Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On
Even Realities G2’s biggest software update yet brings an app store and a meeting prep tool that changes how you work

Even Realities G2’s biggest software update yet brings an app store and a meeting prep tool that changes how you work

27 March 2026
Review: Samsung Galaxy S26 and Galaxy S26+

Review: Samsung Galaxy S26 and Galaxy S26+

27 March 2026
Android 17 makes your internet controls way less frustrating

Android 17 makes your internet controls way less frustrating

27 March 2026
Facebook X (Twitter) Instagram
Just In
  • Even Realities G2’s biggest software update yet brings an app store and a meeting prep tool that changes how you work
  • Review: Samsung Galaxy S26 and Galaxy S26+
  • Android 17 makes your internet controls way less frustrating
  • Review: Garmin inReach Mini 3 Plus Satellite Messenger
  • The Mac Pro is dead at Apple, and I’ll miss the cheese-grater powerhouse
  • When Satellite Data Becomes a Weapon
  • AMD’s latest Ryzen 9 9950X3D2 pushes X3D to the limit
  • New Bernie Sanders AI Safety Bill Would Halt Data Center Construction
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » Roku closes the barn door, badly, after a half-million accounts are compromised
News

Roku closes the barn door, badly, after a half-million accounts are compromised

News RoomBy News Room12 April 20245 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Roku closes the barn door, badly, after a half-million accounts are compromised
Share
Facebook Twitter LinkedIn Pinterest Email

I gave Roku a bit of a hard time in March after it came to light that some 15,000 accounts were affected in a security breach. To be fair, that breach wasn’t entirely Roku’s fault because it was done via credential stuffing. That’s the method by which credentials are used from some other leak and just tried in various other services in hopes that you’ve reused a password somewhere. That attack netted more than 15,000 hits.

That’s bad enough. Worse was that Roku still didn’t have two-factor authentication, which would have required the evildoers to have a second set of credentials and could have prevented many of the unauthorized entries.

But apparently things actually got worse from there. Roku today announced that the investigation into the 15,000-account breach uncovered a second attack, “which impacted approximately 576,000 additional accounts.” (For context, Roku had 80 million active accounts at the end of 2023.)

Like the first attack, Roku says that “it is likely that login credentials used in these attacks were taken from another source, like another online account, where the affected users may have used the same credentials.” In other words, more credential stuffing. Roku says that fewer than 400 cases saw unauthorized purchases or streaming subscriptions using the payment methods that were attached to those accounts.

All of that is bad. Very bad, actually. (Especially for the 400 accounts that actually saw money change hands.)

Roku finally enables 2FA, sort of

If there’s any good news to come from this, is that’s Roku has finally enabled two-factor authentication. Sort of. First, here’s what Roku had to say in its post announcing the second breach:

“As a part of our ongoing commitment to information security, we have enabled two-factor authentication (2FA) for all Roku accounts, even for those that have not been impacted by these recent incidents. As a result, the next time you attempt to log in to your Roku account online, a verification link will be sent to the email address associated with your account, and you will need to click the link in the email before you can access the account.”

That second part is important. The main two-factor authentication Roku has implemented is that it will send you a link, via email, as the secondary form of authentication. That’s better than nothing. You also can enter the last five digits of your device ID if for some reason you can’t get to your email to click the link.

What you don’t get is any options. You can’t choose whether the two-factor authentication is done by “magic link” (wherein the company sends you a temporary link to approve access), or time-based code via SMS or authenticator app. Or some other method. That’s not the end of the world, I suppose. An emailed link is fairly frictionless — provided that the email account itself isn’t also compromised.

But it’s also not without issues.

Post-2FA device activation

Just to test things out, I reset my Roku account password. All subsequent logins have ended up with Roku sending me a email with a link to click, just like Roku said would happen. That works fine in a web browser. I log in with my email and password, then wait a couple seconds for Roku to send me a link to click. Same goes for logging in to the Roku app.

