Skip to main content

I don’t know what to do about Roku

Phil Nickinson holding a Roku remote control over his eyes as the Roku screensaver plays behind him.
How much longer before you can no longer afford to use a Roku device? Phil Nickinson / Digital Trends

I’ve found myself thinking a lot about Roku this week. Or, rather, trying really hard not to think about Roku and all the ways it should be doing better.

The streaming platform and the company mostly need no introduction. It basically started as a low-cost way to stream Netflix and then grew into a wonderfully service-agnostic option. That is, it treated Netflix like it treated HBO. Or whatever other service had a “channel” (read: app) on the platform.

Recommended Videos

Roku was (and is) inexpensive to buy, and easy to use. And I’m just not sure I can recommend it anymore.

A few reasons for that. First, and perhaps the least worrisome, is that Roku is now more of an advertising platform first and a streaming platform second. Those things go hand in hand, sure. But make no mistake, it’s the ad part that’s running the show now. Of Roku’s two revenue buckets — devices (as in hardware) and platform (advertising and anything else) — one finished 2023 with about 510% more revenue than the other. That is, $2.994 billion versus $491 million. And only one of those segments turned a profit. I’ll let you figure out which was which.

Not to say that I love what Roku has become, but you can’t blame a business for making money. (And an ad-blocking scheme at least helps a little.)

I’m also not in the camp of folks freaking out recently over Roku’s Dispute Resolution Terms. It’s dangerous (and dumb) for anyone who’s not a lawyer to pretend to be a lawyer for the purposes of parsing the fine print of a user agreement. And while I’m not a huge fan of forced arbitration in principle, it’s also not realistic for a company to potentially have to fight lawsuit after lawsuit. It has to be able to protect itself and mitigate that sort of thing. Arbitration is one way.

The Roku arbitration opt-out clause, as read on a phone.
Is the Roku arbitration opt-out really that bad? And probably related: Are you a lawyer? Phil Nickinson / Digital Trends

The recent to-do has to do with the right-to-opt-out clause. You have 30 days to opt out of arbitration. You have to do so in writing, by mail. (As legal stuff is often done.) And you have to include a copy of your receipt. Folks are upset about that last part, as if they’ve never received a receipt for something they’ve purchased before, either online or in meatspace. And a whole month isn’t exactly a long time to hang on to something like that immediately after purchase.

Don’t get me wrong — it’s doubtful I’d think twice about a receipt from a $30 Roku device. If I picked up one up in a store, the receipt might be tossed out before I get home. But if I bought something online? It’ll likely be in my email forever. But in any event, it’s not unreasonable for Roku to require someone demanding to opt out of arbitration to prove that they actually purchased a product in the first place. That’s the most basic of requirements. Because if you can’t prove you actually bought the thing, then you have no reason to opt out of arbitration at all, right?

And I’d even be willing to not raise too much Cain over a recent security event in which 15,000-plus Roku accounts apparently got hit by a credential-stuffing attack. That’s an attack by which your username and password were leaked elsewhere, and then were used on some other service, just to see if they’d work. In this case, those logins also worked at Roku.

We cannot and must not blame the victim (that’s ultimately the account holder, not Roku), though it is a reminder that we should have unique passwords for every single service. Don’t reuse passwords, boys and girls. No, the blame goes to the hackers. Mostly.

It’s Roku’s response that really bothers me. In its letter notifying users of the data breach — something that some states require by law — Roku opens with the following: “We take our viewers’ privacy and security seriously.”

I’m not convinced it actually does, for one simple reason: Roku does not even have the option — let alone the requirement — for two-factor authentication on its accounts.

Roku needs to implement two-factor authentication. Yesterday.

In the year of our lord 2024, that is inexcusable. Every company should at least offer 2FA as an option. (It really should require it.) Amazon requires it if you log in to a Fire TV device. Google requires it if you log in to Android TV or Apple TV. Apple has it as part of its accounts processes.

The account section of the Roku website, as seen on a phone.
Roku’s account options are handy, so long as you don’t want to use two-factor authentication. Phil Nickinson / Digital Trends

I asked Roku about potentially offering 2FA at some point. It didn’t answer that question. Not about 2FA over text message. Or time-based software token. Or Passkeys. It did, however, give the following unattributed statement, which I’ll reproduce here in its entirety:

“Roku’s security team recently detected suspicious activity that indicated a limited number of Roku accounts were accessed by unauthorized actors using login credentials obtained from third-party sources (e.g., through data breaches of third-party services that are not related to Roku). In response, we took immediate steps to secure these accounts and are notifying affected customers. Roku is committed to maintaining our customers’ privacy and security, and we take this incident very seriously.”

So there’s that.

If Roku really took its 80 million monthly active users’ security seriously, it would at least offer two-factor authentication as an option. After a breach like this you’d think Roku might implement 2FA in addition to requiring password resets.

But it hasn’t yet. And I’m just not sure I can recommend anyone use Roku until it does.

(Note: A previous version of this column said that the 15,000-plus accounts represented about 19 percent of Roku’s 80 million monthly after users. Obviously that was not correct — it’s more like 0.018 percent. That’s much less worse, and I regret the error. But it does not change the need for two-factor authentication.)

Phil Nickinson
Section Editor, Audio/Video
Phil spent the 2000s making newspapers with the Pensacola (Fla.) News Journal, the 2010s with Android Central and then the…
What is HDR10+? What you need to know about the HDR format
Best TV vs Biggest: Sony A95L & TCL QM8

The QLED and OLED TVs we know and love do a phenomenal job of bringing rich colors, stunning brightness, and sharp motion clarity to our favorite movies and shows. But one of the unsung heroes of an excellent viewing experience is High Dynamic Range (HDR), a common feature in most TVs that delivers a brighter and more colorful image with a higher level of contrast between light and dark areas, making for a beautiful viewing experience. Over the last few years, the best TVs have become excellent HDR displays, and several formats of the technology have appeared, with one of the latest and best being HDR10+.

Joining the ranks of other HDR codecs, including Dolby Vision, HDR10, and HLG, HDR10+ unlocks the full potential of your TV’s picture processing, but it’s not a format you’ll find on every modern TV. So, which TVs support HDR10+, and what other inside baseball is there to know about the picture standard? Our TV experts spend hundreds of hours reviewing the latest TVs each year, so we've put together explainer to help you understand HDR10+.
What is HDR?

Read more
Roku closes the barn door, badly, after a half-million accounts are compromised
Roku Streaming Stick 4K.

I gave Roku a bit of a hard time in March after it came to light that some 15,000 accounts were affected in a security breach. To be fair, that breach wasn't entirely Roku's fault because it was done via credential stuffing. That's the method by which credentials are used from some other leak and just tried in various other services in hopes that you've reused a password somewhere. That attack netted more than 15,000 hits.

That's bad enough. Worse was that Roku still didn't have two-factor authentication, which would have required the evildoers to have a second set of credentials and could have prevented many of the unauthorized entries.

Read more
What does the Star button do on a Roku remote control?
Roku Star button on the remote.

Anyone looking to bring additional smarts to their TV has probably stumbled upon Roku. The device is available in multiple formats -- but its remote control has remained largely untouched with these new product launches. There have been a few tweaks over time, but by and large, Roku is using the same remote today as it did years ago.

One of the most compelling features of the Roku remote control is the Star button. Its use isn't immediately obvious, but it essentially works as a way to access various menus or toggle different video options. For example, depending on what app is loaded on your screen, the Star button might let you turn on subtitles modify display and sound settings.

Read more