Roku says hackers gained access to 576k accounts in latest data-breach incident
wsj.com
wsj.com
This will keep continuing until there are consequences for executives and companies - meaning fines, including retroactive ones, and jail time. For now, we need to keep spreading awareness and then pressure lawmakers to do something about it. But techies can just stop paying these companies any more money too.
and "low damages" (to/for whom?) don't typically inform the feasibility of a class action. it's generally presumable that individual damages are insufficient to justify most individual action—hence class formation/certification. but the 'profitability' of attorneys' fees awards certainly do.
Roku though? The data stored in a Roku account is not totally insensitive, but it's not seriously sensitive. A lax security posture is justifiable. I would personally not care a bit if somebody infiltrated my Roku account and I don't believe most people would. The accounts mostly exist for Roku's purposes more than their customers.
My only concern might be people using my account to authorise charges I did not approve to rent movies, but I don't see why anybody would actually want to do that, since it's a lot more cumbersome than piracy.
Use a password manager people.
Anyone who has supported digital devices for friends and family (especially elderly ones) knows it is in fact not easy.
These accounts exist for the commercial benefit of companies. They could tie authorization to the hardware if they wanted to, like it used to be before the internet, but they don't. The idea that consumers need to do data and security management for the commercial benefit of corporations has gotten absurd. We're doing their IT for them, and still getting hacked even when we do it right. Remember Equifax? Pepperidge farms remembers Equifax.
“Characters should be adjacent on that particular gridded qwerty keyboard that TVs tend to use or two-off in a single directions. Double characters are also ok. Long strings of upper or lower case letters.”
I guess the number of possible passwords is something like 26*(9^(n-1)), ignoring special characters and (rare) case changes. Also ignoring the edges of the keyboard, which probably really messes my path up because it isn’t very tall.
That said, it's possible to come up with an easy to remember scheme and is unique (like {ServiceName}@{houseNumber} or the like).
In that case, we generate passwords and try them against every (hash, salt) pair in the database. We can usually crack 60 percent of a database this way, and more if we use AI driven cracking (PassGAN, 2017).
It makes sense to try variants of "netflix{birthday}" early on, since that uncovers a significant portion of the database. Your mom would have just been unlucky to be part of that low-hanging cohort.
Long winded way of saying that other devices do it as well
This lack of focus on Casting is certainly causing it feel like it is becoming obsolete. For instance many Android apps now have bugs when it comes to casting (stuttering video or the cast button only showing up when restarting the app).
If you're already buying a smart tv device and putting it on your network, downloading an app that gives you better control over it doesn't seem like a step too far. Especially with phone permissions being more finely grained than whatever the box itself is doing.
From a reputational perspective I see people reacting thinking their data has been stolen, whilst not realising that this was due to credential stuffing.
If I was Roku I wouldn't have said the words "Data Breach" at all, I would just email customers recommending them that they change their password.
We need legislation to force businesses to do security audits of their products if they collect PII, and fix the bugs in a reasonable time frame. If they don't they need major penalties that are recurring and increase over time. This way a whistleblower can report their company if they fail to properly perform an audit or fail to fix the bugs.
This may seem toothless, but avoiding shame and fines is a big motivator for companies in industries where data privacy regulation exists. If we can force them to start investing in security, that reduces the likelihood of security holes sticking around forever, leading to breach.