Plex confirms a security attack, although they ensure that all passwords were encrypted
The multimedia plex software platform has reported about a Security incident that would have compromised part of the user accounts information. If you are a user of this software, either self -lined or as a streaming service, this interests you. Although the company ensures that passwords were encrypted by a system of HASHING Sure, advise all users to modify their credentials as a precautionary measure.
Protected data, but with potential risks
In its statement, the company says the following:
“An unauthorized third party accessed a limited subset of customer data from one of our databases. While we quickly contained the incident, the information to which it was accessed included emails, user names, passwords secreted safely and authentication data.
All the passwords of accounts that could have been accessed were securely coded, according to the best practices, which means that a third cannot read them. As a precautionary measure, we recommend that you take some additional measures to protect your account (see the details below). Be sure that we do not store credit card data on our servers, so this information was not compromised in this incident. “
As you can see, Plex makes it clear that the exposed information is limited and that the protection systems applied to passwords hinder their deciphering. On paper, users should not worry, as long as what the platform affirms is true.
Anyway, in its writing the company has detailed what users should do based on how they log in:
- If you use password. Change your key visiting https://plex.tv/reset. During the process, mark the option to close session on all connected devices. This includes any Plex multimedia server you have, which guarantees that no one else can keep access with the old password.
- If you use a single login (SSO). Go to https://plex.tv/secury and select “Close session on all devices.” Then you must log in again regularly.
In addition, Plex advises some additional measures, such as enable authentication in two factors To add an extra security layer. It also indicates the importance of Do not reuse the same password in other services and review the recent activity of the account and distrust emails that request passwords or payment information.
The company has indicated that There is no evidence of unauthorized access to sensitive data such as payment or billing information. However, the scope of the attack is still under review and new security measures are not ruled out in the next few days.
