Action required: Important notice of a potential data breach

Thanks @FordGuy61
Yes, the Synology server is present in the list of authorized devices.
Yes also I am using DSM 7.0
So I have to delete it via the packages interface on the synology

MyDS218 - Synology DiskStat...

When you say reinstall PMS using the Claim token option, how should I proceed?

Thanks again :slight_smile:
Skelton

This! Exactly! Got the security breach email. I read through it and followed the instructions. Now locked out of my server with no option that I see to reclaim my server. I appreciate the quick action taken by plex but I think it could have been handled better.

same and now it doesn’t even show up so not able to claim

Thanks @FordGuy61 , uninstalling it worked and I managed to see the server under the General section. I also managed to reclaim it (without a token) but my libraries have completely disappeared. All my settings have reset as well… This is very frustrating.

Hello @Skeltondark,

Do I have to remove PMS from Synology and then reinstall it for it to work again?
(And if I do that I will lose my entire film/series library…)

Yes. I think it works fine again.
You can uninstall with “Sign out and unclaimed this server”.
It isn’t affected your server data includes entire library.
After that reinstall PMS with claim server token.

1 Like

Thanks for posting. Would these instructions apply to plex not running on a Synology NAS?

For what it’s worth, while a little fiddly, resetting my password and getting everything to work correctly again and so far has the iPad app seemed to work OK.

I reset my password online then went into PMS, restarted it, logged in with the new password and reclaimed the server.

And then went into the app, logged out and log back in and happy days.

I’ll still have to deal with this on other devices but all things being equal a minor inconvenience.

I host PMS in a Windows VM pointing to a NAS.

I am at odds with the notion that you have to reclaim the server by simply changing your password. After all, it is still the same account.

1 Like

This is what I’m afraid of. A “simple” password change SHOULD NOT cause so many other issues.

2 Likes

@EspenB89 No, Plex would not hold the password for your Google account, they would pass authentication over to Google and Google would confirm it and pass confirmation back to Plex as part of the SSO process.

The hackers would, however, have gotten hold of your Google email address as this would be associated with your Plex.tv account. So, I do not think you should be concerned with your password (encrypted or otherwise) being taken in the breach.

I would personally not be inclined to use 3rd-party authentication to log into any service and use a unique email/password combo for each service I use, as this prevents any chain-reaction after a data breach such as this.

Not shilling, but something like SimpleLogin can assist here.

Thank you for your response @fusengum (@FordGuy61),

for the deletion which option should I choose to be sure not to do anything stupid:

Uninstall only.Keep all existing files for later reinstallation.

Uninstall the package. Delete all account information. Preserve all metadata.

Erase all Plex Media Server from this system. (Non-recoverable)

Thanks a lot.
Skelton

Or use appropriately complex/lengthy passwords. All too often people go with the minimum eight character length.

Length of password above most other criteria will effectively be the determining factor of how easy or difficult it is to break.

Hey PLEX can you not spaming the password change afrer openning web interface? Im not going to do it while I read this thread… so stop that already!

Same here. My Server doesn´t show up. Fu.k this!

The uninstall/re-install method is specific to Synology DSM 7.

Removing the server from Authorized Devices will work on any server.

Claiming by using the IP address will also work on any server (you can’t use 127.0.0.1 or localhost on a Synology, as it is headless).

Another user unable to claim their server after following the password reset steps.

  • Running Plex on TrueNAS. Reset password and no prompt to claim the server.
  • Remove server from authorised devices. No prompt to claim the server.

Appreciate the quick response to the breach but as others have said, there are clearly some process improvements needed in how Plex manages and recovers devices.

I’ve found that resetting things wiped the setting for what libraries were being shared with the managed user on my account. I think I saw a warning about this regarding my server being de-authorized from my account. The surprising thing is that when no libraries have been set to share with a user Plex seems to think that counts as ALL libraries shared?

I changed from my profile to the managed user on my Smart TV after re-authing it and the Managed User had access to all the server libraries suddenly.

I went in on the web interface and confirmed it showed as no libraries set to be shared. I re-added the correct libraries, and when I went back into the smart TV app the other libraries were still on the sidebar, but if you select them they display as empty. After doing a Reset of Customization and powering the TV off and back on after 30 seconds the sidebar shows the correct libraries now.

Just wanted to mention this for anyone with kids set up as Managed Users and aren’t thinking of checking if their shared libraries are still correct.

I also had issues resetting my password - and now cannot see my Plex Server at all - on the UI it just says ‘Connecting’… when you say reclaim, is there a guide I can follow? I am using a Asustor NAS for my Plex media server

1 Like

Nope - nothing working. Removed Server (Ubuntu / Linux / Raspberry Pi) from Plex authorized devices. Go back into Settings. No option to claim. However server is now gone. Brilliant programming. Trying localhost / SSH tunnel - then General. That doesn’t work - can’t claim - no option for it. Using the Curl also doesn’t work - shows unauthorized. I’m sure uninstall would remove all libraries, out of options from what I can see - Wishing I had not followed the email directive as it obviously wasn’t thought through.

I was in the same boat. This is what I did:

PMS is running on unraid on a different subnet.
Started windows vm on unraid
Used chrome on vm to open plex
Then drilled down to server and clicked on it
Was able to claim.

If you don’t it on a different subnet then I don’t know
If you don’t have a vm to access it with then use ssh tunnel mentioned earlier.
hope this helps

In Synology Package Manager, uninstall Plex Media Server. Use the “Sign out and unclaim this server” option.

In Synology Package Manager, re-install Plex Media Server, using the Claim Token option. Additional screens will show you how to obtain and enter the token.

Then login to your server via the local IP address. Once that is successful, you can login via app.plex.tv.

Note: You need to be on the same subnet as your server. If you are remote, you’ll have to use a SSH tunnel.

2 Likes