Live data from Hacker News

Facebook Says Hackers Stole Detailed Personal Data from 14M People

bloomberg.com

101–110 of 217 posts

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#101

Facebook posting: https://newsroom.fb.com/news/2018/10/update-on-security-issu... Check if you are affected here: https://www.facebook.com/help/securitynotice (posting because it took 10+ mins to find it - many media outlets are not linking directly to it)

the best way to keep your passwords secure is the old fashioned way. Write them down and put them in a lock box. I only access my financial information from one computer. Perhaps I am paranoid.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#102
post #34

Facebook posting: https://newsroom.fb.com/news/2018/10/update-on-security-issu... Check if you are affected here: https://www.facebook.com/help/securitynotice (posting because it took 10+ mins to find it - many media outlets are not linking directly to it)

FB should timestamp these articles. It happened a couple of weeks ago, or is this new news?

Everybody should timestamp all articles.

People don't want to because they want their content to be "evergreen" and they think that if there's a date that's more than a year or so old, people will disregard / discount the content. So by default many blog CMSs default to not showing the date of any articles.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#103

Earlier quoted context omitted.

> wised up and switched to random 16-character responses As an earlier comment pointed out [1], random responses to security questions are a bad idea. I've personally tested this by entering a random security answer, calling the service, saying I forgot my password and entered gibberish as my security answer, and being let through. I presume technically-savvy people think this is more secure; if I can guess that, an…

I’d love to know which businesses have such an asinine policy. Name and shame! They are basically allowing a password reset with zero authentication.

Company policy wouldn't matter as much as just getting the wrong customer service rep that is trying to be a bit too "helpful".

In social engineering, it is common to call back multiple times looking for a gullible customer service rep. Even using a recording of a crying baby in the background to Garner sympathy is something I've seen done.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#104
Interesting trend I'm noticing with Facebook data controversies: 3rd parties are exploiting Facebooks connectedness to exponentially scale the # of accounts targeted by an attack.

Both Cambridge Analytica and these hackers were able to launch a successful attack on a relatively small number of accounts and through Facebook's graph like network were able to leverage the initial attack to affect more people.

Social networks mirror real life networks; they can be attacked with virus like tendencies.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#105
post #50

Earlier quoted context omitted.

> I assume Facebook has a lot of smart people working on security. I am not willing to roll the dice on that assumption.

I am. I know a bunch of them personally. They are definitely the some of the best security people I know. They just have a really hard problem to solve. If you think about it, a breach of 30 million accounts out of 2 billion ain’t that bad.

> a breach of 30 million accounts out of 2 billion ain’t that bad

That we know of. These sorts of leaks always seem to end up having a much wider impact than initially reported.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#106
post #64
post #17

Earlier quoted context omitted.

I do exactly the same. Big pain the few times I've had to read over the phone a giant randomized string, but the phone reps always seem to think it's funny.

Use a Gasser password generator, like the one in Multics[1], to make password that are easier to pronounce, but still long and complex enough to offer some value as security challenge answers. You can read 'mettlograter' or 'donetrapalyn' over the phone as easily as you can type them, and they're much better than '/1a!P:l3', which has approximately the same complexity. [1] https://multicians.org/thvv/gpw-js.html

For security questions, to avoid social engineering, you are better off using real, but incorrect answers and saving those. So for favorite food, put brocolli instead of your actual favorite food and rather than nonsensical answers.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#108
post #57

What's the most sci-fi worst case scenario that could come of this?

Public collectively shrugs, sites get hacked all the time and nothing bad ever happens to them, so it's just people getting worked up over nothing.

I consider that pretty scary, at least.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#109
post #9

That's one of the numerous reasons I'll never use fb as a payment or ecommerce platform when they launch these products.

I doubt other payment or ecommerce platforms are any more secure. Given its size, I assume Facebook has a lot of smart people working on security. And they still screw it up. How are smaller platforms, who can't attract or pay for the very best talent, going to do any better (other than by being smaller targets, I guess)?

> How are smaller platforms, who can't attract or pay for the very best talent, going to do any better

Well, they could just not collect as much data?

Post reply on HN