Action required: Important notice of a potential data breach

Man, this is funny. Are you aware that what I am explaining you is a big problem in Germany? I do not like it but it is what it is. I am not even talking about theoretical things, this happens in Germany basically EVERY single day. And everyone in Germany into illegal downloads knows at least one person blackmailed by those lawyers.

Plex is more or less safe as long as it is kept PRIVATE. And with the breach now it seems my server was not private and might still not be private even after doing everything Plex told me to do.

I am not saying Waldorf Frommer (the most prominent lawyer doing that) is going to write software tomorrow to sign in into my server and blackmail me. But it is something that technically might happen, but probably won’t.

Are you BTW American? You seem to keep insisting in thinking that Germany works like America. I am not saying this with the intention to offend you in any way. Just that it looks like that.

Plex is not about illegal downloads.
I know of not a single case where a user of Plex has been fingered as an illegal file sharer, just because they were using Plex and had pirated media on that server.
They were always fingered because they used e.g. torrent software or binary internet news groups and the plaintiff got evidence about that traffic and what was shared or accessed.
Or they were so stupid to try and operate a “pay for share” commercial operation using Plex.

Nope.

Of course Plex is not about illegal downloads, however you know what I am talking about. And in Germany downloads are not really prosecuted, so the problem is uploading. If I am caught uploading something copyrighted without permission I might have problems.

And of course I do not know either anyone blackmailed by the German lawyers due to Plex, because as I mentioned, as long as the server is kept PRIVATE there is no problem here. Having a local “copy” is kind of a protected act, same with the local private reproduction. But once a person outside my private sphere is streaming from my server there might be a problem. And of course as long as Plex is kept PRIVATE there is no issue, but I am learning here that that might not be the case and there could be the “little inconvenience” of an unwanted person streaming my library. That to me is NOT a little inconvenience.

Hence why it was recommended to reset all access tokens.

I think you are lost in the discussion. Of course we know we have to reset them. But then there is the tokens that are not from our own servers and we can’t reset them ourselves. That’s how this whole conversation started.

So you’re asking for a means to force all your shared users to perform the reset procedure as well?

The people asking for a whole general reset did it up there already. Because they came to the conclusion that would be the only way to really restore the safety.

I am more interested in really understanding what happened and its consequences then I can take my own decisions. For example, I think I will have to completely block my server from the outside world due to its current unsafe status.

And it is my feeling Plex has not been clear in all this mess and sometimes the answers to our questions are very defensive. We are even more interested than you in keeping Plex safe. Yes, you were hacked, but we understand these things happen, we just want to move forward. And its been proven difficult without the knowledge.

Man o man, I’m glad I don’t live in Germany where blackmailing lawyers are apparently legit but if you want to share a ripped DVD you bought with a friend using a computer you can go to jail!

Then again, being private doesn’t really matter. All they need to do in Germany is to blackmail one of your friends! But that’s what you get in Blurmany!

Sure, a lot of things can happen, but in general they won’t.

There are plenty examples of lawyers in the U.S. with similar business models. BTW the last German lawyer who got “famous” using entrapment tactics was eventually disbarred and does no longer live.

If you think that as a U.S. citizen you are immune to ppl like this, you are wrong.

1 Like

I think the difference is that generally in the US such lawyers are eventually put behind bars. Do some lawyers in the US sometimes break the law? Sure they do. Am I immune to people like that? No, I’m not. Is it likely to happen to me? Most likely NO. Just don’t move to Germany where apparently such things are rampant…

I will not take this discussion further. Let’s stick to the topic.

I received an e-mail a few days ago that my e-mail address for my plex account had been changed. I used the link provided by Plex to undo the change, then changed my password, added 2FA, re-signed in to my server, etc…

Everything is working as it should now, but I noticed when looking back through previous e-mails that my sign in name / account has always been jzakilla. Now after doing this, my account name / sign in name is jzakilla_

Is there anyone that can point me in the right direction to figure out if the attackers cloned my account or something similar?

Try to simply change it back using the link below. (you might have to wait 1 month before you’re able to do so.)
But since you are not really using it for anything (not even for logging in), you can simply use a better moniker of your choice by setting a “Full Name” in your account settings https://app.plex.tv/desktop/#!/settings/account

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.