whole thing about it in the movie Hackers... from 1995.

In 2022, your data isn't safe. It's widely known your data isn't safe. You need to take steps to make it matter less when its mishandled.

Don't get me wrong, the Plex infra team should feel bad about themselves, but if this breach in anyway compromises anything else in your life other than your media center -- and if your hashed password gets cracked -- then that's on you in my opinion.

Re: Plex: Important notice of a potential data breach

#174

Earlier quoted context omitted.

> a hacker could still compromise a system that has the key in memory. Security is about layers. Simply because a hacker “could” do something, does not mean it’s a bad idea. Getting the encryption key when it’s not stored in the database requires the hacker to now have access not to just the database but to another system as well.

This is an excellent point, but there's nuance to it. This seems like an acceptable solution for email and a lot of other PII. However, if you were to propose the same thing for passwords, with the same argument, I'd be dead against it -- even beyond the total lack of need for the system to ever have the actual password. I'm not quite sure how to explain this, though.

There’s no reason a company needs to know your password. But they do need to know a way to contact you.

Re: Plex: Important notice of a potential data breach

#175

Earlier quoted context omitted.

I've switched to using jellyfin and i've never looked back.

kodi.tv doesn't require any account either. The 2TB SSD I have connected to the RPI hosting it works as a good enough media server for my whole network. I love the unique channels and the ability to stream Newpipe from phone to it. I might try Jellyfin to learn its features.

Not sure how you've setup Kodi however I switched from Kodi to Jellyfin about a year ago.

I purchased a low powered computer with a Celeron N5100 (sorry I might have the model wrong) but I was looking for something that could support and transcode modern video formats in hardware, and connected my external drives too. From there I was able to install Jellyfin, then the Jellyfin clients on all my devices (TV, Phone, iPad etc).

It seems to work really well, espeicaly when exposing the server to the internet using nginx, a SSL certificate, DNS and a dynamic DNS provided by my Asus router. Unsure of the security of this or how to harden it -> VPN might be better for more security conscious people.

You mention you like the unique channels and the Newpipe feature, I don't think any of this is available in Jellyfin, it doesn't seem to be very customisable at all with the exception of a limited list of plugins.

Re: Plex: Important notice of a potential data breach

#176
post #138

Earlier quoted context omitted.

> I don't really understand the freak outs here. Because most people reuse the same email address and password, and are potentially way more exposed than you are.

I find it hard to believe that most people on HN reuse the same e-mail and password. That practice has always been known to be stupid. There's a whole thing about it in the movie Hackers... from 1995. In 2022, your data isn't safe. It's widely known your data isn't safe. You need to take steps to make it matter less when its mishandled. Don't get me wrong, the Plex infra team should feel bad about themselves, but if…

What's the best way to use unique emails. I get that Apple has the 'Hide my Email' feature but it's not clear to me how to best use it, especially outside of Apple ie. Where do I find a list of emails that it's created for me and what they were used for.

Temporary email services don't seem helpful either if you need to go through password reset processes or receive emails after the address has been removed.

Do people just use use custom domains with catch all addresses? Is this really the best way?

Re: Plex: Important notice of a potential data breach

#177
post #176

Earlier quoted context omitted.

I find it hard to believe that most people on HN reuse the same e-mail and password. That practice has always been known to be stupid. There's a whole thing about it in the movie Hackers... from 1995. In 2022, your data isn't safe. It's widely known your data isn't safe. You need to take steps to make it matter less when its mishandled. Don't get me wrong, the Plex infra team should feel bad about themselves, but if…

What's the best way to use unique emails. I get that Apple has the 'Hide my Email' feature but it's not clear to me how to best use it, especially outside of Apple ie. Where do I find a list of emails that it's created for me and what they were used for. Temporary email services don't seem helpful either if you need to go through password reset processes or receive emails after the address has been removed. Do people…

There are email Alias services such as anonaddy.com or SimpleLogin.io doing the same thing hide my email is doing.

Re: Plex: Important notice of a potential data breach

#178
post #86

Earlier quoted context omitted.

Jellyfin has an official app for Roku but I am not sure about other platforms like webOS.

No app for webOS (although emby exists). You can, of course, use the Web player over your local network.

Just released on Official store. https://jellyfin.org/posts/webos-july2022/

Re: Plex: Important notice of a potential data breach

#180
post #176

Earlier quoted context omitted.

I find it hard to believe that most people on HN reuse the same e-mail and password. That practice has always been known to be stupid. There's a whole thing about it in the movie Hackers... from 1995. In 2022, your data isn't safe. It's widely known your data isn't safe. You need to take steps to make it matter less when its mishandled. Don't get me wrong, the Plex infra team should feel bad about themselves, but if…

What's the best way to use unique emails. I get that Apple has the 'Hide my Email' feature but it's not clear to me how to best use it, especially outside of Apple ie. Where do I find a list of emails that it's created for me and what they were used for. Temporary email services don't seem helpful either if you need to go through password reset processes or receive emails after the address has been removed. Do people…

Disclosure: I work at 1Password.

I used to use a catchall with my domain, but now I use our masked email feature. You need a 1Password account, and for fastmail to be your host.

https://1password.com/fastmail/

Depending on your settings, you can use your own domain (which is portable, but less anonymous) or you can generate *@fastmail.com addresses.

Post reply on HN