PSA: Linking a Google/Facebook account gives you a permanent backdoor to your own account

Story time: I’m an idiot who managed to forget the password to both my Plex account (sign-in via email) as well as the associated email’s password. With no remaining avenue for recovery, I felt an existential dread knowing that I would one day have my existing credentials expired and have no more ability to log into and manage my account.

While I am aware that I could simply move my server to a new account by invalidating the server preferences.xml, I was unsure how that would affect the accounts I am currently sharing libraries with. I have been forced to re-share libraries in the past and it often clutters the UI of those who don’t fully understand Plex’s customization features (ex. my elderly parents).

As a basic security measure, Plex requires users to know their current password in order to change it. However, linking a Google/Facebook account does NOT require retyping your password. This allowed me to essentially create a backdoor into my own account via a new separate login/password pair. This seems like a potential point of failure for security, but in its current form it actually helped me re-access core functionality like authorizing new devices. I am writing this both as a possible security warning for the developers and as a PSA for anyone who may find themselves in a similar situation to me.

Well apparently Plex are actively looking at 2FA and the best way to implement it.
As for Google and Facebook linking. I do neither ever.
I was gonna state the obvious here regarding Facebook sign in but that’s another subject.

1 Like

Oh, the evil Brother and Sister. One watches your every move, the other can’t wait to sell you off.

I would never suggest using 3rd party sign in, get a password manager is far safer. Or Create a password protected file deep in your computer for a list of online accounts.

Last password is highly regarded.

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.