Earlier quoted context omitted.
In my opponion, all of those cases very well justify a manual check, or some sort of extended identification before the user is let in. It indicates a deeper cultural issue of "convenience/profit over security" if those are sufficient reasons to not check the sub parameter.
> all of those cases very well justify a manual check, or some sort of extended identification before the user is let in. Just curious, what would that check look like that's not open to the same vuln?
The person paying for your subscription must contact us to verify your account is still legit."