# Security Breach

**URL:** https://forums.plex.tv/t/security-breach/805763
**Category:** General Discussions
**Created:** [August 24, 2022, 6:59am UTC](https://forums.plex.tv/t/security-breach/805763 "2022-08-24T06:59:39Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![LEdgeley](https://avatars.discourse-cdn.com/v4/letter/l/90db22/32.png) [@LEdgeley](https://forums.plex.tv/u/LEdgeley)
#### Post date: [August 24, 2022, 6:59am UTC](https://forums.plex.tv/t/security-breach/805763/1 "2022-08-24T06:59:39Z")

</div>

There is a concerning lack of clarity in the email Plex sent out today about yesterday’s security breach. The email claims:

> a third-party was able to access a limited subset of data that includes […] **encrypted passwords**. Even though all account passwords that could have been accessed were **hashed** and secured in accordance with best practices[…]

(my bold)

These two sentences contradict each other. If Plex stored encrypted passwords - and that’s not best practice - they can be decrypted by anyone with the key. If they were hashed (and salted. Please say they were salted) they cannot. So which is it - encrypted or hashed?

It’s worrying that Plex can’t even get their security disclosures right; makes you wonder what else is broken about their security practices.

---

<div class="post-metadata">

### Author: ![jajwoodward](https://avatars.discourse-cdn.com/v4/letter/j/51bf81/32.png) [@jajwoodward](https://forums.plex.tv/u/jajwoodward)
#### Post date: [August 24, 2022, 7:33am UTC](https://forums.plex.tv/t/security-breach/805763/2 "2022-08-24T07:33:18Z")

</div>

I’m still trying to confirm if this applies to Plex thats accessed with a third party authenticator such as Google or Apple, that information is completely missing from the email and as far as I can tell has yet to be answered by the Plex powers that be.

---

<div class="post-metadata">

### Author: ![stix](https://avatars.discourse-cdn.com/v4/letter/s/edb3f5/32.png) [@stix](https://forums.plex.tv/u/stix)
#### Post date: [August 24, 2022, 8:20am UTC](https://forums.plex.tv/t/security-breach/805763/3 "2022-08-24T08:20:39Z")

</div>

Plex employees are more active on Reddit than here…

![image](https://global.discourse-cdn.com/plex/original/4X/8/d/b/8dbf582db2670833bc85141c62565404453767a4.png)

Source: [https://www.reddit.com/r/PleX/comments/wwb8uy/plex\_breached\_were\_passwords\_encrypted\_or\_hashed/](https://www.reddit.com/r/PleX/comments/wwb8uy/plex_breached_were_passwords_encrypted_or_hashed/)

---

<div class="post-metadata">

### Author: ![jssadmin](https://avatars.discourse-cdn.com/v4/letter/j/c77e96/32.png) [@jssadmin](https://forums.plex.tv/u/jssadmin)
#### Post date: [August 24, 2022, 8:27am UTC](https://forums.plex.tv/t/security-breach/805763/4 "2022-08-24T08:27:39Z")

</div>

Would be nice to get better information. as i agree with OP, I raised an eyebrow reading the email too, which is it encrypted or hashed out, did the breach also result in a leak of any keys that can reverse the encryption. This brings into question how and why we need to Authenticate to their service first before we are authenticated on a service that is running on our hardware… if it is for licensing there are better ways of doing that these days anyways.

---

<div class="post-metadata">

### Author: ![dsk2k](https://avatars.discourse-cdn.com/v4/letter/d/c37758/32.png) [@dsk2k](https://forums.plex.tv/u/dsk2k)
#### Post date: [August 24, 2022, 10:04am UTC](https://forums.plex.tv/t/security-breach/805763/5 "2022-08-24T10:04:11Z")

</div>

I agree it’s dumb this info is missing from the email, but if you authenticate via third party Plex never has your actual login details so you shouldn’t worry, this works via OAuth which is def secure.

---

<div class="post-metadata">

### Author: ![Divideby0](https://avatars.discourse-cdn.com/v4/letter/d/74df32/32.png) [@Divideby0](https://forums.plex.tv/u/Divideby0)
#### Post date: [August 24, 2022, 2:51pm UTC](https://forums.plex.tv/t/security-breach/805763/6 "2022-08-24T14:51:24Z")

</div>

I think they used the word “encrypted” because the general public just hears that and knows “secure”. I’m taking a class right now in encryption, so I’m understanding the different kinds of encryption, and now I appreciate that when they say hash, that is what they really use. (A definite +1 on hoping they salted them too)

Near as I hear about google auth, is that your account still HAS a regular account password to log in. So authenticating using google allows you to login without using the regular password. This means your account is still possibly compromised like everyone else, but your google info is 100% secure (unless you made the common mistake of using the same email/password combo for google as you did for the base Plex account.)

---

<div class="post-metadata">

### Author: ![system](https://global.discourse-cdn.com/plex/original/3X/2/a/2acb9765406f63293d357b4ec509ec39aa28f2ad.png) [@system](https://forums.plex.tv/u/system)
#### Post date: [November 22, 2022, 2:52pm UTC](https://forums.plex.tv/t/security-breach/805763/7 "2022-11-22T14:52:18Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
