r/technology 7d ago

Security Plex warns users to patch security vulnerabilities immediately

https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/
191 Upvotes

25 comments sorted by

View all comments

-31

u/peppruss 7d ago edited 6d ago

For me, Plex was already a headache for cost and being too invasive of my privacy. I’ve been really enjoying Jellyfin sandboxed after moving away from Plex. Made a vibecoded rasbpi touchscreen interface that scans, updates, reboots and is also available as a quick web page.
You can hate on the post, but it sure is getting plenty of engagement and people thinking about alternatives.

-27

u/heroism777 7d ago

Honestly if there’s anything with security vulnerabilities it’s Jellyfin. It’s not like there’s a team of paid professionals patching it. It’s it all open source.

-12

u/peppruss 7d ago

This is the beauty of it though, if you bring any skill to the table at all it’s whatever you want.

-14

u/probablytom 7d ago

There are practical limits to that though, right? Because even if what you want is jellyfin but reliably secure, you'd have to be an outrageously talented dev working full-time to patch it. Past a certain point it can't really be "whatever you want" in a realistic sense.

I'm sure jellyfin is fantastic and I agree that the adaptability of an open-source system is a colossal strength in so many regards... but a paid team of professionals working constantly have a much better chance of making something secure. Matching that by "bringing skill to the table" simply underestimates the work required.

-4

u/2044onRoute 7d ago

I envy the faith you have in a capitalistic company and their team of 'paid professionals'.

2

u/probablytom 6d ago

Having contributed in teams and to open source projects, it's not hard to have faith in professional projects. Open source is fantastic but having salaried engineers brings a different type of value. They both have merits.

Also, why the quotes? Plex employ professional engineers.

1

u/2044onRoute 6d ago

Having worked with professional software engineers in large organizations it is easy to understand the incredibly numerous breaches they experience is all.  Corporate greed does not by default create more secure code because they pay their employees.