FYI....
https://forums.plex.tv/t/important-notice-of-security-incident/930523
|
|
|
Somewhat timely receiving a password reset email, with links in it, after the recent NPM developer 2FA phishing email..
Like, I know its legit but I'm still not going to click on the password reset link in the email and did it manually instead
Quic referral link https://account.quic.nz/refer/276294 free setup code R276294EBWOBK

Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies
Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.
dfnt:
Somewhat timely receiving a password reset email, with links in it, after the recent NPM developer 2FA phishing email..
Like, I know its legit but I'm still not going to click on the password reset link in the email and did it manually instead
Same, the people at Plex really should know better than to send an email with a link to click to reset passwords.
Senecio:
dfnt:
Somewhat timely receiving a password reset email, with links in it, after the recent NPM developer 2FA phishing email..
Like, I know its legit but I'm still not going to click on the password reset link in the email and did it manually instead
Same, the people at Plex really should know better than to send an email with a link to click to reset passwords.
"in accordance with best practice".... or not...
hmmm, didn't get the email.... to reset or not to reset....
I did not get a email either. However I use google sign in so perhaps its Plex managed accounts only?
tanivula:
hmmm, didn't get the email.... to reset or not to reset....
Why wouldn't you reset....
signing out of all devices was a punish. Especially trying to claim the server (lxc container in promos on a different vlan).
had to edit preferences.xml
and remove email address and set the local no auth networks
Previously known as psycik
Home Assistant: Gigabyte AMD A8 Brix, Home Assistant with Aeotech ZWave Controller, Raspberry PI, Wemos D1 Mini, Zwave, Shelly Humidity and Temperature sensors
Media:Chromecast v2, ATV4 4k, ATV4, HDHomeRun Dual
Server Host Plex Server 3x3TB, 4x4TB using MergerFS, Samsung 850 evo 512 GB SSD, Proxmox Server with 1xW10, 2xUbuntu 22.04 LTS, Backblaze Backups, usenetprime.com fastmail.com Sharesies Trakt.TV Sharesight
Yeah bugger signing out of all devices, I've just changed my password and I expect that'll be enough.
Join Quic Broadband with my referral - no sign up fee and gives me account credit
Anything I say is the ramblings of an ill informed, opinionated so-and-so, and not representative of any of my past, present or future employers, and is also probably best disregarded.
davidcole:
signing out of all devices was a punish. Especially trying to claim the server (lxc container in promos on a different vlan).
had to edit preferences.xml
and remove email address and set the local no auth networks
Yep, my server is hosted on an nVidia Sheild TV in the comms cabinet so its a pain to reclaim a server. But done now, so my wife can watch her Great British Sewing Bee and I can go to bed safe in the knowledge that I won't be kicked out of the house.
I am pretty happy with their response to this. It's transparent and seems to have been done in a timely fashion. They are storing passwords correctly and are only advising out an adundance of caution.
One of the better recent breach notifications.
As long as you have humans, and an internet connection, you can't guarantee a breach won't occur.
toejam316:That’s a funky function. A password reset imho should drop/expire all active sessions.
Yeah bugger signing out of all devices, I've just changed my password and I expect that'll be enough.
I just did mine today and yes you there’s a button for you to sign out of all websites in the renew password process.
MadEngineer:
toejam316:That’s a funky function. A password reset imho should drop/expire all active sessions.
Yeah bugger signing out of all devices, I've just changed my password and I expect that'll be enough.
Not usually. Having said that, everyone one will have 2fa so it's done
|
|
|