• AtariDump@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    6
    ·
    23 hours ago

    Which doesn’t have half the features and crap security compared to Plex/Emby.

    • xthexder@l.sw0.com
      link
      fedilink
      English
      arrow-up
      14
      arrow-down
      1
      ·
      edit-2
      20 hours ago

      The security thing is ironic because my personal Jellyfin server (nor anything else on it) has been hacked, but Plex itself has had their database leaked recently. It’s actually the main reason I switched because I don’t like their auth servers being a giant common target. (Also, technically it theoretically means Plex employees can just let themselves in to people’s private servers)

      • kieron115@startrek.website
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        15 hours ago

        From their blog post about it:

        An unauthorized third party accessed a limited subset of customer data from one of our databases. While we quickly contained the incident, information that was accessed included emails, usernames, securely hashed passwords and authentication data. Any account passwords that may have been accessed were securely hashed, in accordance with best practices, meaning they cannot be read by a third party.

        The passwords were hashed and, I’m inferring from their language, salted per-user as well. Assuming a reasonable length password (complexity doesn’t matter much here, what we want is entropy) it would take a conventional (i.e. not quantum) computer tens to hundreds of millions of years to crack one user’s password.

        • xthexder@l.sw0.com
          link
          fedilink
          English
          arrow-up
          3
          ·
          15 hours ago

          Yeah, I’m not really worried about it. I changed my password and moved on. It’s just that hackers have every reason to try and exploit Plex, while individual servers are hardly worth someone’s time and effort to go after when the payoff is maybe 1-2 usernames and emails