6 ms·
Disney+ Might Have a Notable Hacker Problem
- deleted 7y ago[deleted]
- MaupitiBlue 7y agoWith 10m moms and dads signing up, I'm going to guess this is largely due to password reuse from prior hacks. Christmas123.
- amflare 7y agoYeah, this is my hypothesis. It is just a brute force attack using old email and passwords from previous hacks on other services.
- Matsta 7y agoBingo. People using the same login on multiple sites. The sellers get Massive email: password lists which are known combo lists. These are usually from hacked sites that have been SQL injected. People probably all have giant lists of Netflix, Hulu Etc. accounts and then just recheck them on Disney+ Then they'll use a checker app which just mass checks the sites. I imagine Disney don't have a catchpa setup or requiring it after a large amount of failed logins. There's no point IP limiting logins as most guys will be using massive botnet proxies services that give you a zillion IP's.
- smacktoward 7y agoIt does seem like a particularly soft target in that regard. We really need a 2FA solution that's friendly enough for normal people to use. Like, yesterday.
- WorldMaker 7y agoWe really need even just a 1FA solution that's friendly enough for normal people to use securely. Passwords clearly aren't secure for normal people, and we should stop pretending like they ever were.
- thu2111 7y agoIt exists already. Disney could just federate their logins to Google, for example, and all these problems are solved for them for free. Note that both Google and Facebook have extensive infrastructures in place to detect and block password reuse based account hacking. Knowing the password is not enough to always log in to a Google account. In some cases the login process will ask you questions about your account or ask you to receive a code on your phone to verify authenticity. It's a bit like a heuristically triggered and thus easier form of 2FA. Disney's problem here is that they have tried to make their own global federated account system but without much expertise in doing so. Tech firms have successfully fought off and blocked these attacks years ago.
- MaupitiBlue 7y agoAlso more likely to be a leak from some account harvester / malware / ... rather than D+ getting hacked. Shame on D+ for not screening passwords against known hacked u/p.
- mjevans 7y agoThe email change is particularly disturbing. A good security design would be to send the old email a notice of change request and give them a link that can always be used to undo that change (which might require the at the time older password as well).
- deckar01 7y agoMost services don't do that. I have had my personal email account DDoSed before and requiring access to that inbox to change my email address would have been impossible for over a month.
- Starkus 7y agoDoes anyone else still torrent? I rarely watch a tv show or a movie, but when I do I just torrent it. I've been doing this since Limewire (which was a lot of really shitty porn at the time). Showed my boys Princess Mononoke the other day - will show them the Mandalorian tonight, a buddy told me its pretty good
- vinylkey 7y agoI'm sure some people do. I prefer to pay for things though.
- 8fingerlouie 7y agoIt’s not a matter of paying for stuff, at least not in Europe. I have 3 different streaming subscriptions (still cheaper than 8 channels of flow tv with its 50% commercials), and I absolutely hate watching a tv show, only to find out the European version of the streaming service doesn’t have the last 4 seasons yet, despite the show being over and the finale having “aired” in the US. In cases like that I turn to torrents and download whatever seasons I’m missing, watch them and delete them again. I still keep my streaming subscriptions though. It has gotten better, and the problem is mostly confined to cross studio/service shows, or services not available in Europe. HBO Nordic hasn’t even announced an air date for Mr. Robot season 4 yet, which I guess is great as I can only dodge spoilers for so long, so when it eventually hits I’ll know the ending. Even if the show was available on a European streaming service, I’d probably stream it anyway. There’s a limit to how many streaming services I care to have, and torrenting is so much easier than trying to navigate the dark patterns most streaming services put around their unsubscribe pages. I’m also too lazy to subscribe/unsubscribe multiple times per year to multiple services. Perhaps a “pay per view” model that bills you X per show watched, up to a maximum equal to the monthly subscription fee. That way I could have multiple subscriptions and only pay subscription fees to the services I actually use, and once I stopped watching them I’d automatically be unsubscribed. Of course that will never happen while there are a million services.
- bronco21016 7y agoI think many people, even if they pay for the services, still torrent. It’s so much more convenient to have everything in Plex where it plays across all devices rather than chase down which app/device combo has the content you’re looking for.
- dhagz 7y agoExtra fun tip I'm sort of nervous putting out there just because it's a potential attack vector: if you used the same email address as your existing MyDisneyExperience account, guess what? The password you set while registering for Disney+ is now the password for your MDE account - they were "merged" without notification (that I saw). So not only is your Disney+ account compromised, potentially the account you use to book vacations is as well. EDIT: I have "merged" in quotes because I am not sure if changing your D+ email changes it for your MDE account as well, or vice-versa.
- gamblor956 7y agoBased on the description of the hack, if your Disney+ account was "hacked" then your MDE account details were already on the black market. TLDR: Disney+ wasn't actually hacked. But many people reused credentials from other sites that were already in account leaks.
- WorldMaker 7y ago> I have "merged" in quotes because I am not sure if changing your D+ email changes it for your MDE account as well, or vice-versa. If the merger of Disney Movie Rewards and Disney accounts, or the merger of Marvel and Disney accounts are any indication to go by, it's likely forever to always be a mess. Disney's goal for "one account system" has just been one wild ride after another. Given how many of their websites still in 2019 redirect to or through *.go.com for reasons unknown, I have to imagine their web tech stack is a fascinating archeology dive under the hood.