12 ms·
Disney+ fans without answers after thousands hacked
- devmunchies 7y agoyikes. It doesn't support the security feature of logging everyone out of the account? So if a someone gets access to your account they're in for good.
- silviogutierrez 7y agoSounds like JSON web tokens! Should have stuck to sessions if that's the case. Admittedly, the performance benefits of jwt are probably warranted here. But still, you either end up building an in-memory blacklist or a DB table thus negating most benefits.
- echelon 7y agoIt's not that hard to build a highly available active-active session service given time and engineering headcount. It's hard if you're trying to get out the door fast, though.
- silviogutierrez 7y agoYea I'm not saying it's impossible. But I'm saying it's probably easier to just make traditional cookies/sessions scale. I went through my shiny jwt phase. I'm happily back in session land though.
- tracker1 7y agoI often tend to just use relatively short lived tokens (12 hrs mostly), which avoids a lot of issues in practice. It depends on the use case. Depending on their DB systems and caching infrastructure, the JTI in as a key in a revocation database would work. It's not always worth implementing though.
- tedunangst 7y agoSounds like that's exactly what did happen, at least to some users. Someone got access and logged out the original owner. Which is why they're complaining.
- kilo_bravo_3 7y agoI don't know what answer they're due, except "This happened because you reused a password".
- hsailor 7y agoI am sure Netflix and amazon prime users also reuse their passwords, but I haven’t yet heard about users having the Disney+ issues with these accounts.
- ummonk 7y agoNetflix and amazon might check against leaked passwords, and / or require sms or email verification when an unusual login attempt is detected.
- mcintyre1994 7y agoNo idea about Netflix, but for Amazon I bet there’s less account sharing than the other two - because it’s your actual Amazon account. My Netflix account is the only one that doesn’t have a very complex password manager password, because I share it with family. I won’t share my amazon account because I won’t give it that sort of password. I guess Disney+ is much closer to Netflix on that scale.
- mikey_p 7y agoNetflix definitely has trouble with this because they too lack the whole "delete all sessions" capability, so it's next to impossible to recover an account that has been compromised. My partner went through this, and Netflix support told her to delete the account and make a new one (losing all our recommendations in the process). Why they can't be bothered to add a "log out all users" feature the way something like Github or even Plex offers is beyond me.
- J5892 7y agoNetflix does have that feature: https://www.netflix.com/ManageDevices https://www.netflix.com/ManageDevices
- MattSteelblade 7y agoConfirmed. I've used it
- magashna 7y agoIt would really make me laugh if Disney was at fault but it sounds like people with compromised credentials reusing those same creds.
- Bootwizard 7y agoHow do you know of your credentials are compromised?
- skyo 7y agoProbably the best way to check is https://haveibeenpwned.com/ https://haveibeenpwned.com/
- dagurp 7y agoOr https://monitor.firefox.com/ https://monitor.firefox.com/ (which is basically the same thing)
- dylan604 7y agoCheck out your Recently Viewed/Watched category. If things you haven't watched yourself start to appear there, then chances are...
- AWildC182 7y agoAt this point if they're rolling out a massive service without strong authentication controls and 2FA then it is their fault.
- organsnyder 7y agoThe attack surface is pretty small, though, isn't it? The most sensitive thing there is probably your viewing history and contact info. The additional overhead of supporting MFA (not from a technical standpoint, but from a user education one) would be tremendous, especially considering the customer base.
- rvz 7y agohttp://cryto.net/~joepie91/blog/2016/06/13/stop-using-jwt-for-sessions/ http://cryto.net/~joepie91/blog/2016/06/13/stop-using-jwt-fo...
- NiceGuy_Ty 7y agoAll of the pros of JWTs _do_ apply to Disney+
- TallGuyShort 7y agoThey can still torrent the content, which is what I'm doing after I paid for the first month of Disney+ and then found out their DRM disallowed Linux because of "security levels".
- markovbot 7y agoYou issued a charge back with your credit card company for that, right?
- pcr0 7y agoYou'll probably never be allowed to sign up for D+ again. I'd only use charge backs as a final resort if I can't contact the company and/or I never want to do business with them in my life.
- gsich 7y agoJust use a different payment system next time.
- WrtCdEvrydy 7y agoNah, just cancel quietly.
- cwkoss 7y agoDifferent card and different email
- ocdtrekkie 7y agoCredit chargebacks are a really great way to end up being banned from a lot of companies' businesses going forwards. It's a last resort, not a "I'm too lazy to ask for a refund" strategy. It sounds like Disney+ was accepting refunds for preorders up until the launch day. Whether or not they can refund after presumably may depend on whether or not they can tell you've watched some of the content.
- joshmn 7y agoLaughing at some of this reporting. > More than 4,000 customer accounts appeared in the search To clear this up: No, not true. The software in the screenshot called Open Bullet and it's basically a request builder for Selenium (ok it's more than that but you get the idea). You add in lists of usernames/passwords (from database dumps) and it runs your script. You have success/fail reporting, and that's where you get "Hits: 4" > Ads on the dark web for stolen Disney+ accounts That's a sellers page from shoppy.gg — not the dark web.
