Live data from Hacker News

Disney+ fans without answers after thousands hacked

bbc.com

21–30 of 88 posts

Re: Disney+ fans without answers after thousands hacked

#21
Well. There’s a reason why Netflix is successful. They spent a lot of money and time operating as a tech-heavy company before becoming a content-heavy company. Just as an example, their Open Connect appliances (https://openconnect.netflix.com/en/) are an impressive piece of technology that probably needed years of research.

Launching a streaming service sounds simple in the paper but there are hundreds of complexities under the hood that ensure availability, speed, security, and reliability.

If my Netflix experience wasn't as trivially smooth as it is (from a UX point of view) I wouldn’t pay for it.

Re: Disney+ fans without answers after thousands hacked

#22
post #4

I am sure Netflix and amazon prime users also reuse their passwords, but I haven’t yet heard about users having the Disney+ issues with these accounts.

Big launch -> lots of problems at once -> newsworthy. The rest have all have the same problem, just not all at once so no one cares. (And also it's easier for support to handle when not in a big lump, and also they're not brand new to the job.)

Re: Disney+ fans without answers after thousands hacked

#23
post #4

I am sure Netflix and amazon prime users also reuse their passwords, but I haven’t yet heard about users having the Disney+ issues with these accounts.

Even with identical security stance (which I doubt) across services I'd still expect this because A) pwnable accounts on existing services were most likely already pwned, whereas Disney+ has a mass onboarding of pwnable accounts, so it's Christmas for scrit kiddies and B) there's a ton of attention on Disney+ right now so there will be much more press scrutiny regardless of the true scale of the problem.

Re: Disney+ fans without answers after thousands hacked

#24

They can still torrent the content, which is what I'm doing after I paid for the first month of Disney+ and then found out their DRM disallowed Linux because of "security levels".

You issued a charge back with your credit card company for that, right?

Re: Disney+ fans without answers after thousands hacked

#25
post #16

Laughing at some of this reporting. > More than 4,000 customer accounts appeared in the search To clear this up: No, not true. The software in the screenshot called Open Bullet and it's basically a request builder for Selenium (ok it's more than that but you get the idea). You add in lists of usernames/passwords (from database dumps) and it runs your script. You have success/fail reporting, and that's where you get "…

While you are correct, the BBC are 'really trying' their best to explain this disaster to the average John and Jane. But again they are still in the middle-ages when it comes to mentioning the technical side of these 'attacks'.

Says pretty much a lot about them when it comes to technology in general.

Re: Disney+ fans without answers after thousands hacked

#26
post #4

I am sure Netflix and amazon prime users also reuse their passwords, but I haven’t yet heard about users having the Disney+ issues with these accounts.

No idea about Netflix, but for Amazon I bet there’s less account sharing than the other two - because it’s your actual Amazon account. My Netflix account is the only one that doesn’t have a very complex password manager password, because I share it with family. I won’t share my amazon account because I won’t give it that sort of password. I guess Disney+ is much closer to Netflix on that scale.

Netflix definitely has trouble with this because they too lack the whole "delete all sessions" capability, so it's next to impossible to recover an account that has been compromised. My partner went through this, and Netflix support told her to delete the account and make a new one (losing all our recommendations in the process). Why they can't be bothered to add a "log out all users" feature the way something like Github or even Plex offers is beyond me.

Re: Disney+ fans without answers after thousands hacked

#27
post #4

I am sure Netflix and amazon prime users also reuse their passwords, but I haven’t yet heard about users having the Disney+ issues with these accounts.

I used to use the same password for Netflix and several other websites. I definitely had issues with people using my Netflix account that had somehow gotten the password. I'm sure that happens regularly.

Re: Disney+ fans without answers after thousands hacked

#28
post #25
post #16

Laughing at some of this reporting. > More than 4,000 customer accounts appeared in the search To clear this up: No, not true. The software in the screenshot called Open Bullet and it's basically a request builder for Selenium (ok it's more than that but you get the idea). You add in lists of usernames/passwords (from database dumps) and it runs your script. You have success/fail reporting, and that's where you get "…

While you are correct, the BBC are 'really trying' their best to explain this disaster to the average John and Jane. But again they are still in the middle-ages when it comes to mentioning the technical side of these 'attacks'. Says pretty much a lot about them when it comes to technology in general.

I understand that. I wish that they would at least correct the first photo of the combos. Saying that there are 4000 accounts when there are 4 is misleading. "A hacker checking the logins of 4,000 potential accounts" is better and more accurate subtext.

Re: Disney+ fans without answers after thousands hacked

#29
post #5

It would really make me laugh if Disney was at fault but it sounds like people with compromised credentials reusing those same creds.

At this point if they're rolling out a massive service without strong authentication controls and 2FA then it is their fault.

The attack surface is pretty small, though, isn't it? The most sensitive thing there is probably your viewing history and contact info. The additional overhead of supporting MFA (not from a technical standpoint, but from a user education one) would be tremendous, especially considering the customer base.
Post reply on HN