frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Roblox parental controls are a dystopian security disaster

17•notsure357•7h ago
My 14 year old daughter got hacked by someone who was able to add themselves as a "linked parent" to her account. I'm not even sure that this person got ahold of her password in the first place. All this happened on Wednesday morning (6/24/26) but on the day it happened I did not recieve a single email about any of this even though the account is tied to my email address (verified). Usually if there is a new log in on an unrecognized device I would have gotten an email about it, but nothing was sent on 6/24 to me. I suspect that even if two factor authentication was already added to her account it would have done nothing, because there was a two factor authentication passkey added to her account which was definitely not set up by her. But by using that newly created authentication passkey the "linked parent" was clearly able to log into her account (which I didn't get any emails about), go into every game and transfer out every last collectable thing she had collected since 2020.

And wouldn't you know it, Roblox says they aren't responsible for those lost collectables. All the christmas and birthday roblox gift cards from the last 6 years which were used to buy those collectable items are completely wiped away for fun by this "linked parent". My daughter is absolutely devastated by her loss of these collectables.

During the password reset process I had to disable two factor authentication to be able to log in to the account. Once in the account, the two factor passkey could not be removed from the account without having access to the passkey and I had to go through an AI chatbot to get that removed. The "linked parent" also changed the date of birth to make my daugter become 8 years old in Roblox and apparently for whatever reason you are only allowed to change the date of birth once, meaning I had to make request after request trying to get the date of birth changed. Every time I am making these support requests I have to prove I am a human (captcha), enter six digit email security codes, and then try to talk to an AI bot that only partially understands my issues. I can request to speak to a human which immediately ends the chat with the ai bot telling me a support request has been filed.

What is most baffling of all is that I had requested removing the "linked parent" in question and between both the AI and whatever support team is behind that AI, I could not get the "liked parent" removed. I even had one ticket closed out with an email response telling me "We are unable to update or modify the parental settings on your child’s account due to security reasons. Parental controls can be managed on the account with parent privileges linked to your child’s account." When I was talking to an AI bot about this they explained that the "linked parent" was the only person who could remove themselves from my child's account and trying to request anything beyond that answer was denied. I finally hit a wall in which I had made too many requests and they were no longer accepting form submissions from me. My wife is trying to work on this stuff now because I'm at a dead end. She was able to get the account moved to her email address because she had made payments to Roblox in the past to fund the account, but the "linked parent" is still there.

Why would I ever want to give money to Roblox again after all of this? Kids are more savvy than anyone else on that gaming system and will keep finding loopholes to do these sorts of things. No matter how many procedural layers of restricted communication are added this is only made worse because fundamentally Roblox assumes no liability for any lost items within a system where these collectables can be traded among friends or stolen from thieves. I don't know that Roblox will be able to solve these problems ever when their solutions seem to be actually making things worse. If you have any stock in Roblox I would say they are a STRONG SELL!

Comments

notsure357•7h ago
The truly ironic part about all this is that Roblox is a gaming system and for some kids there is probably nothing more fun than tying to "game the system" and make things worse for everyone else. The child exploitation issues are far more scarier and there is probably even less accountability trying to decipher that as a parent.
kgwxd•6h ago
My kid got his 5 year old account hacked in Feb. Roblox didn't give a shit. They kept saying to start a new account, and turn on multi-factor auth. That account already had all that. They hacked him via the multi-factor mechanism! Gave them more details, not enough. They eventually just ignored me. Thousands of dollars over those 5 years. Either way, both my kids are done with the shit platform anyway. The new rules made them hate it anyway.

It's not just collectibles either. Premium was active on the account, and he had a few private server passes that had a pretty high one time fee. The worst.

notsure357•6h ago
I don't understand how a system is designed in which I am getting emails when I log in to Roblox on an unrecognized device but absolutely no email notifications of any kind when someone else is claiming to be a parent and the date of birth gets modified! How did these things happen without any email notification? But yeah it is definitely somehow my fault for not setting a higher security level on my account, not Roblox's fault.

The open source DOCX editor submitted to HN a few weeks ago has been deleted

57•gcanyon•4h ago•36 comments

Ask HN: Is "no source code was copied" still a sufficient copyright defense?

51•oscgam1•11h ago•66 comments

Roblox parental controls are a dystopian security disaster

17•notsure357•7h ago•3 comments

Tell Zillow: Fee-Simple vs. Leasehold Filter

3•HoldOnAMinute•4h ago•1 comments

Ask HN: Where is the programming profession going?

135•syntaxbush•1d ago•149 comments

Ask HN: Which AI concepts are here to stay, and which will churn?

3•datsci_est_2015•5h ago•3 comments

Ask HN: Techniques for learning things quickly using coding agents?

2•throwaw12•5h ago•1 comments

Ask HN: Who remembers Fry's Electronics – the "church" of IT people?

6•netfortius•14h ago•4 comments

Ask HN: Norway bans AI in elementary schools

14•mellosty•1d ago•12 comments

Ask HN: How much coding should beginners learn in the AI era?

33•JohnDSDev•2d ago•45 comments

Ask HN: How is GPU power draw measured at scale?

5•anax32•15h ago•2 comments

I feel like VSCode is falling apart

11•othmanosx•1d ago•10 comments

Ask HN: Why does every AI demo sound perfect but real world deployment always

7•VaderAi•19h ago•9 comments

Tell HN: OpenAI has started putting ads on paid programs

113•shantnutiwari•1d ago•64 comments

Decoupling Compute and Memory for Async GPUs

8•yiyingzhang•1d ago•2 comments

Ask HN: What surprised you about Estonia e-Residency and running an Estonian OÜ?

80•jvilalta•1d ago•70 comments

Ask HN: What home printer do you use/recommend?

18•niyazpk•3d ago•22 comments

Ask HN: Will programmers write more efficient code during the memory shortage?

153•amichail•1w ago•246 comments

My website gets more attacks than human visitors

5•tommy2970•1d ago•4 comments

Ask HN: Quickbooks Alternative?

5•bix6•1d ago•2 comments

Google AI overview for "keynesian economics" is written in Korean

4•something765478•1d ago•4 comments

Ask HN: Do you thank your agents when they did a good job?

7•ex-aws-dude•1d ago•12 comments

As; HN: I was curious why MTP affects PP TPS in llama.cpp. My PoC recovers it?

3•i_am_rocoe•1d ago•1 comments

Ask HN: What are the hardest problems AWS Lambda MicroVMs can solve now?

6•iaziz786•2d ago•2 comments

Ask HN: Is anyone using the A2A protocol?

96•asim•1w ago•45 comments

Ask HN: Anthropic banned me from using Claude Code and I don't know what to do

81•ayi•3d ago•93 comments

Ask HN: What tools are you using for AI-assisted code review?

26•agos•1w ago•31 comments

How to find AI-conservative companies to work for?

20•tossitawayplz•3d ago•12 comments

Got access to Gemini's actual thinking

4•StizzurpXDD•1d ago•0 comments

Ask HN: Yahoo deleted all my emails. Now what?

15•neya•2d ago•13 comments