this post was submitted on 12 Apr 2024
375 points (98.0% liked)

Technology

59708 readers
1855 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
top 44 comments
sorted by: hot top controversial new old
[–] [email protected] 122 points 7 months ago* (last edited 7 months ago) (1 children)

Can't wait till we find out that the arbitration agreement they forced on people was penned up shortly after they discovered the breach.

[–] [email protected] 74 points 7 months ago (3 children)

I think its already been shown that it was penned up shortly after they discovered the last breach.

[–] [email protected] 16 points 7 months ago (1 children)

insert shocked.gif here.

Fuck these companies. They all need to rot.

[–] [email protected] 1 points 7 months ago

Seriously; anyone not pirating deserved this. Maybe they'll learn better.

[–] [email protected] 10 points 7 months ago (1 children)

So instead of giving people notice so they can change their information they decide to sit on it until they cover their asses. Typical.

[–] [email protected] 4 points 7 months ago

The only way yo be safe is to pirate.

Anything else puts you at unnecessary risk.

[–] [email protected] 6 points 7 months ago

Never buying a Roku product ever again. Their TVs used to be a good deal but I’ll play a premium for something else next time.

[–] [email protected] 73 points 7 months ago (5 children)

Life is so much better after I gave up on these atrocious media boxes and TV operating systems and just use a small computer connected to the TV.

I control the interface, I control the connection, it works perfectly. Steam Link for games, Jellyfin for media - always working, never showing ads, never bothering me with accounts or updates.

[–] [email protected] 6 points 7 months ago (1 children)

I've been looking to do something like that.

I have a NAS running my JellyFin server in a container, i'd like to have the box/pc connected to my tv running something open source with the respective clients for my streaming services.

Kodi seems like it's a hassle to get streaming apps working seamlessly.

[–] [email protected] -2 points 7 months ago

Streaming apps

You people never learn, do you? If youre not pirating, you're at risk.

[–] [email protected] 5 points 7 months ago

I'm about to make my own android tv box with a raspberry Pi 5

Tried to use it straight with Linux as an OS but emby (paid jellyfish) didn't quite work well enough

[–] [email protected] 2 points 7 months ago (1 children)

Do you use your phone as a remote for it, or how do you navigate its interface?

[–] [email protected] 6 points 7 months ago (1 children)

I have a little cheapo Chinese Bluetooth keyboard thingy. It's very small, with a keyboard and trackpad. I also use my Xbox controller, which works great with Steam's UI.

[–] [email protected] 3 points 7 months ago (1 children)

Thanks! I always wonder how people handle navigation with setups like you described.

[–] [email protected] 3 points 7 months ago

Here's what I use but for the love of God do not pay 21 USD for this thing. Not sure why prices are bizarre in the US, but here in Brazil I paid what would convert to around 8 USD for it.

[–] [email protected] 2 points 7 months ago (2 children)

I feel like Jellyfin is a better solution than something like Plex, but I still feel like there is a trade off. I’m not dealing with ads, accounts, and content appearing / disappearing. But I was the TV and media library’s sys admin in the house, and that came with a different set of inconveniences.

[–] [email protected] 4 points 7 months ago

Tbh Kodi is just kinda a hassle in general. I much prefer Jellyfin and will probably ditch Kodi in favor of it in the near future.

[–] [email protected] 2 points 7 months ago (1 children)

That's absolutely correct, and something to keep in mind in case you're already stressed out with work or lacking free time.

Nowadays, after the initial setup, tools like Sonarr rarely give me trouble - but once I a while I'll have to sit down and resolve a conflict with file naming, for instance. Or when series have weird releases like animes breaking naming conventions for seasons.

[–] [email protected] 1 points 7 months ago

That's absolutely correct, and something to keep in mind in case you're already stressed out with work or lacking free time

Exactly. I’m exchanging some amount of money and time in order to watch stuff on my TV and phone. These days I’m exchanging a bit more money because I have less time.

[–] [email protected] 2 points 7 months ago (1 children)

Is there a guide that you used for setting up?

[–] [email protected] 8 points 7 months ago* (last edited 7 months ago) (1 children)

I didn't follow a guide, but there are many good ones online.

For games, really just install Steam on your main computer and the TV client, make sure Remote Play is configured to use the most out of your connection and set to the desired resolution. This is about it.

For torrents, you want a downloading client (I use qBittorrent), software that will automatically download movies and TV shows based on what you want (Sonarr, Radarr, all the *Arr stuff) and some server that will store the media and organize it in a "Netflix-like" easy to use interface, for that I use Jellyfin on my main PC.

So in short, for games, I open Steam Big Picture, select the game, I'm playing. For media, my PC downloads everything I want at night and during the day it's all there with subtitles, episodes, descriptions, etc, ready to play by opening up Jellyfin. It's mostly hands off, but the initial setup can be a bit painful if you've never used these tools before, specially dealing with the *Arr setup.

[–] [email protected] 2 points 7 months ago
[–] [email protected] 45 points 7 months ago (1 children)

Hey, at least their research is focusing on serving you ads through HDMI instead of security, so even if you're not using the Roku, you can still get their ads over HDMI.

