Live data from Hacker News

Facebook Says Hackers Stole Detailed Personal Data from 14M People

bloomberg.com

121–130 of 217 posts

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#121
post #6

This is why I hate not having custom security questions from Banks. What is my fathers middle name? Well, if you have facebook and he puts it up there you can find out. I have no control over that. I could start using fake answers but trying to remember the fake answers vs real answers is tough. Whereas when I get a custom question I have a custom answer that I will always remember. Such as made up on the spot Name o…

As a kid with a newspaper round I set up a bank account and didn’t know what it meant when I was asked for my mother’s maiden name, so made up an answer. Accidental security. It is a hard problem.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#122
post #108
post #57

What's the most sci-fi worst case scenario that could come of this?

Public collectively shrugs, sites get hacked all the time and nothing bad ever happens to them, so it's just people getting worked up over nothing. I consider that pretty scary, at least.

Oh come on. Mass blackmail, that'd be pretty cool. Or models trained on our behaviour, subtly affecting the market to make us do silly things purely for the enjoyment of some accidental bitcoin millionaire, never detectable by governmental or human-intution anomaly-detectors because all effects are below the noise level. Something cool like this must be going on somewhere, and I want to read a (non-fiction) book about it.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#123

Facebook posting: https://newsroom.fb.com/news/2018/10/update-on-security-issu... Check if you are affected here: https://www.facebook.com/help/securitynotice (posting because it took 10+ mins to find it - many media outlets are not linking directly to it)

the best way to keep your passwords secure is the old fashioned way. Write them down and put them in a lock box. I only access my financial information from one computer. Perhaps I am paranoid.

True but not relevant at all to the current discussion.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#125

I guess I don't really understand the frustration of some people. I do but I don't. I don't have a facebook account, or instagram, or any social media, haven't had one in many years. No one NEEDS to have one. I guess to me, if you don't want this info to be exposed, just don't have an account. Assume the worst can happen. This is not like other sites, I get that you're "trusting" them with your info, but you are will…

"No one NEEDS to have one. "

So what? That doesn't change a single thing. All you are doing with this line of thinking is blaming the victim. The fault here is Facebook's and the attacker's. No one else's.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#126
post #6

This is why I hate not having custom security questions from Banks. What is my fathers middle name? Well, if you have facebook and he puts it up there you can find out. I have no control over that. I could start using fake answers but trying to remember the fake answers vs real answers is tough. Whereas when I get a custom question I have a custom answer that I will always remember. Such as made up on the spot Name o…

Or just don't use facebook.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#127
post #18
post #9

Earlier quoted context omitted.

I doubt other payment or ecommerce platforms are any more secure. Given its size, I assume Facebook has a lot of smart people working on security. And they still screw it up. How are smaller platforms, who can't attract or pay for the very best talent, going to do any better (other than by being smaller targets, I guess)?

Visa and MasterCard seems to handle security ok.

This requires pretty loose definitions of OK, which, I guess, works out OK for Visa and MasterCard ?

Both systems experience what on the Web we'd consider a staggering level of problems. Fraud losses just in the UK for the card payment system exceed £500M per year. They're proud of themselves for catching about 60% by value of potential fraud. That is, people _tried_ to steal over a billion pounds each year, but only get away with £500M...

They use out-dated cryptography, they straight up lie to their partners, to customers and even to the courts. I trust them about as much as some random Etsy maker.

Now, my country's laws mean when Visa screws up, my bank, regulated by those laws, has to make me whole. And I'm a middle-aged white guy, so good old-fashioned unconscious bias means when I'm screaming at a regulator about my rights they listen.

But if I didn't have those laws, if I was an elderly black lady, I can expect that I'd be told it's not the payment card company, I must have secretly travelled to Hong Kong last weekend and bought $5000 of men's watches and so I have to pay for that transaction even if I have witnesses who say I never left... after all the computer says it was my card and how could that be wrong?

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#128
post #34

Earlier quoted context omitted.

FB should timestamp these articles. It happened a couple of weeks ago, or is this new news?

Everybody should timestamp all articles. People don't want to because they want their content to be "evergreen" and they think that if there's a date that's more than a year or so old, people will disregard / discount the content. So by default many blog CMSs default to not showing the date of any articles.

Facebook is not a small blog operator. They should view this as a professional communications medium.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#130

Earlier quoted context omitted.

I use KeePass for password management and the way I handle this is I generate a random string for each security question answer, then just include it in the Notes field of the entry.

People are social engineering a random string when talking to customer care. The attacker says “Ah, a bunch of random characters, do I have to say it?” or even worse I have had a customer service rep look at it, laugh and say never mind. I use “batteryhorsestaple” type of passwords stored in a password manager for the security questions. Those are easy to say over the phone and more resistant to social engineering.

Of course, if the customer service rep can see the plaintext, it's not particularly secure is it?
Post reply on HN