Live data from Hacker News

Facebook Says Hackers Stole Detailed Personal Data from 14M People

bloomberg.com

61–70 of 217 posts

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#61
So: “We collected detailed personal data on 14M people, much of it not directly given to us by those people. This created an enticing target for data thieves. Despite our obscene profits from data, we disproportionately reinvested in protection of this sensitive information. Since we lacked security and have a unique ability to hold more data in one place than anyone else, thieves got more of your data than they could have dreamed of.”

Did I miss anything?

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#62

Logged in today and found: "[name], we have more information about the security incident we discovered on September 25, 2018. An unauthorized third party accessed your name, email address and phone number. We acted quickly to secure the site and took action to protect your account, and we're working closely with law enforcement to address the incident." Ridiculous.

Why is that ridiculous?

Here are the facts:

1. A software company had a security incident.

2. They urgently resolved the issue.

3. They looked into who was impacted, and sent customized notifications letting people know how they were impacted.

None of this behavior is ridiculous. It's quite responsible. What would you expect to happen differently?

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#64
post #17

Earlier quoted context omitted.

I use KeePass for password management and the way I handle this is I generate a random string for each security question answer, then just include it in the Notes field of the entry.

I do exactly the same. Big pain the few times I've had to read over the phone a giant randomized string, but the phone reps always seem to think it's funny.

Use a Gasser password generator, like the one in Multics[1], to make password that are easier to pronounce, but still long and complex enough to offer some value as security challenge answers.

You can read 'mettlograter' or 'donetrapalyn' over the phone as easily as you can type them, and they're much better than '/1a!P:l3', which has approximately the same complexity.

[1] https://multicians.org/thvv/gpw-js.html

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#65

Facebook posting: https://newsroom.fb.com/news/2018/10/update-on-security-issu... Check if you are affected here: https://www.facebook.com/help/securitynotice (posting because it took 10+ mins to find it - many media outlets are not linking directly to it)

I forget what the text looks like in your second link when you're not logged in but after I logged in the verification text appears as follows:

""" Is my Facebook account impacted by this security issue? Based on what we've learned so far, your Facebook account has not been impacted by this security incident. If we find more Facebook accounts were impacted, we will reset their access tokens and notify those accounts. """

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#66
post #34

Facebook posting: https://newsroom.fb.com/news/2018/10/update-on-security-issu... Check if you are affected here: https://www.facebook.com/help/securitynotice (posting because it took 10+ mins to find it - many media outlets are not linking directly to it)

FB should timestamp these articles. It happened a couple of weeks ago, or is this new news?

This is new, particularly the details around search history and location data being stolen, as of an hour ago.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#67

Earlier quoted context omitted.

I use KeePass for password management and the way I handle this is I generate a random string for each security question answer, then just include it in the Notes field of the entry.

People are social engineering a random string when talking to customer care. The attacker says “Ah, a bunch of random characters, do I have to say it?” or even worse I have had a customer service rep look at it, laugh and say never mind. I use “batteryhorsestaple” type of passwords stored in a password manager for the security questions. Those are easy to say over the phone and more resistant to social engineering.

>The attacker says “Ah, a bunch of random characters, do I have to say it?

The vast majority of users aren't using random characters, so how would they know to say that to begin with? Are you implying they try that line, idk, 10,000 times until it (maybe) works?

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#68
post #6

This is why I hate not having custom security questions from Banks. What is my fathers middle name? Well, if you have facebook and he puts it up there you can find out. I have no control over that. I could start using fake answers but trying to remember the fake answers vs real answers is tough. Whereas when I get a custom question I have a custom answer that I will always remember. Such as made up on the spot Name o…

I use KeePass for password management and the way I handle this is I generate a random string for each security question answer, then just include it in the Notes field of the entry.

I don't understand what this buys you. If you have access to your password vault, why do you need the security questions? If you lose access to the vault, don't you lose the account?

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#69
post #62

Logged in today and found: "[name], we have more information about the security incident we discovered on September 25, 2018. An unauthorized third party accessed your name, email address and phone number. We acted quickly to secure the site and took action to protect your account, and we're working closely with law enforcement to address the incident." Ridiculous.

Why is that ridiculous? Here are the facts: 1. A software company had a security incident. 2. They urgently resolved the issue. 3. They looked into who was impacted, and sent customized notifications letting people know how they were impacted. None of this behavior is ridiculous. It's quite responsible. What would you expect to happen differently?

Well, let's see. A feature used to view profile information had a vulnerability that allowed an attacker to get my phone number. My phone number isn't even listed on my profile.

This means the credentials from the original implementation of said feature weren't locked down to only data available from your viewable profile.

While my phone number may be available elsewhere outside of FB, I only have it tied to my account as a password reset contact.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#70

Earlier quoted context omitted.

I use KeePass for password management and the way I handle this is I generate a random string for each security question answer, then just include it in the Notes field of the entry.

People are social engineering a random string when talking to customer care. The attacker says “Ah, a bunch of random characters, do I have to say it?” or even worse I have had a customer service rep look at it, laugh and say never mind. I use “batteryhorsestaple” type of passwords stored in a password manager for the security questions. Those are easy to say over the phone and more resistant to social engineering.

Security Answer: HelpAnImposterIsTryingToHackMe
Post reply on HN