this post was submitted on 09 Sep 2025
243 points (99.6% liked)

Selfhosted

52520 readers
958 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
top 50 comments
sorted by: hot top controversial new old
[–] floofloof@lemmy.ca 70 points 1 month ago (26 children)

Went there to update my password but got reminded what a horrible experience Plex is these days, so deleted my account instead.

[–] JustARaccoon@lemmy.world 10 points 1 month ago (1 children)

Wdym it's like a couple of clicks

[–] kbobabob@lemmy.dbzer0.com 4 points 1 month ago

They're probably just using some shit browser or something. I had no issues either.

load more comments (24 replies)
[–] FreedomAdvocate 36 points 1 month ago (1 children)

Should have been put in the OP because people are going to jump the gun:

While we quickly contained the incident, information that was accessed included emails, usernames, securely hashed passwords and authentication data.

Any account passwords that may have been accessed were securely hashed, in accordance with best practices, meaning they cannot be read by a third party.

[–] AreaKode@lemmy.world 26 points 1 month ago (1 children)

Still, always good practice to change your password after this sort of leak. However unlikely it is that someone could access your account, it's never a bad idea.

[–] FreedomAdvocate 6 points 1 month ago (2 children)

If you use a unique password and have 2FA on there’s no real need, but yeah it can’t hurt.

load more comments (2 replies)
[–] ramenshaman@lemmy.world 24 points 1 month ago (2 children)

Glad I started out with Jellyfin

[–] JustEnoughDucks@feddit.nl 5 points 1 month ago* (last edited 1 month ago)

I mean, jellyfin is absolutely even.more of a security nightmare than Plex, with multiple unfixed CVEs IIRC (software, not website or forum)

I use jellyfin also, but I only trust it not exposed to the internet at all. That is one very big area of improvement for them.

That and subtitle syncing.

load more comments (1 replies)
[–] bridgeenjoyer@sh.itjust.works 16 points 1 month ago (6 children)

Meanwhile I made a post asking if plex is bad now and most people on it said "no it's great I paid for my lifetime pass years ago and its been the best!" Yeah, we know the truth now.

Jellyfin all the way.

[–] TrickDacy@lemmy.world 32 points 1 month ago (11 children)

Seems unlikely that this happened. Most people on Lemmy despise Plex and forgive all the shortcomings of Jellyfin

[–] bridgeenjoyer@sh.itjust.works 7 points 1 month ago

Thats what I thought too. But I posted on ask lemmy, not here.

load more comments (10 replies)
[–] AmbiguousProps@lemmy.today 17 points 1 month ago* (last edited 1 month ago) (5 children)

I'd love to switch. I would do it right now, but the problem is that Jellyfin's security isn't better if you open it up to the internet. For example, I'd have to set up a VPN for my remote users for proper security, and most of my users are in other states, not technically inclined, and watch on their TVs. I'd have to at least support a raspberry pi for them, or some sort of site to site VPN, and if it goes down, I'll be expected to fix it. On top of that, if I do a simple raspberry pi based VPN, it would be made even more complicated since they'd want it to work with their smart TVs.

Again, I really want to switch. But Jellyfin needs to fix their security issues before I can. I'm also happy with the way Plex is reporting this, it's above the standard "your data is lost" notifications.

Edit: here's a link to the related GitHub issue I've been following: https://github.com/jellyfin/jellyfin/issues/5415

And @Saik0Shinigami@lemmy.saik0.com has a great thread explaining more: https://lemmy.today/comment/18923504

[–] bagodogs@sh.itjust.works 9 points 1 month ago (1 children)

Jellyfin is great... As long as you're the only one who needs to access the server. I've switched to using Jellyfin myself, but I still run Plex for others to access.

I've found that I get a smoother playback experience on Jellyfin, but even outside of potential security issues, there are a still couple of features I miss from Plex.

[–] Seefoo@lemmy.world 4 points 1 month ago (1 children)
[–] bagodogs@sh.itjust.works 3 points 1 month ago

One was automatic collections, but the plugin for this has since been updated, and the bug I was experiencing has been fixed. The one remaining feature that I'm missing is user ratings for media. On Plex I have automatic collections of movies that I've rated four and five stars, and it's quite useful.

[–] exu@feditown.com 4 points 1 month ago (4 children)

Most of these require some form of random id to exploit, which leaves you either brute forcing ids or brute forcing a user account

[–] AmbiguousProps@lemmy.today 4 points 1 month ago (1 children)

I mean, that's fine, but it's still an issue and a risk that would cause me to want to use VPN for remote viewing. It doesn't seem like security is Jellyfin's priority at the moment, not that it's Plex's either, but it's not to a place where it's worth it to switch from a security standpoint, personally.

[–] MaggiWuerze@feddit.org 4 points 1 month ago (5 children)

Plex has a whole team dedicated to security. It's obviously not perfect and it is a larger attack surface than Jellyfin, but I'll take that any day over devs who treat security as an afterthought

load more comments (5 replies)
[–] MaggiWuerze@feddit.org 4 points 1 month ago* (last edited 1 month ago) (6 children)

Again, its not random. It's not a UUID. Its an md5 hash of the filepath. Which is easily guessable since most people have a very similar if not identical folder structure, especially since a lot have it managed by the *arr suite. take that plus the publicly available release names for movies and you're done

load more comments (6 replies)
load more comments (2 replies)
[–] binarytobis@lemmy.world 4 points 1 month ago

My big complaint with Jellyfin is that their documentation showed a “fast forward” hotkey that convinced me to switch from Plex, and when I started it up it was a misnamed “jump forward five seconds” button instead.

It’s still better for my needs, but I remain angry.

load more comments (2 replies)
[–] FreedomAdvocate 13 points 1 month ago (1 children)

Plex followed best practices and made sure that in the event of a data breach your accounts were safe, and alerted us promptly to the breach and reassured us that nothing private/of value was compromised.

JellyFin knowingly leaves multiple API endpoints with zero authentication.

I know which one I prefer, and it’s not the one with gaping security holes marked as “won’t fix”.

[–] filcuk@lemmy.zip 5 points 1 month ago (2 children)

People don't seem to understand that no-one can reasonably stop a breach today.
The question is whether the attackers got anything of value and how easy they got in.

load more comments (2 replies)
[–] remon@ani.social 6 points 1 month ago* (last edited 1 month ago)

Even is plex is "bad" now, it's still years ahead of jellyfin.

[–] Hupf@feddit.org 4 points 1 month ago

Leave Plex

alone!

[–] icylobster@lemmy.world 4 points 1 month ago (1 children)

Plex hasn't been getting better, but it still does what I need. I have a lifetime pass from years ago. If I was starting today I would be a lot less inclined to pay for Plex though. They keep adding things I don't want.

load more comments (1 replies)
[–] gerowen@lemmy.world 6 points 1 month ago

I dropped it in favor of Jellyfin some time back, but this was a good excuse to go ahead and delete my family's accounts.

load more comments
view more: next ›