But I ran into issues trying to log in to a Roku streaming stick after a hard reset. There are two options here. With one, the Roku device can display a QR code on the TV. Scan it with your phone, and you’re prompted to log in using your email and password. Easy enough. And that login will send you a link via email that you have to click before you’re actually able to do anything on the device you’re trying to activate. Only, it doesn’t appear that the authentication is returned to the device.

But if you choose the option by which you manually type your email using the Roku remote, you’ll be sent a different-looking email. Click that link, and your Roku device will authenticate and activate, just as it should. In other words, it looks like the QR code method is trying to log you in to your account, while the manual method is trying to properly activate the device.

Roku says it’s looking into this part.

The really frustrating part

This really shouldn’t be that difficult. Two-factor authentication is not particularly new. And while any 2FA obviously adds a layer of complexity to any login scheme — and if Roku is known for anything, it’s simplicity — 2FA is also the sort of thing that users have gotten used to over the years.

Roku needs to do a few things. Foremost is that it needs to fix the device authentication. It’s simply broken if you try to use the QR code. (The good news is that should be a server-side fix.) It should allow you to choose your method of authentication. That likely would take a little longer to roll out. But given that Roku should have had proper 2FA set up years ago, that’s hardly an excuse.

Security is always going to be an uphill battle. It’s too easy for the bad guys to play offense. Defense is costly and time-consuming. But it’s not getting any less important. Roku still needs to do better.











Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleChange Healthcare Faces Another Ransomware Threat—and It Looks Credible
Next Article House Votes to Extend—and Expand—a Major US Spy Program

Related Articles

Even Realities G2’s biggest software update yet brings an app store and a meeting prep tool that changes how you work
News

Even Realities G2’s biggest software update yet brings an app store and a meeting prep tool that changes how you work

27 March 2026
Review: Samsung Galaxy S26 and Galaxy S26+
News

Review: Samsung Galaxy S26 and Galaxy S26+

27 March 2026
Android 17 makes your internet controls way less frustrating
News

Android 17 makes your internet controls way less frustrating

27 March 2026
Review: Garmin inReach Mini 3 Plus Satellite Messenger
News

Review: Garmin inReach Mini 3 Plus Satellite Messenger

27 March 2026
The Mac Pro is dead at Apple, and I’ll miss the cheese-grater powerhouse
News

The Mac Pro is dead at Apple, and I’ll miss the cheese-grater powerhouse

27 March 2026
When Satellite Data Becomes a Weapon
News

When Satellite Data Becomes a Weapon

27 March 2026
Demo
Top Articles
5 laptops to buy instead of the M4 MacBook Pro

5 laptops to buy instead of the M4 MacBook Pro

17 November 2024132 Views
ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024111 Views
Costco partners with Electric Era to bring back EV charging in the U.S.

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 2024100 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
When Satellite Data Becomes a Weapon News

When Satellite Data Becomes a Weapon

News Room27 March 2026
AMD’s latest Ryzen 9 9950X3D2 pushes X3D to the limit News

AMD’s latest Ryzen 9 9950X3D2 pushes X3D to the limit

News Room27 March 2026
New Bernie Sanders AI Safety Bill Would Halt Data Center Construction News

New Bernie Sanders AI Safety Bill Would Halt Data Center Construction

News Room27 March 2026
Most Popular
The Spectacular Burnout of a Solar Panel Salesman

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025137 Views
5 laptops to buy instead of the M4 MacBook Pro

5 laptops to buy instead of the M4 MacBook Pro

17 November 2024132 Views
ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024111 Views
Our Picks
Review: Garmin inReach Mini 3 Plus Satellite Messenger

Review: Garmin inReach Mini 3 Plus Satellite Messenger

27 March 2026
The Mac Pro is dead at Apple, and I’ll miss the cheese-grater powerhouse

The Mac Pro is dead at Apple, and I’ll miss the cheese-grater powerhouse

27 March 2026
When Satellite Data Becomes a Weapon

When Satellite Data Becomes a Weapon

27 March 2026

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2026 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.