this post was submitted on 09 Sep 2025
244 points (99.6% liked)

Selfhosted

59850 readers
380 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam.

  3. Posts here are to be centered around self-hosting. Please ensure it is clear in your post how it relates to self-hosting.

  4. Don't duplicate the full text of your blog or git here. Just post the link for folks to click.

  5. Submission headline should match the article title.

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] FreedomAdvocate 13 points 9 months ago (1 children)

Plex followed best practices and made sure that in the event of a data breach your accounts were safe, and alerted us promptly to the breach and reassured us that nothing private/of value was compromised.

JellyFin knowingly leaves multiple API endpoints with zero authentication.

I know which one I prefer, and it’s not the one with gaping security holes marked as “won’t fix”.

[–] filcuk@lemmy.zip 5 points 9 months ago (1 children)

People don't seem to understand that no-one can reasonably stop a breach today.
The question is whether the attackers got anything of value and how easy they got in.

[–] anas@lemmy.world 0 points 9 months ago (1 children)

This breach was, in fact, very preventable. Plex didn’t need to force users to authenticate with a central server to access their own self-hosted media in the first place.

[–] FreedomAdvocate 5 points 9 months ago

That’s not how “preventable” works.