Earlier quoted context omitted.
So their automated systems detected malicious access as legitimate access, and legitimate access as malicious access? And this is somehow working as intended?
I'm not sure what you are suggesting facebook should do. They can't very well just assume all attackers will set the evil-bit now can they? https://en.wikipedia.org/wiki/Evil_bit The automated system has done "the right thing" and fallen back to manual verification when it detected suspicious activity. They can't request id for every activation or reactivation.
Facebook activated my dormant account and won’t let me deactivate it
101–110 of 165 posts
Re: Facebook activated my dormant account and won’t let me deactivate it
#102Earlier quoted context omitted.
For many third-party websites your facebook account is your identity, i.e. they are super duper important.
>For many third-party websites your facebook account is your identity, i.e. they are super duper important. Correction, for many third party websites a facebook account is /an/ identity. If you closed your facebook account, what are the odds you're going to be using it as your openID login all over the place? Probably none.
Re: Facebook activated my dormant account and won’t let me deactivate it
#103After several weeks, I got an email yesterday telling me that due to no further suspicious activity, they unlocked the account without Photo ID verification. I went in and scheduled the account for deletion.
Re: Facebook activated my dormant account and won’t let me deactivate it
#104It may not be Facebook themselves that caused the account reactivation. I'm was very recently in a similar situation having a Facebook account that was deactivated about 5 years ago (I thought I had deleted it). I received the exact same account reactivation notification email as in the article and I also started receiving photo post notification emails. Upon attempting to sign in to my Facebook account to investigat…
As it is now it's simply not possible for a regular person to decide that they do not wish to further participate with any of facebook's services, remove their account and all the data associated with it, and be confident that all of the data collection, analysis, and 3rd party identification/authorization that goes on with active facebook accounts stops when their account removal process is complete.
So no matter what any one individual does in regards to their unwanted facebook account there is always the possibility that something they would really prefer not to happen with it comes to be... like some hacker from who knows where gaining control of it and so adding another key element to their identity fraud dosier collection.
Re: Facebook activated my dormant account and won’t let me deactivate it
#105Earlier quoted context omitted.
They assume their automated system can catch evil users in the act. It couldn't. It failed it's job and let the attacker do what they wanted while preventing the legitimate user from controlling their account. So the automated system did more harm than good. It should either be overhauled or disabled.
> They assume their automated system can catch evil users in the act. Where do they assume that?
Re: Facebook activated my dormant account and won’t let me deactivate it
#106Earlier quoted context omitted.
and at the bottom of the page: > You can also try other challenges to confirm your identity.
The identity challenge does not matter: you shouldn't have to confirm your identity to protest against the reactivation of an account you intended to close. The point still stands: OP intended to close their account in 2012, and are now being signed up again without their consent.
I'm going to guess that OP of article had a similar situation; Using another service, an errant click was made that triggered an event on Facebook.
Re: Facebook activated my dormant account and won’t let me deactivate it
#107At least they emailed you about it. In my case they reactivated it for some reason and I had no idea for months until someone told me they saw my Facebook page. I had just deactivated because I wanted to take a break from all the fake relationships, but I never really hated the company itself. But now that I know this company just does whatever they want and doesn't care about the contract with their users, I despise…
Well, if you give somebody your facebook password and they reactivate your account, shouldn't you be angry with that somebody?
I am angry at you.
Re: Facebook activated my dormant account and won’t let me deactivate it
#108Earlier quoted context omitted.
> I pay for Facebook. That makes me a customer. How does one pay for Facebook? Is there a premium service I'm not aware of?
Hey, sorry. I edited my comment to clarify shortly after posting it, but I imagine you probably loaded the page in the meantime and responded later. I run ads on Facebook for several Facebook pages and additionally promote their posts (using the per-post boosting) fairly regularly.
In your example though the Ads are the product you're paying for. Not the Facebook account that is purchasing them, though I see how they're inherently linked.
Re: Facebook activated my dormant account and won’t let me deactivate it
#109What would the alternative be? Allow anyone to request that an account is deleted? Facebook needs some form of verification due to the password being breached (and its great that they are checking for that sort of thing)
"anyone" with the proper access credentials?
Re: Facebook activated my dormant account and won’t let me deactivate it
#110Earlier quoted context omitted.
I'm not sure what you are suggesting facebook should do. They can't very well just assume all attackers will set the evil-bit now can they? https://en.wikipedia.org/wiki/Evil_bit The automated system has done "the right thing" and fallen back to manual verification when it detected suspicious activity. They can't request id for every activation or reactivation.
They assume their automated system can catch evil users in the act. It couldn't. It failed it's job and let the attacker do what they wanted while preventing the legitimate user from controlling their account. So the automated system did more harm than good. It should either be overhauled or disabled.
They don't even know right now that it did the wrong thing. Presuming the root cause is a login from somewhere else from a password DB, all they know is they have 2 logins with the right password from 2 widely separated places. How are they to know which one is the right one? Asking for a real ID sounds like a good start, but the author refuses to provide one. Understandable, I suppose, but how else can he prove that he's the real account owner and not the other guy?