Live data from Hacker News

Facebook activated my dormant account and won’t let me deactivate it

smashcompany.com

101–110 of 165 posts

Re: Facebook activated my dormant account and won’t let me deactivate it

#101

Earlier quoted context omitted.

So their automated systems detected malicious access as legitimate access, and legitimate access as malicious access? And this is somehow working as intended?

I'm not sure what you are suggesting facebook should do. They can't very well just assume all attackers will set the evil-bit now can they? https://en.wikipedia.org/wiki/Evil_bit The automated system has done "the right thing" and fallen back to manual verification when it detected suspicious activity. They can't request id for every activation or reactivation.

Why not? Deactivation and reactivation is a very rare activity that warrants secondary authorization. A simple confirmation email does the trick most of the time.

Re: Facebook activated my dormant account and won’t let me deactivate it

#102

Earlier quoted context omitted.

For many third-party websites your facebook account is your identity, i.e. they are super duper important.

>For many third-party websites your facebook account is your identity, i.e. they are super duper important. Correction, for many third party websites a facebook account is /an/ identity. If you closed your facebook account, what are the odds you're going to be using it as your openID login all over the place? Probably none.

I think you underestimate the human ability to forget. Lots of people will decide to close their facebook account without thinking through the consequences (like that they used it to authenticate a dozen places).

Re: Facebook activated my dormant account and won’t let me deactivate it

#103
To echo others in this thread, the same happened to me. The account was deactivated in 2009, and I used a password that I know to have been compromised in hacks of other services.

After several weeks, I got an email yesterday telling me that due to no further suspicious activity, they unlocked the account without Photo ID verification. I went in and scheduled the account for deletion.

Re: Facebook activated my dormant account and won’t let me deactivate it

#104

It may not be Facebook themselves that caused the account reactivation. I'm was very recently in a similar situation having a Facebook account that was deactivated about 5 years ago (I thought I had deleted it). I received the exact same account reactivation notification email as in the article and I also started receiving photo post notification emails. Upon attempting to sign in to my Facebook account to investigat…

This would be less an issue if Facebook would forthrightly handle account deletion.

As it is now it's simply not possible for a regular person to decide that they do not wish to further participate with any of facebook's services, remove their account and all the data associated with it, and be confident that all of the data collection, analysis, and 3rd party identification/authorization that goes on with active facebook accounts stops when their account removal process is complete.

So no matter what any one individual does in regards to their unwanted facebook account there is always the possibility that something they would really prefer not to happen with it comes to be... like some hacker from who knows where gaining control of it and so adding another key element to their identity fraud dosier collection.

Re: Facebook activated my dormant account and won’t let me deactivate it

#105

Earlier quoted context omitted.

They assume their automated system can catch evil users in the act. It couldn't. It failed it's job and let the attacker do what they wanted while preventing the legitimate user from controlling their account. So the automated system did more harm than good. It should either be overhauled or disabled.

> They assume their automated system can catch evil users in the act. Where do they assume that?

The system exists. If it can't do that, it has no purpose.

Re: Facebook activated my dormant account and won’t let me deactivate it

#106
post #49

Earlier quoted context omitted.

and at the bottom of the page: > You can also try other challenges to confirm your identity.

The identity challenge does not matter: you shouldn't have to confirm your identity to protest against the reactivation of an account you intended to close. The point still stands: OP intended to close their account in 2012, and are now being signed up again without their consent.

This happened to me recently, with Facebook. However, Facebook didn't reactivate my account, I was the one who mistakenly clicked on a link on Spotify when I reactivated my account which somehow triggered the reactivation.

I'm going to guess that OP of article had a similar situation; Using another service, an errant click was made that triggered an event on Facebook.

Re: Facebook activated my dormant account and won’t let me deactivate it

#107

At least they emailed you about it. In my case they reactivated it for some reason and I had no idea for months until someone told me they saw my Facebook page. I had just deactivated because I wanted to take a break from all the fake relationships, but I never really hated the company itself. But now that I know this company just does whatever they want and doesn't care about the contract with their users, I despise…

Well, if you give somebody your facebook password and they reactivate your account, shouldn't you be angry with that somebody?

Where did i say I gave someone my password? I said it just got re-activated automatically without me knowing. No one else other than me knows the password. And I never got a notice.

I am angry at you.

Re: Facebook activated my dormant account and won’t let me deactivate it

#108
post #90

Earlier quoted context omitted.

> I pay for Facebook. That makes me a customer. How does one pay for Facebook? Is there a premium service I'm not aware of?

Hey, sorry. I edited my comment to clarify shortly after posting it, but I imagine you probably loaded the page in the meantime and responded later. I run ads on Facebook for several Facebook pages and additionally promote their posts (using the per-post boosting) fairly regularly.

Okay that makes sense. I thought it was from the perspective of a John Q. User who has a Facebook account.

In your example though the Ads are the product you're paying for. Not the Facebook account that is purchasing them, though I see how they're inherently linked.

Re: Facebook activated my dormant account and won’t let me deactivate it

#109
post #3

What would the alternative be? Allow anyone to request that an account is deleted? Facebook needs some form of verification due to the password being breached (and its great that they are checking for that sort of thing)

>Allow anyone to request that an account is deleted?

"anyone" with the proper access credentials?

Re: Facebook activated my dormant account and won’t let me deactivate it

#110

Earlier quoted context omitted.

I'm not sure what you are suggesting facebook should do. They can't very well just assume all attackers will set the evil-bit now can they? https://en.wikipedia.org/wiki/Evil_bit The automated system has done "the right thing" and fallen back to manual verification when it detected suspicious activity. They can't request id for every activation or reactivation.

They assume their automated system can catch evil users in the act. It couldn't. It failed it's job and let the attacker do what they wanted while preventing the legitimate user from controlling their account. So the automated system did more harm than good. It should either be overhauled or disabled.

It did that, in this one particular case. Facebook has what, hundreds of millions of users, maybe billions? No system anybody can come up with can handle every case that every one of those users will have perfectly. They have something that their experience leads them to believe is at least pretty good for most cases. They're not going to change it because it did the wrong thing for one guy.

They don't even know right now that it did the wrong thing. Presuming the root cause is a login from somewhere else from a password DB, all they know is they have 2 logins with the right password from 2 widely separated places. How are they to know which one is the right one? Asking for a real ID sounds like a good start, but the author refuses to provide one. Understandable, I suppose, but how else can he prove that he's the real account owner and not the other guy?

Post reply on HN