- rvz 7y agoWhile you are correct, the BBC are 'really trying' their best to explain this disaster to the average John and Jane. But again they are still in the middle-ages when it comes to mentioning the technical side of these 'attacks'. Says pretty much a lot about them when it comes to technology in general.
- joshmn 7y agoI understand that. I wish that they would at least correct the first photo of the combos. Saying that there are 4000 accounts when there are 4 is misleading. "A hacker checking the logins of 4,000 potential accounts" is better and more accurate subtext.
- AshwinDurairaj 7y agoI'm laughing too. Its all opportunistic as Disney+ is hot on the news right now. Wait till they find out that these tools are cracking Hulu, Reddit etc etc, probably also the BBCs own site. And I guarantee the net is more than 4000 for them.
- pcroh 7y agoWell... it's the BBC. What did you expect?
- tobr 7y agoWhy are Disney+ customers referred to as “fans”?
- geodel 7y agoI guess similar reason Restaurants' customers are referred to as guests.
- tobr 7y agoHuh, not really? A “fan” is an enthusiast or admirer. It implies a certain type of relationship to the thing you are a fan of. I don’t know that “guest” implies anything similar, it’s just a visitor.
- imgabe 7y agoGuest implies that you have been invited and expect to receive hospitality from your host. Visitor is just someone who showed up somewhere.
- fenwick67 7y agoDisney has a very active fandom and several amusement parks that try and elevate their work to cultural touchstones. It seems like a warranted language choice here. Just like how you might call Yankees ticket-holders 'fans' instead.
- UweSchmidt 7y agoStating the obvious: marketing tries to redefine language to influence customers. You can either shrug it off or actively fight it. Like: If you go along with calling sandwiches "subs" you might associate this particular food with Subway and may consider competing food products less. Off the tangent: Companies pay to rename sports arenas. They're not paying you, so you could just say "we're going to $teamname stadium" instead of $companyname stadium".
- bobbonew 7y agoOP you can do better with that title. We all know it wasn’t “hacked”.
- mcbits 7y agoDisney apparently wasn't hacked, but the users were. Password guessed/stolen = account hacked in common parlance.
- buzzerbetrayed 7y agoIn common parlance, yes. However, I would argue it doesn’t mean that on hacker news.
- mcbits 7y agoThe BBC doesn't write for Hacker News. And I would argue that just about everyone here understands what "hacked" means in this context anyway.
- whoisjuan 7y agoWell. There’s a reason why Netflix is successful. They spent a lot of money and time operating as a tech-heavy company before becoming a content-heavy company. Just as an example, their Open Connect appliances (https://openconnect.netflix.com/en/ https://openconnect.netflix.com/en/) are an impressive piece of technology that probably needed years of research. Launching a streaming service sounds simple in the paper but there are hundreds of complexities under the hood that ensure availability, speed, security, and reliability. If my Netflix experience wasn't as trivially smooth as it is (from a UX point of view) I wouldn’t pay for it.
- freehunter 7y agoDoesn’t Disney own Hulu? They shouldn’t be new to the streaming video world.
- whoisjuan 7y agoBut just as a controlling shareholder. I don't think they have any input or say on Hulu's operation besides the typical influence you can exert as a board member even when it's from a vote controlling position. I may be wrong but I doubt they can use Hulu's streaming technology or IP in general unless they license it from Hulu somehow. If Hulu was an actual Disney subsidiary it would be different. Although Hulu is controlled by Disney, Comcast still owns a third part of it.
- arjunbajaj 7y agoNot quite. Since March 2019, Disney fully controls Hulu [1]. In 2024, Comcast can sell its remaining stake to Disney. [1]: https://variety.com/2019/digital/news/disney-full-control-hulu-comcast-deal-1203214338/ https://variety.com/2019/digital/news/disney-full-control-hu...
- xnyan 7y agoDisney is the the biggest kid at the pool in media and their is really nowhere in the entire entertainment industry where their influence can't be felt. Disney happens to 100% own hulu now, but even before that I don' see how you can look at their operations and not conclude they were in control.
- derrikcurran 7y agoI recently had some suspicious activity on my HBO and Hulu accounts. I checked my email address on haveibeenpwned.com and found some pastebin links at the bottom from August 2019. Sure enough, my email and password for HBO were there in plain text along with many others. The format was like this: ================ notarealperson@email.com:password123 Subscription: Your HBO NOW subscription is billed through [HBO] Expiry Date: September 20, 2019 21 Days Remaining I haven't figured out the source yet. It's possible that someone just took these recent dumps and ran them against Disney+
- aaron695 7y ago> Disney+ fans without answers after thousands hacked A google search of one of the email:password came up with a Soundcloud 2018 email:password dump. Seems like a everyday dump of reused passwords. That happens everyday for all the services. Just seems like everyone wants to take down Disney. Like OMG that had an issue on the first day streaming! I also want to see them fail, but for no good reason I just enjoy seeing people fail, I guess I'm not alone.
- calvinbhai 7y agoI thought Disney+ rollout would have no hiccups, because I thought Hotstar (I think it is mostly India based content) owned by Disney did quite well during the cricket world cup, in terms of live streaming (which I thought is more complex than streaming movies). My respect for Netflix goes up each time a new streaming service has a hiccup.