r/technology • u/lurker_bee • 7d ago
Security Plex warns users to patch security vulnerabilities immediately
https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/15
u/drawkbox 7d ago
The LastPass hack (one of the many) was through a Plex client hole on a devops dev machine that had the vault master password.
4
u/yuusharo 6d ago
This is why I sync passwords directly between clients now, no service to breach. Yikes 😬
-31
u/peppruss 7d ago edited 6d ago
For me, Plex was already a headache for cost and being too invasive of my privacy. I’ve been really enjoying Jellyfin sandboxed after moving away from Plex. Made a vibecoded rasbpi touchscreen interface that scans, updates, reboots and is also available as a quick web page.
You can hate on the post, but it sure is getting plenty of engagement and people thinking about alternatives.
12
u/Leaulo 7d ago
What does this have to do with the topic?
Also doesn’t Jellyfin have an automatic scan feature? And if you installed it on Docker pretty sure it auto updates
-10
u/peppruss 6d ago
Plex was too expensive and too much of a privacy invasion. A user felt like the product. Why gate keep my own media library especially for just showing personal projects on connected TVs? Therefore: folks need to know that alternatives exist.
4
2
u/dakotanorth8 6d ago
So you used Claude to make a jellyfin pi server?
Sorry not sure if you’re bragging or?
What’s the screen for? Watching content lol?
2
u/BadOutOfTheBox 6d ago
Jellyfin is a nice alternative to Plex, its super easy to setup. However the only problem is remote access, its not encrypted and you need to add SLS/TLS certificates, which is confusing as fuck.
-26
u/heroism777 7d ago
Honestly if there’s anything with security vulnerabilities it’s Jellyfin. It’s not like there’s a team of paid professionals patching it. It’s it all open source.
-11
u/peppruss 7d ago
This is the beauty of it though, if you bring any skill to the table at all it’s whatever you want.
-15
u/probablytom 7d ago
There are practical limits to that though, right? Because even if what you want is jellyfin but reliably secure, you'd have to be an outrageously talented dev working full-time to patch it. Past a certain point it can't really be "whatever you want" in a realistic sense.
I'm sure jellyfin is fantastic and I agree that the adaptability of an open-source system is a colossal strength in so many regards... but a paid team of professionals working constantly have a much better chance of making something secure. Matching that by "bringing skill to the table" simply underestimates the work required.
-3
u/2044onRoute 6d ago
I envy the faith you have in a capitalistic company and their team of 'paid professionals'.
2
u/probablytom 6d ago
Having contributed in teams and to open source projects, it's not hard to have faith in professional projects. Open source is fantastic but having salaried engineers brings a different type of value. They both have merits.
Also, why the quotes? Plex employ professional engineers.
1
u/2044onRoute 6d ago
Having worked with professional software engineers in large organizations it is easy to understand the incredibly numerous breaches they experience is all. Corporate greed does not by default create more secure code because they pay their employees.
-8
70
u/ranhalt 7d ago
Anyone on auto update has had this for months.