Curious on hacking

I see semi frequent posts her about peoples Plex account being hacked. I do not see any web searches indicating Plex is careless or particularly weak security wise such that this should be an issue.

So I wonder, is it really hacking i.e. breaking someone’s password or stealing it via wed tools or more like poor password use of old passwords or sharing accounts?

I just don’t see why a real hacker would bother hacking most peoples Plex account, not worth the time.

Any opinions?

Theoretically it can be both, but usually it is only the latter.
Tatulli is a rewarding target, because:

  • it is often left accessible from the internet (might be desired functionality, but it carries a risk)
  • often, no authentication is required (user error)
  • Tatulli shows the access Token in cleartext, directly in its Settings area. (bad design decision by the developer)

You can sell “sharing” access to the server.
If you happen to capture an account with a lifetime Plex Pass, you can sell the account as such.

Even though both can be remedied in several ways, some twerps keep on doing it.

Good to know, basically stay away from Tatulli and use a good password practice and there should be no issues

Tautulli is a fine software, but you need to follow the guide to set it up and secure it.

It is that and some third party’s software implementations that have poor security.

The best security is do not allow remote access and the second best is strong passwords and having secure connections and not using or properly configuring any third party software. There is no third best.