Live data from Hacker News

Facebook Says Hackers Stole Detailed Personal Data from 14M People

bloomberg.com

51–60 of 217 posts

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#52
post #6

This is why I hate not having custom security questions from Banks. What is my fathers middle name? Well, if you have facebook and he puts it up there you can find out. I have no control over that. I could start using fake answers but trying to remember the fake answers vs real answers is tough. Whereas when I get a custom question I have a custom answer that I will always remember. Such as made up on the spot Name o…

PSA: Woah.wait. I just thought since personal data of about ~30 million people was leaked, most of them would be having Gmail accounts. So, isn't Gmail under threat too? I think GOOGLE should also issue an advisory asking people to change their security questions. Did I miss something?

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#53

Earlier quoted context omitted.

I used to use real answers but then wised up and switched to random 16-character responses. I wish there was a way to find out which services I’m vulnerable on due to my stupidly using real data, without attempting to do a password reset on all of my online accounts.

> wised up and switched to random 16-character responses As an earlier comment pointed out [1], random responses to security questions are a bad idea. I've personally tested this by entering a random security answer, calling the service, saying I forgot my password and entered gibberish as my security answer, and being let through. I presume technically-savvy people think this is more secure; if I can guess that, an…

I’d love to know which businesses have such an asinine policy. Name and shame! They are basically allowing a password reset with zero authentication.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#54

Facebook posting: https://newsroom.fb.com/news/2018/10/update-on-security-issu... Check if you are affected here: https://www.facebook.com/help/securitynotice (posting because it took 10+ mins to find it - many media outlets are not linking directly to it)

They should not require you to log in to their site to look up whether they have victimized you. I used to have a FB account but threw the random password away. Was I affected? No way to know?

Not to mention those of us with deleted Facebook accounts. It looks like I’m not affected but to anyone who had an account during those dates and deleted it since, how do they find out?

Yet another reason they should email affected users, guess they care more about not publicizing bad information than taking responsibility.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#55

Facebook posting: https://newsroom.fb.com/news/2018/10/update-on-security-issu... Check if you are affected here: https://www.facebook.com/help/securitynotice (posting because it took 10+ mins to find it - many media outlets are not linking directly to it)

They should not require you to log in to their site to look up whether they have victimized you. I used to have a FB account but threw the random password away. Was I affected? No way to know?

I guess they may be concerned with unauthenticated users checking if others are compromised.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#56

Earlier quoted context omitted.

They should not require you to log in to their site to look up whether they have victimized you. I used to have a FB account but threw the random password away. Was I affected? No way to know?

Not to mention those of us with deleted Facebook accounts. It looks like I’m not affected but to anyone who had an account during those dates and deleted it since, how do they find out? Yet another reason they should email affected users, guess they care more about not publicizing bad information than taking responsibility.

They explicitly state they will email impacted users.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#58

Earlier quoted context omitted.

I use KeePass for password management and the way I handle this is I generate a random string for each security question answer, then just include it in the Notes field of the entry.

People are social engineering a random string when talking to customer care. The attacker says “Ah, a bunch of random characters, do I have to say it?” or even worse I have had a customer service rep look at it, laugh and say never mind. I use “batteryhorsestaple” type of passwords stored in a password manager for the security questions. Those are easy to say over the phone and more resistant to social engineering.

How about "donotgiveoutoverthephone"?

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#60
post #6

This is why I hate not having custom security questions from Banks. What is my fathers middle name? Well, if you have facebook and he puts it up there you can find out. I have no control over that. I could start using fake answers but trying to remember the fake answers vs real answers is tough. Whereas when I get a custom question I have a custom answer that I will always remember. Such as made up on the spot Name o…

[deleted]
Post reply on HN