frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Roblox parental controls are a dystopian security disaster

5•notsure357•1h ago
My 14 year old daughter got hacked by someone who was able to add themselves as a "linked parent" to her account. I'm not even sure that this person got ahold of her password in the first place. All this happened on Wednesday morning (6/24/26) but on the day it happened I did not recieve a single email about any of this even though the account is tied to my email address (verified). Usually if there is a new log in on an unrecognized device I would have gotten an email about it, but nothing was sent on 6/24 to me. I suspect that even if two factor authentication was already added to her account it would have done nothing, because there was a two factor authentication passkey added to her account which was definitely not set up by her. But by using that newly created authentication passkey the "linked parent" was clearly able to log into her account (which I didn't get any emails about), go into every game and transfer out every last collectable thing she had collected since 2020.

And wouldn't you know it, Roblox says they aren't responsible for those lost collectables. All the christmas and birthday roblox gift cards from the last 6 years which were used to buy those collectable items are completely wiped away for fun by this "linked parent". My daughter is absolutely devastated by her loss of these collectables.

During the password reset process I had to disable two factor authentication to be able to log in to the account. Once in the account, the two factor passkey could not be removed from the account without having access to the passkey and I had to go through an AI chatbot to get that removed. The "linked parent" also changed the date of birth to make my daugter become 8 years old in Roblox and apparently for whatever reason you are only allowed to change the date of birth once, meaning I had to make request after request trying to get the date of birth changed. Every time I am making these support requests I have to prove I am a human (captcha), enter six digit email security codes, and then try to talk to an AI bot that only partially understands my issues. I can request to speak to a human which immediately ends the chat with the ai bot telling me a support request has been filed.

What is most baffling of all is that I had requested removing the "linked parent" in question and between both the AI and whatever support team is behind that AI, I could not get the "liked parent" removed. I even had one ticket closed out with an email response telling me "We are unable to update or modify the parental settings on your child’s account due to security reasons. Parental controls can be managed on the account with parent privileges linked to your child’s account." When I was talking to an AI bot about this they explained that the "linked parent" was the only person who could remove themselves from my child's account and trying to request anything beyond that answer was denied. I finally hit a wall in which I had made too many requests and they were no longer accepting form submissions from me. My wife is trying to work on this stuff now because I'm at a dead end. She was able to get the account moved to her email address because she had made payments to Roblox in the past to fund the account, but the "linked parent" is still there.

Why would I ever want to give money to Roblox again after all of this? Kids are more savvy than anyone else on that gaming system and will keep finding loopholes to do these sorts of things. No matter how many procedural layers of restricted communication are added this is only made worse because fundamentally Roblox assumes no liability for any lost items within a system where these collectables can be traded among friends or stolen from thieves. I don't know that Roblox will be able to solve these problems ever when their solutions seem to be actually making things worse. If you have any stock in Roblox I would say they are a STRONG SELL!

Comments

notsure357•1h ago
The truly ironic part about all this is that Roblox is a gaming system and for some kids there is probably nothing more fun than tying to "game the system" and make things worse for everyone else. The child exploitation issues are far more scarier and there is probably even less accountability trying to decipher that as a parent.
kgwxd•1h ago
My kid got his 5 year old account hacked in Feb. Roblox didn't give a shit. They kept saying to start a new account, and turn on multi-factor auth. That account already had all that. They hacked him via the multi-factor mechanism! Gave them more details, not enough. They eventually just ignored me. Thousands of dollars over those 5 years. Either way, both my kids are done with the shit platform anyway. The new rules made them hate it anyway.

It's not just collectibles either. Premium was active on the account, and he had a few private server passes that had a pretty high one time fee. The worst.

notsure357•43m ago
I don't understand how a system is designed in which I am getting emails when I log in to Roblox on an unrecognized device but absolutely no email notifications of any kind when someone else is claiming to be a parent and the date of birth gets modified! How did these things happen without any email notification? But yeah it is definitely somehow my fault for not setting a higher security level on my account, not Roblox's fault.