[–] sugar_in_your_tea 2 points 7 months ago

You don't need security if you're a virus...

[–] TalesOfTrees 35 points 7 months ago (3 children)

I'm thankful Roku has had data breaches. Mostly because I have a Roku TV that was somehow compromised and now, even after a couple of years and several full factory resets, whoever used my throwaway account signed up for all the streaming services at the highest tier. Hard to be mad when I havent had to pay for anything.

And no, before anyone says anything, it's not putting my home network at risk, as it's just the Roku account that's compromised. Nothing tied to me personally, not even a card/address on the account, so I just chalk it up to "as long as it keeps working, Im not worrying about it".

[–] [email protected] 15 points 7 months ago (1 children)

Free stuff is great and all, but I imagine they’re using a stolen CC to pay for those subscriptions and they’re exploiting someone who’s not great at paying attention to their credit card bill.

You may want to report it so that someone isn’t getting fucked over.

[–] [email protected] 13 points 7 months ago (1 children)

Do not report it, Roku won't investigate financial fraud, but they will kick you out.

[–] [email protected] 2 points 7 months ago (1 children)

They will boot your account if you contact CS and say “my account has been compromised?”

[–] [email protected] 3 points 7 months ago (1 children)

At worst, they might cancel the subscriptions. I imagine trying to give the money back (get the charges reversed) is the labor intensive part.

[–] [email protected] 2 points 7 months ago

Exactly. Having been on the CS side of the house for stuff like this, I can’t imagine they would penalize the customer for coming forward. Customer service ain’t got time for that. They’re going to remove the card, reset the password, and maybe report the card.

Taking money from someone else’s bank account is a shitty thing to do. I don’t know why anyone here would be in support of not reporting this.

[–] [email protected] 4 points 7 months ago (2 children)

My account is with mailinator (free throwaway email) and I'm hopeful someone does this for me. That sounds quite nice.

[–] [email protected] 5 points 7 months ago

But it’s probably using a stolen CC. I wouldn’t feel too great about using someone else’s credit card without their knowledge. I’d report it and try to get the card suspended.

[–] TalesOfTrees 3 points 7 months ago

I used to blame my cousin, as she has a raging drug addiction and does shady crap like steal people's credit cards/checks and it was only after she had been over that I had noticed. But nope, still going despite time and resets. If I knew a way of pulling login info off the TV, I'd probably share it, because hell, why not.

[–] [email protected] 1 points 7 months ago

lol yep. I used a 10 minute mail address for my Roku account and the fakest name ever. Good luck, thieves!

[–] [email protected] 20 points 7 months ago (1 children)

This is not a "Roku data breach."

This is a use of compromised user credentials, with Roku as the target.

[–] [email protected] -1 points 7 months ago (2 children)

Yeah, but they don’t have contemporary best practices in place that would’ve reduced their exposure to this.

[–] [email protected] 12 points 7 months ago (1 children)

The only thing that would have prevented this in this context would be mandatory MFA. Did they have that? No, but there's a huge number of places that are way more sensitive than a streaming platform that don't have mandatory MFA (coughETradecough).

It is wholly misleading to characterize this as a "Roku data breach," and it's disingenuous to portray Roku in this instance as somehow glaringly worse than everyone else.

[–] [email protected] 1 points 7 months ago* (last edited 7 months ago) (1 children)

Wouldn't salted hashes have prevented this?

You just add some extra characters to every password before hashing and then stolen hashes and rainbow tables don't work any more.

In other words, I think ghostalmedia is correct, best practices would have prevented this.

[–] [email protected] 1 points 7 months ago (1 children)

No. Nobody has stolen hashes. They have usernames and passwords collected from elsewhere, that they tried against Roku, because people tend to reuse usernames and passwords.

[–] [email protected] 1 points 7 months ago (1 children)

Ugh... Who is still storing passwords in the clear... For fuck sake...

[–] [email protected] 1 points 7 months ago (1 children)

That doesn’t have anything to do with it, really. There’s plenty of ways that credentials get “leaked,” not the least of which is users who reuse passwords also falling for scam emails that have them “log in” to something. It could matter if some specific credentials were initially acquired because some other place was storing clear text passwords, and that place had a breach.

Still wouldn’t be an issue at all if users didn’t reuse passwords. That’s the lynchpin. This is users’ fault, not Roku’s.

[–] [email protected] 1 points 7 months ago

It could matter if some specific credentials were initially acquired because some other place was storing clear text passwords, and that place had a breach.

Exactly, that was my assumption.

After all, reusing passwords for multiple sites becomes a problem as soon the password becomes known. But for that password to become known, some site had to either allow the plaintext password to be leaked, or an unsalted hash. Or the site has to allow for insecure (easily guessable) passwords to be used.

Reusing passwords is undeniably the user's fault, but only because some other site's security measures may also have been negligent.

[–] [email protected] 2 points 7 months ago

Will be interesting to see how people react when Netflix rolls out mandatory two factor auth for logins.

[–] [email protected] 2 points 7 months ago

i believe that data breaches are so frequent, that we now have a dedicated community to post these.