We have recently experienced a security incident that may potentially involve your Plex account information. We believe the actual impact of this incident is limited; however, action is required from you to ensure your account remains secure.

  • FreedomAdvocate@lemmy.net.au
    link
    fedilink
    English
    arrow-up
    14
    ·
    2 days ago

    Any account passwords that may have been accessed were securely hashed, in accordance with best practices, meaning they cannot be read by a third party.

    Rest assured that we do not store credit card data on our servers, so this information was not compromised in this incident.

    Sounds like as far as security incidents go, this is as good as they can be. Sounds like someone got in and could maybe see some email addresses and not much else.

    • papertowels@mander.xyz
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      1
      ·
      edit-2
      2 days ago

      No security guy, but if the passwords were just hashed and not salted it’s not ideal. Better than plaintext for sure though.

      EDIT: Plex employee confirmed they do salt (and pepper, which I’m less familiar with), the last time they were hacked and had passwords exposed, fwiw.

      • Die4Ever@retrolemmy.com
        link
        fedilink
        English
        arrow-up
        7
        ·
        edit-2
        2 days ago

        If they were hashed then they were likely salted too, not much reason to not do both. Especially since they said “in accordance with best practices”, otherwise they’re just lying lol. They probably just didn’t want to make the announcement too technical.

      • FreedomAdvocate@lemmy.net.au
        link
        fedilink
        English
        arrow-up
        5
        ·
        2 days ago

        in accordance with best practices

        They absolutely would have been salted, as that is best practice. Just not something the average Plex user understands most likely.