this post was submitted on 08 Sep 2025
88 points (98.9% liked)

Plex

3008 readers
1 users here now

Welcome to Plex, a community dedicated to Plex, the media server/client solution for enjoying your media!

founded 2 years ago
MODERATORS
 

We have recently experienced a security incident that may potentially involve your Plex account information. We believe the actual impact of this incident is limited; however, action is required from you to ensure your account remains secure.

you are viewing a single comment's thread
view the rest of the comments
[–] papertowels@mander.xyz 8 points 4 months ago* (last edited 4 months ago) (2 children)

No security guy, but if the passwords were just hashed and not salted it's not ideal. Better than plaintext for sure though.

EDIT: Plex employee confirmed they do salt (and pepper, which I'm less familiar with), the last time they were hacked and had passwords exposed, fwiw.

[–] Die4Ever@retrolemmy.com 7 points 4 months ago* (last edited 4 months ago) (1 children)

If they were hashed then they were likely salted too, not much reason to not do both. Especially since they said "in accordance with best practices", otherwise they're just lying lol. They probably just didn't want to make the announcement too technical.

[–] papertowels@mander.xyz 0 points 4 months ago

I choose to believe this lol

[–] FreedomAdvocate 6 points 4 months ago

in accordance with best practices

They absolutely would have been salted, as that is best practice. Just not something the average Plex user understands most likely.