Plex Server Web Client Displays Content (Not Mine) Prior to Login

This sums up most of my concerns about the update.

I CANNOT have any video hosting publicly accessible, it’s a ticking time bomb my ISP could jump on. I don’t want the hastle of having to explain that no I do not have the rights to distribute this free content but even though it’s my domain, it’s not actually my content. That would be a fun phone call.

I’ve been using plex for 4 years or so now, I really didn’t mind the plex as a streaming service stuff, but this is too far.

I like the idea of 2 options :

  • Login and access server content
  • Continue without login that then REDIRECTS to plex.tv and does not stay on my domain

I don’t often use the forum but I am truly concerned about this and am seriously considering moving to EMBY now. For the moment I rolled back to a previous version.

10 Likes
  • Continue without login that then REDIRECTS to plex.tv and does not stay on my domain

No, our servers should not be an advertisement banner for Plexs’ own streaming content. I brought Plex to manage and host my own content, end of.

5 Likes

No, our servers should not be an advertisement banner for Plexs’ own streaming content. I brought Plex to manage and host my own content, end of.

In this case, it wouldn’t.

My proposal is as such:

Anon user goes to https://plex.mydomain.com.

User gets the following prompts:
free

So they never actually view anything on your server, it all goes back to how it used to work + the added benefit (to Plex) of allowing their free content to work on their web player via a redirect to plex.tv.

Alternatively, we need people to vote on Restrict Plex Web to LAN Networks

Apologies for the crappy Photoshop job, haven’t used it in years!

4 Likes

If Plex has added functionality to allow web servers to serve content to guests then the admin should decide what content those guests view on the private admins domain/server. If an option is added to continue as guest on a private domain it should keep the user at the private domain and not redirect to plexs server.

Plex forgot to add a few settings in the Plex admin panel before they rolled out this update: Allow/don’t allow guests, the ability to restrict which libraries they can view and restrictions for guests based off Settings - Online Media Sources.

well, I just found this out when testing my plex remote access from another laptop and is horrified seeing plex free contents are there without login…

IMO, this is a bad UX decision in the name of convenient and not considering the privacy of users. Sorry for being blunt, but it is how I see it.

6 Likes

That should be how free content on plex.tv should be handled.

It provided by plex.tv, and so it should redirect to a plex.tv domain in order to see them, NOT on the user’s url exposed to the internet.

I am wondering if this is a violation of IP and will landed individual user running its own plex and expose it for access when not at home in any sort of trouble.

3 Likes

I’d much prefer this. The current design is baffling at best. I miss feeling like I was the one in control over the way Plex behaved.

The lack of continued acknowledgment is a bummer as well - 10 days without a peep is disheartening.

2 Likes

Excellent. I also take great issue with this.

I’ve explicitly disabled all of your online media sources and now I find out anyone who can find my IP and port through shodan can use my web interface to watch content from your service is completely unacceptable. If you don’t have a plex account you should see NOTHING but a login screen on my web interface.

I’m not concerned about my ISP believing this is somehow coming from me. I simply don’t see how this could have ever been considered a good idea. You are essentially turning every internet facing user hosted plex (regardless of whether they participate in your free offerings or not) into an app.plex.tv mirror for free streaming content. Keep that crap on your own domain.

My hosted server, on my internet connection I pay for, is for MY CONTENT, not whatever crap you’re shoveling today.

12 Likes

I couldn’t of said it better, thank you for summarizing how I am feeling.

3 Likes

Any admins/developers want to provide an update to this?

3 Likes

A very encouraging comment from @ChuckPa about our reaction to this change being discussed within Plex.

5 Likes

Management is aware of the perception being created. They had not anticipated it.
At last word they are rethinking this mechanism.
It was done as a way to give more people easy access to free content in the light of COVID restricting everyone’s activities.

well, I guess that’s something
I really don’t want to revert to 1.20 again

but blaming this decision on the current covid situation, seems a bit … shallow at least
you can provide free content on plex.tv to anyone you like
but don’t use my server for this

3 Likes

The biggest “violation” of someone’s server comes from it being accessible on a well known DDNS.

The only thing being loaded is the Plex/Web client.

After that, it jumps to https://app.plex.tv

PS: I shared the screenshot from the OP of this thread with management and presented the case. That’s what brought the realization.

pulls toes out of fishbowl before being bitten :slight_smile:

3 Likes

Obscurity is a good security layer. It’s never sufficient, but is valuable opsec.

Sadly there’s no obscurity on the Internet. Here’s a dynamic list of 300k+ accessible Plex servers.

https://www.shodan.io/search?query=plex

I know that “only” the app is being served. The word “only” is an opinion and a minimization. Consent means being informed and having a choice.

(Mmm, toes. Chomp. Delicious.)

And, very sincerely, thank you for sharing the information.

3 Likes

I at least hope you appreciate the pedicure :stuck_out_tongue:

My server is open to the internet. I keep logs and it’s not been found either… pfSense firewall.

If it’s not too terribly off topic, I’m curious if you did anything special? I had to open 32400, pointed to plex, but that was all. Did you take extra steps to lock it down?

I ask because I’ve had some trouble getting plex to authenticate successfully when logging in locally. A bit frustrating when my server is, evidently, free to serve up everything plex has on offer to the whole wide internet, but I can’t even log in to watch my own media, on my own LAN.

Thanks for the update, Chuck. Nice to hear someone fighting this corner.

Mistakes like this happen. People think they’re doing the right thing, but they sometimes don’t think about it from a different perspective. That’s likely all that’s gone on here and I’m glad it’s being discussed seriously.

Best,

2 Likes

I received an alert in my Plex app saying a new device (Chrome) had connected to my server. Seeing as it was the middle of the workday and nobody that uses my server uses Chrome to watch movies, I had to check to make sure my credentials weren’t compromised. I use individual, randomized passwords for all sites so my main concern was Plex got breached.

Looking at the logs, someone from India had connected, downloaded some javascript files (about 12 MB worth) with 200 response codes, then there were some 401’s, then that’s it.

Is that what it looks like when someone connects and gets pushed to plex.tv for the free streaming? Why did I get a new device alert for that? It didn’t appear that anybody logged in, but all of the get requests in the debug log end in ‘signed in’.

1 Like

What notification did you receive? The “New Device [User] used a new device to access [Servername]: Chrome” mobile push notification?

Save your logs.

Consider opening a new topic for this, too - it would be nice if a Plex person reviewed the logs and could speak precisely about it and about your account.

I agree with most of your thought process. A drive-by shouldn’t generate a notification about server access.

It is possible for a stranger to log into their account after loading Plex Web from your Plex Server. I don’t think that generates a notification either.

Yes, that’s the notification. The username, I believe, was mine in the alert, which is why i was really concerned. I can’t find anywhere to look at previously closed alerts on iOS. I have the logs saved, I’ll open a new thread and see what happens.