We have recently experienced a security incident that may potentially involve your Plex account information. We believe the actual impact of this incident is limited; however, action is required from you to ensure your account remains secure.

you are viewing a single comment's thread
view the rest of the comments
[–] 21 points 1 year ago (7 children)

I’m no Plex fanboy but from what I’ve read Jellyfin auth leaves a lot to be desired from a security standpoint, particularly if you are opening it to the web. And chances are if your jellyfin server was breached, you wouldn’t get an email about it.

  • source
  • parent
  • hideshow 7 child comments
  • [–] 14 points 1 year ago (6 children)

    It's simple, don't open it to the web directly.

    If you have the ability to make your server public you also have the ability to put Wireguard on it, and after initial setup it's trivial to use it.

    You shouldn't really host publicly any service that you won't be monitoring regularly for security incidents.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 22 points 1 year ago (4 children)

    But I like sharing my plex library with people.

    Jellyfin’s gonna be a bigger project than I thought I guess.

  • source
  • parent
  • hideshow 4 child comments