Plex hacked: passwords, usernames and email addresses affected

Published by

Click here to post a comment for Plex hacked: passwords, usernames and email addresses affected on our message forum
https://forums.guru3d.com/data/avatars/m/189/189980.jpg
Oops.
data/avatar/default/avatar08.webp
Hilbert Hagedoorn:

Plex, a popular video platform, warned many users today via e-mail that there had been a security breach in which, in addition to the username, the user's password and e-mail address could have been ... Plex hacked: passwords, usernames and email addresses affected
Hadn't seen the mail - changed PW right away now ! Thanks for the heads up
https://forums.guru3d.com/data/avatars/m/180/180832.jpg
Moderator
changed it, had 2 factor authentication on anyways.
https://forums.guru3d.com/data/avatars/m/189/189980.jpg
Glad I went with Jellyfin.
https://forums.guru3d.com/data/avatars/m/253/253034.jpg
anticupidon:

Glad I went with Jellyfin.
I mean they could have been hacked and just not told you about it
https://forums.guru3d.com/data/avatars/m/189/189980.jpg
True. Nothing is ever 100% secure.
https://forums.guru3d.com/data/avatars/m/166/166942.jpg
Plex? Never heard about it before. 20million users... Jellyfin? Not heard about that either...
https://forums.guru3d.com/data/avatars/m/145/145154.jpg
I use it for free on a local network with external access for PLEX blocked. It's never had any of my personal data or CC#s beyond just an email address. I'll change all the affected devices, but am I missing something? Not sure what exposing my video playlists/habits is going to nefariously accomplish. I suspect this is more scary for people who pay and use PLEX on the road (open to web).
https://forums.guru3d.com/data/avatars/m/92/92165.jpg
0blivious:

I use it for free on a local network with external access for PLEX blocked. It's never had any of my personal data or CC#s beyond just an email address. I'll change all the affected devices, but am I missing something? Not sure what exposing my video playlists/habits is going to nefariously accomplish. I suspect this is more scary for people who pay and use PLEX on the road (open to web).
I doubt anyone was after anything outside of usernames, emails and passwords. That sounds somewhat less egregious but such things are used for credential stuffing attacks. This affects a lot of people that reuse passwords which is probably most people. So while maybe all they did was get your Plex credentials if you reuse them at your bank or whatever then you are at risk. From what I understand, to Plex's credit, they notified everyone VERY quickly and they did even force password resets. I know this because I got the email in the wee hours of the morning and I went to change my password and it was already forcing me to reset. I have used Plex for years and I do use it remotely and I have to this point (knock on wood) not had any security issues.
https://forums.guru3d.com/data/avatars/m/201/201426.jpg
anticupidon:

Glad I went with Jellyfin.
And clown comment goes too..... Plex handled this very well.
https://forums.guru3d.com/data/avatars/m/108/108389.jpg
WhiteLightning:

changed it, had 2 factor authentication on anyways.
Change password for every other site too...
https://forums.guru3d.com/data/avatars/m/189/189980.jpg
Agonist:

And clown comment goes too..... Plex handled this very well.
There we go with all of this. If it makes you happy. Thanks, I just love posting here. Replies like yours makes G3D a wonderful place. Cheers!
https://forums.guru3d.com/data/avatars/m/253/253034.jpg
Also the passwords were all encrypted, so probably not actually an issue (although ofc still change password just in case)
https://forums.guru3d.com/data/avatars/m/246/246171.jpg
I tried Plex for a few days and other than compatibility with more file formats, I just didn't really care that much. Back when I still used a smart TV, I just used miniDLNA - works with the most basic apps, uses practically no resources on your server, works on just about any CPU architecture, and gets the job done just fine. Now, I don't use either. I just have my computers play media files directly.
data/avatar/default/avatar16.webp
gUNN1993:

Also the passwords were all encrypted, so probably not actually an issue (although ofc still change password just in case)
Not strictly true - when they didn't have encripted pw'd it's hard for them to crack. Now they have got the file with them all in they can run over them at some huge rate and will probably have most of them cracked in a few days. If your password uses words and the standard tricks for replacement it will probably be decoded.
https://forums.guru3d.com/data/avatars/m/253/253034.jpg
Dribble:

Not strictly true - when they didn't have encripted pw'd it's hard for them to crack. Now they have got the file with them all in they can run over them at some huge rate and will probably have most of them cracked in a few days. If your password uses words and the standard tricks for replacement it will probably be decoded.
Wow that's madness, well glad I use 20 character randomly generated then XD
https://forums.guru3d.com/data/avatars/m/260/260324.jpg
If you log in with Google you don't have a password so nothing to steal I guess 🙂 .
https://forums.guru3d.com/data/avatars/m/268/268248.jpg
I never used anything like that ....hell I did not even knew the service ! And nowdays I just user the build in droidcast in my phone battery is not and issue and I do not even have to move my royal butt anymore 😛