r/technology • u/lurker_bee • 12h ago
Security Plex warns users to patch security vulnerabilities immediately
https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/7
u/drawkbox 5h ago
The LastPass hack (one of the many) was through a Plex client hole on a devops dev machine that had the vault master password.
-14
u/peppruss 7h ago edited 6h ago
I’ve been really enjoying Jellyfin sandboxed after moving away from Plex. Made a vibecoded rasbpi touchscreen interface that scans, updates, reboots and is also available as a quick web page. As they say, “anything is possible at zombo com… welcome… to zombo com.”
5
-17
u/heroism777 7h ago
Honestly if there’s anything with security vulnerabilities it’s Jellyfin. It’s not like there’s a team of paid professionals patching it. It’s it all open source.
-4
u/peppruss 6h ago
This is the beauty of it though, if you bring any skill to the table at all it’s whatever you want.
-6
u/probablytom 5h ago
There are practical limits to that though, right? Because even if what you want is jellyfin but reliably secure, you'd have to be an outrageously talented dev working full-time to patch it. Past a certain point it can't really be "whatever you want" in a realistic sense.
I'm sure jellyfin is fantastic and I agree that the adaptability of an open-source system is a colossal strength in so many regards... but a paid team of professionals working constantly have a much better chance of making something secure. Matching that by "bringing skill to the table" simply underestimates the work required.
1
u/2044onRoute 25m ago
I envy the faith you have in a capitalistic company and their team of 'paid professionals'.
-8
53
u/ranhalt 11h ago
Anyone on auto update has had this for months.