TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Roku data breach: Over 15k accounts affected

113 pointsby willyg123about 1 year ago

19 comments

breviteaabout 1 year ago
Sure wish CISA and SEC would effectively monitor and fine companies that suffer data breaches. After all, we're not being paid for that data, yet we remain the victim of their actions.
评论 #39674231 未加载
评论 #39674497 未加载
Brybryabout 1 year ago
Is this not just credential stuffing?<p>The article cites these two sources[1][2] which say<p>&gt; Unauthorized individuals using account credentials believed to have been obtained from third-party source(s) were used to access individual customer accounts<p>[1] <a href="https:&#x2F;&#x2F;apps.web.maine.gov&#x2F;online&#x2F;aeviewer&#x2F;ME&#x2F;40&#x2F;e9cc298b-379b-47ba-a10d-e2263963b574.shtml" rel="nofollow">https:&#x2F;&#x2F;apps.web.maine.gov&#x2F;online&#x2F;aeviewer&#x2F;ME&#x2F;40&#x2F;e9cc298b-37...</a><p>[2] <a href="https:&#x2F;&#x2F;oag.ca.gov&#x2F;system&#x2F;files&#x2F;Template%20Notification%203-8-2024.pdf" rel="nofollow">https:&#x2F;&#x2F;oag.ca.gov&#x2F;system&#x2F;files&#x2F;Template%20Notification%203-...</a>
hentrepabout 1 year ago
&gt; potentially affecting 15,363 individuals in the United States, including 76 in the state of Maine.<p>Odd that Roku singles out the 0.5% of users affected within the state of Maine. Must be related to some sort of Maine data breach law? I didn&#x27;t dig too deeply, but not seeing anything explicitly called out in their statutes [0].<p>[0] <a href="https:&#x2F;&#x2F;legislature.maine.gov&#x2F;legis&#x2F;statutes&#x2F;10&#x2F;title10sec1348.html" rel="nofollow">https:&#x2F;&#x2F;legislature.maine.gov&#x2F;legis&#x2F;statutes&#x2F;10&#x2F;title10sec13...</a>
NoPicklezabout 1 year ago
This just looks more like Roku had identified significant amounts of credential stuffing across customer accounts. As opposed to someone breaking into the back end of Roku and leaking customer account details.<p>It could also be targeted credential stuffing given recent events. An interesting tactic to create problems for a company.<p>I&#x27;m not saying Roku is a good company, but this isn&#x27;t really a data breach but poor credential management by customers.
cadence-about 1 year ago
Looks like Ars Technica called it:<p><i>Roku is also taking heat for using forced arbitration at all, which some argue can have one-sided benefits. In a similar move in December, for example, 23andMe said users had 30 days to opt out of its new dispute resolution terms, which included mass arbitration rules (the genetics firm let customers opt out via email, though). The changes came after 23andMe user data was stolen in a cyberattack. Forced arbitration clauses are frequently used by large companies to avoid being sued by fed-up customers.</i><p><a href="https:&#x2F;&#x2F;arstechnica.com&#x2F;gadgets&#x2F;2024&#x2F;03&#x2F;disgraceful-messy-tos-update-allegedly-locks-roku-devices-until-users-give-in&#x2F;" rel="nofollow">https:&#x2F;&#x2F;arstechnica.com&#x2F;gadgets&#x2F;2024&#x2F;03&#x2F;disgraceful-messy-to...</a>
评论 #39674550 未加载
评论 #39674474 未加载
iAkashPaulabout 1 year ago
That recent push by Roku for accepting updated EULA around arbitration makes quite a lot more sense
enragedcactiabout 1 year ago
For those who don&#x27;t know, just a week or so ago Roku amended the arbitration clause of their terms of service and soft-bricked every Roku in the US until you Agreed to the new terms. This even extended to TVs from other brands with Roku software, making the TV non-functional even as a dumb display since the Roku software controls input selection AND would ignore any HDMI-CEC commands. I guess we know why now.<p>There is a 30-day window after agreeing where you can mail them a letter opting out of the new arbitration agreement.<p><a href="https:&#x2F;&#x2F;cordcuttersnews.com&#x2F;roku-issues-a-mandatory-terms-of-service-update-that-you-must-agree-to-or-you-cant-use-your-roku&#x2F;" rel="nofollow">https:&#x2F;&#x2F;cordcuttersnews.com&#x2F;roku-issues-a-mandatory-terms-of...</a>
评论 #39674315 未加载
评论 #39675755 未加载
评论 #39676395 未加载
评论 #39674293 未加载
评论 #39674383 未加载
评论 #39674330 未加载
999900000999about 1 year ago
This is absolutely glorious.<p>Days after forcing it&#x27;s users into mandatory arbitrations this comes out.<p>Would be awesome if holding someone&#x27;s TV hostage until they agree to not sue you was illegal.
评论 #39674720 未加载
评论 #39675201 未加载
CedarMadnessabout 1 year ago
This breach is suspiciously close to their new forced arbitration in their terms of service.
评论 #39674295 未加载
评论 #39674401 未加载
mtlynchabout 1 year ago
Related: Ask HN: Fighting back against Roku&#x27;s forced arbitration?<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=39503941">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=39503941</a> (2024-02-25)
评论 #39674430 未加载
评论 #39674380 未加载
lagniappeabout 1 year ago
Changing terms after the fact does not change the terms that were being operated under during the time of the breach.
评论 #39674342 未加载
评论 #39674388 未加载
评论 #39674283 未加载
whynotmaybeabout 1 year ago
One after the other, can we all assume now that a data breach for any company is not an &quot;if&quot; anymore, just a &quot;when&quot;?
评论 #39674805 未加载
评论 #39674395 未加载
jkic47about 1 year ago
Could that be a reason they amended their terms and conditions in such a draconian way?
评论 #39674435 未加载
djinnandtonicabout 1 year ago
Why does this notification say passwords were compromised and not password hashes? Certainly Roku engineers were better than that?
评论 #39674526 未加载
评论 #39674432 未加载
grimgrinabout 1 year ago
&gt; As a result, unauthorized actors were able to obtain login information from third-party sources and then use it to access certain individual Roku accounts. After gaining access, they then changed the Roku login information for the affected individual Roku accounts, and, in a limited number of cases, attempted to purchase streaming subscriptions.<p>how limited and what subs
评论 #39674528 未加载
bee_riderabout 1 year ago
So, I guess this must be why they changed their TOS.
评论 #39674454 未加载
matrix12about 1 year ago
It sure would be nice to know what was exposed in the hack. Given they are an advertisement company.
评论 #39674404 未加载
评论 #39674531 未加载
BHSPitMonkeyabout 1 year ago
This is your regular reminder to audit your password manager for accounts you no longer need, and then go and have those accounts deleted.<p>Of course you can&#x27;t guarantee that your data will actually be purged, or that it hasn&#x27;t already been compromised from these places - but less exposure is better than more exposure, right?
评论 #39674397 未加载
tiahuraabout 1 year ago
I&#x27;m sorry, after 20 years of data breach alarmism, and resulting de minimus consequences, isn&#x27;t time for some of this to get a &quot;who cares?&quot;
评论 #39674423 未加载
评论 #39674420 未加载