Live data from Hacker News

Disney+ fans without answers after thousands hacked

bbc.com

41–50 of 88 posts

Re: Disney+ fans without answers after thousands hacked

#41

Well. There’s a reason why Netflix is successful. They spent a lot of money and time operating as a tech-heavy company before becoming a content-heavy company. Just as an example, their Open Connect appliances ( https://openconnect.netflix.com/en/ ) are an impressive piece of technology that probably needed years of research. Launching a streaming service sounds simple in the paper but there are hundreds of complexit…

Doesn’t Disney own Hulu? They shouldn’t be new to the streaming video world.

Re: Disney+ fans without answers after thousands hacked

#42

They can still torrent the content, which is what I'm doing after I paid for the first month of Disney+ and then found out their DRM disallowed Linux because of "security levels".

You really couldn't have predicted that that would be a possibly?

Re: Disney+ fans without answers after thousands hacked

#43
post #39
post #32

Earlier quoted context omitted.

You'll probably never be allowed to sign up for D+ again. I'd only use charge backs as a final resort if I can't contact the company and/or I never want to do business with them in my life.

Just use a different payment system next time.

Nah, just cancel quietly.

Re: Disney+ fans without answers after thousands hacked

#44

Earlier quoted context omitted.

You issued a charge back with your credit card company for that, right?

Credit chargebacks are a really great way to end up being banned from a lot of companies' businesses going forwards. It's a last resort, not a "I'm too lazy to ask for a refund" strategy. It sounds like Disney+ was accepting refunds for preorders up until the launch day. Whether or not they can refund after presumably may depend on whether or not they can tell you've watched some of the content.

Interesting, I chargebacked a stubhub ticket I never recieved after a really terrible flow to even figure out if I got the ticket (turns out they partnered with a third party and you needed to download potentially 2!!! apps to get a scannable ticket). I didn't bother with contacting support because of how terrible the experience was. I hope they ban me.

Re: Disney+ fans without answers after thousands hacked

#45
post #26

Earlier quoted context omitted.

No idea about Netflix, but for Amazon I bet there’s less account sharing than the other two - because it’s your actual Amazon account. My Netflix account is the only one that doesn’t have a very complex password manager password, because I share it with family. I won’t share my amazon account because I won’t give it that sort of password. I guess Disney+ is much closer to Netflix on that scale.

Netflix definitely has trouble with this because they too lack the whole "delete all sessions" capability, so it's next to impossible to recover an account that has been compromised. My partner went through this, and Netflix support told her to delete the account and make a new one (losing all our recommendations in the process). Why they can't be bothered to add a "log out all users" feature the way something like G…

You can log out of all accounts via the Netflix website. It does take up to 8 hours last time I used it.

Re: Disney+ fans without answers after thousands hacked

#46
post #17

Why are Disney+ customers referred to as “fans”?

Disney has a very active fandom and several amusement parks that try and elevate their work to cultural touchstones. It seems like a warranted language choice here. Just like how you might call Yankees ticket-holders 'fans' instead.

Re: Disney+ fans without answers after thousands hacked

#47
post #4

I am sure Netflix and amazon prime users also reuse their passwords, but I haven’t yet heard about users having the Disney+ issues with these accounts.

Even with identical security stance (which I doubt) across services I'd still expect this because A) pwnable accounts on existing services were most likely already pwned, whereas Disney+ has a mass onboarding of pwnable accounts, so it's Christmas for scrit kiddies and B) there's a ton of attention on Disney+ right now so there will be much more press scrutiny regardless of the true scale of the problem.

C) The early wave that seems to have been most targeted was early signups that included big sales on 2 and 3-year prepurchases. Risk/reward balance on stealing those accounts must have been hugely tempting.

Re: Disney+ fans without answers after thousands hacked

#48

Well. There’s a reason why Netflix is successful. They spent a lot of money and time operating as a tech-heavy company before becoming a content-heavy company. Just as an example, their Open Connect appliances ( https://openconnect.netflix.com/en/ ) are an impressive piece of technology that probably needed years of research. Launching a streaming service sounds simple in the paper but there are hundreds of complexit…

Doesn’t Disney own Hulu? They shouldn’t be new to the streaming video world.

But just as a controlling shareholder. I don't think they have any input or say on Hulu's operation besides the typical influence you can exert as a board member even when it's from a vote controlling position. I may be wrong but I doubt they can use Hulu's streaming technology or IP in general unless they license it from Hulu somehow. If Hulu was an actual Disney subsidiary it would be different. Although Hulu is controlled by Disney, Comcast still owns a third part of it.

Re: Disney+ fans without answers after thousands hacked

#49

Earlier quoted context omitted.

At this point if they're rolling out a massive service without strong authentication controls and 2FA then it is their fault.

The attack surface is pretty small, though, isn't it? The most sensitive thing there is probably your viewing history and contact info. The additional overhead of supporting MFA (not from a technical standpoint, but from a user education one) would be tremendous, especially considering the customer base.

Some Credit Card information will leak too. Like nearly everyone, Disney covers up everything but the last 4 digits and CC type, and is mostly clean to current standards, but those standards are flawed in that's still a lot of information if you are truly paranoid. (The last 4 digits are the most significant from an information entropy standpoint. The remaining digits follow typical patterns based on card type, which is often shown right next to those 4 digits, and sometimes {!} issuing bank. Apple's trying to change that with stronger reliance on more, harder to guess, easier to wipe, pseudo-random virtual numbers for cards, but not everyone yet has Apple Card and those kind of practices still seem like they are going to be much slower for older issuing banks to adopt.)
Post reply on HN