Give GitHub Copilot CLI real code intelligence with language servers

https://github.blog/ai-and-ml/github-copilot/give-github-copilot-cli-real-code-intelligence-with-...
1•mariuz•1m ago•0 comments

ExtSteamGame: Explainable Steam Recommendations from Game Reviews

https://nextsteamgame.com
1•apeczon•2m ago•0 comments

A History of Tug-of-War Fatalities

https://priceonomics.com/a-history-of-tug-of-war-fatalities/
1•EndXA•2m ago•0 comments

Lufthansa Asked for My Credit Card

https://yashgarg.dev/posts/lufthansa-credit-card/
1•speckx•3m ago•0 comments

<LoginWithChatGPT /> – Unofficial login to personal ChatGPT subscription

https://twitter.com/saviomartin7/status/2070531441415602469
1•saviomartin•4m ago•0 comments

Reckoning with the Political Economy of AI

https://arxiv.org/abs/2604.16106
1•andyjohnson0•6m ago•1 comments

NYT slams Microsoft for building copyright-infringing supercomputer for OpenAI

https://arstechnica.com/tech-policy/2026/06/microsoft-built-supercomputer-to-help-openai-infringe...
1•01-_-•6m ago•0 comments

'Edited' human embryos reveal secrets of our development–and fuel ethical debate

https://www.nature.com/articles/d41586-026-02027-0
2•bookofjoe•8m ago•1 comments

Full duration single-engine static fire test of Starship 40

https://twitter.com/spacex/status/2070482358369763674
1•ivewonyoung•9m ago•0 comments

How to Design Search for a Database

https://bonsai.io/blog/how-to-design-search-for-a-database/
1•binarymax•10m ago•0 comments

Show HN: Statey – the database your AI shares across every chat, over MCP

https://www.statey.ai
2•scottwillman•10m ago•0 comments

Perplexity's Brain Is a Context Graph. That's the Point

https://hydradb.com/blog/perplexity-brain-context-graph
1•manveerc•11m ago•0 comments

Open Letter to Compassionate, Left-Leaning, AI-Hating, Animal-Loving Meat Eaters

https://brennan.day/an-open-letter-to-compassionate-left-leaning-ai-hating-animal-loving-meat-eat...
1•speckx•11m ago•0 comments

Posthog's marketing budget in 2026 (with actual $ figures)

https://posthog.com/founders/actual-marketing-budget-2026
1•herbertl•14m ago•0 comments

MirrorCode: What's the largest software project AI can complete on its own?

https://epoch.ai/MirrorCode
2•tadamcz•14m ago•1 comments

Reed-Solomon for OCR: error correction for messy printed codes

https://github.com/chasangchual/reed-solomon-for-ocr
1•chasangchual•17m ago•0 comments

Aircraft crashes into Beijing's tallest skyscraper, triggering evacuations

https://www.dailymail.com/news/article-15932611/Aircraft-crashes-Beijings-tallest-skyscraper-trig...
1•Bender•18m ago•0 comments

DuckDuckGo, Unable to Resist AI's Pull, Mistakenly Claims Trump Died of Rabies

https://gizmodo.com/duckduckgo-unable-to-resist-the-pull-of-ai-mistakenly-claims-trump-died-of-ra...
1•gnabgib•19m ago•0 comments

PHP and TypeScript Types Comparison

https://gitlab.com/-/snippets/6005114
1•DPDmancul•19m ago•0 comments

Smart lock maker Level has been gutted and its founders are out

https://www.theverge.com/tech/957802/level-lock-layoffs-assa-abloy-kwikset-smart-lock-cloud
1•teepo•19m ago•0 comments

Chronic Pain: The Science of Unlearning Pain

https://www.zeit.de/gesundheit/2025-11/chronic-pain-causes-treatments-pain-perception-english
3•Tomte•20m ago•1 comments

PlayStation Is Deleting 551 Movies from Customers' Accounts

https://kotaku.com/playstation-store-movies-digital-studio-canal-terminator-2000711013
2•ortusdux•22m ago•0 comments

US auto regulators want to kill robotaxi brake pedals

https://www.theregister.com/offbeat/2026/06/26/us-auto-regulators-want-to-kill-robotaxi-brake-ped...
2•Bender•22m ago•0 comments

Yen's decline makes perfect sense to some analysts

https://www.japantimes.co.jp/business/2026/06/26/markets/sticky-weak-yen-june/
3•mikhael•23m ago•0 comments

Microsoft extends Windows 10 security updates to 2027

https://arstechnica.com/gadgets/2026/06/microsoft-adds-another-year-to-windows-10-extended-update...
1•Lihh27•23m ago•0 comments

The Atari Lynx Story [video]

https://www.youtube.com/watch?v=RcjbMCRErz4
2•thm•23m ago•0 comments

Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds

https://www.theregister.com/cyber-crime/2026/06/26/amazon-q-flaw-let-booby-trapped-git-repos-exec...
3•Bender•24m ago•0 comments

Monoids

https://en.wikipedia.org/wiki/Monoid
3•caminanteblanco•25m ago•0 comments

Atlas: Open-source deep research harness

https://steel.dev/blog/atlas-sdk
2•nkko•26m ago•0 comments

The Illusion of Ownership – It's yours until it isn't

https://yashgarg.dev/posts/the-illusion-of-ownership/
2•speckx•27m ago•0 comments