[implemented] Two Factor Authenticator for Plex account

I would like it to see it be used more for administrative purposes. I wouldn’t be to upset(I still be pissed!) if my account was access in a “read only” type of way. 2FA would be used for global settings and media deletion. Sure, we the individuals can set our file systems and restrict access to files BUT the average person does not know how to do that and to be honest, shouldn’t have to. I know many people wanted the ability to use plex to delete media and that’s fine for them but creates a security hole at the same time. I just wish the option to enable/disable file deletion wasn’t so easy to access.
That would be the only reason why I would use 2FA. It would save me so much time not having to edit source files and/or hack the executables. It’s a PITA !!

Yes, I’m not a fan at all that the server is only one tick mark away from being able to delete media, I’d much rather have it as an application sandboxed with no other write permissions than its own database and cache folder.

We’re reading and listening. I’d personally like to see 2FA :sweat_smile:

23 Likes

Plex needs 2FA. Full stop.

Just adding my vote as a Plex Pass user.

2 Likes

r very own Advocate :+1:

Excellent! Thank you for the response!

+1 for me

Let’s make it 1400 :+1:

2FA is a must, so +1 for me

1 Like

+1 here. Two factor authentication is quickly becoming basic web security. There isn’t any clear technical reason why this isn’t implemented.

+1 for this!!

+1, sounds like a good idea.

+1

I too would like to see the official standard protocol implemented:

U2F - FIDO Universal 2nd Factor Authentication

Since this server software is entrusted with all of our personal media files (sensitive if it is family photographs or videos of your young children or other vulnerable members). So therefore being able to improve Plex account security further, from malicious intrusion attempts is absolutely critical. Since photos could have GPS co-ordinates in them or could be mathematically deduced from photo analysis. I have activated 2-factor authentication where it is possible to help to stop or slow down hacking attempts.

@alael May be a good idea if you can edit your post to tag it so that Plex’s team can still see it and they can get the right team to it.

2 Likes

I suggest too the add of 2FA function.

In the current security climate, it is a imperative that 2FA / MFA get implemented and no SMS shouldn’t even be an option due to how broken and easy it is for SIM swapping attacks. U2F / FIDO is a must.

2 Likes

Exactly

My Plex account was hacked last night, 2FA or MFA needs to be implemented hopefully Plex Staff see this

Totally agree, and should definitely be option 2.

Wil Dieteren

Please, Plex. Support 2FA soon. (Hopefully “option 2”, TOTP via software.) Hide it deep in the settings if you must. Just give us some peace of mind. In the meantime, it’d be great if you could better explain the current account security situation.

Yes please!! +1 from me!