back to article Attacker snags account details from streaming service Plex

Users of popular streaming and media organizing service Plex are waking up to an unpleasant email this morning saying, in the words of a Reg reader, "Plex have been hacked and their main site is down as we all rush to change passwords." The email, forwarded by several readers, states that a third-party attacker was able to …

  1. Anonymous Coward
    Anonymous Coward

    Password reset - but what about people using 3rd party signon

    Ok.

    I use plex. I sign in using the SSO/Google option.

    I got the email.

    Am I meant to change my Google account password? Instructions unclear....

    1. Anonymous Coward
      Anonymous Coward

      Re: Password reset - but what about people using 3rd party signon

      Presumably the email was sent to all plex accounts, regardless of whether they're signing in directly, or using a 3rd party oauth provider.

    2. darkknight

      Re: Password reset - but what about people using 3rd party signon

      I use SSO/Google primarily - I did not get the plex email to that address. I did get it to an old address that did not use any SSO.

  2. chivo243 Silver badge

    Plex...

    I tried to use it, had to create an account, reluctantly did that, then it was down hill, where's this we can't find that...

    If they have my login, I'm not really sure if anything is lost?

    My login name and password are unique to me... only email address is reused anywhere ;-}

  3. Paul Hovnanian Silver badge

    Hashed passwords

    What's the hash of "password1"?

    1. katrinab Silver badge
      Trollface

      Re: Hashed passwords

      10b222970537b97919db36ec757370d2

      1. BackToTheFuture

        Re: Hashed passwords

        Have a sprinkling of Salt with that:

        nNK320c7J7mzbI_e^JCGy|x_~/2wmNYv#&EmFXdtPLd[J|/1R[

  4. katrinab Silver badge
    Meh

    I switched to Jellyfin ages ago. It is entirely self-hosted. I'm not really sure what benefits you get from Plex.

    1. MattPi

      I tried Jellyfin too a little, and it's fine for *me* (clunky, requires some system knowledge like most people reading the comments here have), but I didn't feel like it was ready for the rest of my household to use. I should give it another whirl.

      1. katrinab Silver badge
        Meh

        Actually using it, if you have set it up, I would say is as easy as using something like Netflix. Set up a Samba share for the media folder, and adding things is as easy as copying files to it, and doing a rescan if you are to impatient to wait for the autoscan.

    2. tekHedd

      Ready for prime time (lol see what I did there)

      Endorsed.

      I switched to Jellyfin for the second time this summer and this time it stuck. It's entirely usable now with only a few minor glitches. And a *very* long initial scan when I accidentally pointed it at my largeish music library.

      I'm using the Roku app, the Android TV app and the web app and they all work.

  5. Roger Lipscombe

    I ditched Plex a while back -- we're using Emby these days. I wonder how I go about deleting my Plex account?

    1. Anonymous Coward
      Happy

      If you want to delete your Plex account, log into Plex, access your account page, and at the bottom there is an option is red which says 'Delete your account'.

      My money is on that one.

  6. Scott 26

    Cheery news to wake up to.

    But wasn't too laborious to change my password - the only thing extra I had to do was "claim" my media server once I was signed back in and it 'unlocked' my library.

    1. Captain Scarlet
      Mushroom

      Ah yes I reset my password without looking and then found I wasn't authorised for my Plex install. impossible to claim back my server through the gui, found the forum had around 30 people with the same issue as me.

      Instructions for claiming back were all over the place and different wherever you looked with forums having extra steps. Use the linux instructions on the forums, the NAS instructions are cobblers.

      Just now raging my interface for tv and tablet reset (Thanks for removing all my server shortcuts and not adding them back when claimed!).

      Friend has Embery and is gloating, so think this is the kick needed to look at it and some others, as not interested in the spammy features being introduced and I pay yearly I expect to be able to log a proper support ticket (Reason my friend went to Embery when he had an issue with Plex Media Server randomly crashing and got told sorry nothing we can do even though he had PlexPass).

  7. Anonymous Coward
    Anonymous Coward

    It Was A Lot Of Faffing About...

    I got the email first thing this morning.

    The problem was that they sent it out, but were then obviously doing things to the Plex site. So it wasn't initially possible to change your password, and then you couldn't log in because Plex was down.

    Once I'd got through that, my Fire Cube decided it couldn't see my files because the password change had messed up the authorisations (from what I could gather from the messages). All was working on the NAS - eventually, because with Plex being intermittently down it kept tossing errors at me.

    I ultimately ended up deleting Plex on the Cube and reinstalling it, after which it wouldn't even show online content, let alone my NAS, and that was after not being able to use the Plex connect feature, because that was also intermittently down. But on the Plex forums it became clear that there were still issues and everyone else was having the same kinds of problems (once you filtered out the pointless discussions about what sort of password to use, which was about 95% of them, actually).

    Finally, I uninstalled and reinstalled it again this evening and it connected first time.

    Bloody annoying, though.

  8. tiggity Silver badge

    What subset?

    I registered years ago, tried it and it was not for me (ironically had various security concerns)

    The notify all users thing is irritating as no idea if my old, inactive account was included.

    .. though it does smell like they are not sure what data has been lost and are thus notifying everyone

  9. Frank Bitterlich

    Password not reset

    Apparently, they did not reset all passwords; I was able to login today with a direct password, and was not asked to set a new one.

    The messy communications around this incident makes me believe they were pretty much blindsided by it and didn't really have a plan for it.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like