Facebook posting: https://newsroom.fb.com/news/2018/10/update-on-security-issu... Check if you are affected here: https://www.facebook.com/help/securitynotice (posting because it took 10+ mins to find it - many media outlets are not linking directly to it)
How do I check if I've deleted Facebook? Does deleting Facebook mean I no longer have a right to know if my data was breached while I was a member?
Facebook Says Hackers Stole Detailed Personal Data from 14M People
171–180 of 217 posts
Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People
#172Earlier quoted context omitted.
People are social engineering a random string when talking to customer care. The attacker says “Ah, a bunch of random characters, do I have to say it?” or even worse I have had a customer service rep look at it, laugh and say never mind. I use “batteryhorsestaple” type of passwords stored in a password manager for the security questions. Those are easy to say over the phone and more resistant to social engineering.
>The attacker says “Ah, a bunch of random characters, do I have to say it? The vast majority of users aren't using random characters, so how would they know to say that to begin with? Are you implying they try that line, idk, 10,000 times until it (maybe) works?
attacker accesses recovery answers for site A. Sees that it is random characters. Attacker has access to site A.
Attacker phones sites B,C,D and E, trys social engineering. Attacker now has access to site B,C,D,E also.
Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People
#173Earlier quoted context omitted.
People are social engineering a random string when talking to customer care. The attacker says “Ah, a bunch of random characters, do I have to say it?” or even worse I have had a customer service rep look at it, laugh and say never mind. I use “batteryhorsestaple” type of passwords stored in a password manager for the security questions. Those are easy to say over the phone and more resistant to social engineering.
>The attacker says “Ah, a bunch of random characters, do I have to say it? The vast majority of users aren't using random characters, so how would they know to say that to begin with? Are you implying they try that line, idk, 10,000 times until it (maybe) works?
Support: what is your fathers middle name?
Hacker: Michael
Support: sorry that is wrong
Hacker: oh shoot, I forget I always put the incorrect information in this one... i can't remember, did I put a fake name or random characters? Or was this the one I put a bunch of words into?
Support: yeah, it looks like random characters... let's move on
Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People
#174This is why I hate not having custom security questions from Banks. What is my fathers middle name? Well, if you have facebook and he puts it up there you can find out. I have no control over that. I could start using fake answers but trying to remember the fake answers vs real answers is tough. Whereas when I get a custom question I have a custom answer that I will always remember. Such as made up on the spot Name o…
I read a comment on HN that they decided to use a random word like "banana" as the answer to a security question like "What's your mother's maiden name?" Within a couple of days, the bank called his house and spoke with a different relative to get the real answer.
Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People
#175Earlier quoted context omitted.
People are social engineering a random string when talking to customer care. The attacker says “Ah, a bunch of random characters, do I have to say it?” or even worse I have had a customer service rep look at it, laugh and say never mind. I use “batteryhorsestaple” type of passwords stored in a password manager for the security questions. Those are easy to say over the phone and more resistant to social engineering.
How about "donotgiveoutoverthephone"?
"identity theft high risk 2fZMbjL1lLZgnS8La"
Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People
#176Earlier quoted context omitted.
I use KeePass for password management and the way I handle this is I generate a random string for each security question answer, then just include it in the Notes field of the entry.
I don't understand what this buys you. If you have access to your password vault, why do you need the security questions? If you lose access to the vault, don't you lose the account?
Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People
#177Yesterday after news of stolen data emerges, I received a "Facebook password reset" email sent to my gmail address. I ignore all and filter as spam, but sometimes I see them. The email headers do show the source is facebook.
Seems like Facebook allows new account sign up from unverified email addresses. That's a flaw in their policy against spam and abuse, making these hacking events worse when they happen. They need to use activation codes in the email used to sign up with.
Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People
#178Earlier quoted context omitted.
> This means the credentials from the original implementation of said feature weren't locked down to only data available from your viewable profile. Yeah, that's the entire security incident. So are you saying you expect software companies to never have security incidents? Now that's ridiculous.
Why is that ridiculous?
Facebook has some of the best information security researchers, takes bug bounty seriously, and they have got very low hacks compared to the effort hackers put to hack it.
Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People
#179Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People
#180Earlier quoted context omitted.
How do I check if I've deleted Facebook? Does deleting Facebook mean I no longer have a right to know if my data was breached while I was a member?
What if I never signed up. I am sure they know about me. Wonder if there is a way to request that information from them...
If you're in Europe you might have some some recourse (GDPR and such), but if you're from the US you are most likely out of luck.
Regardless, Facebook might have a detailed profile on you but not know your name. I doubt there is much you can do.
[1]: https://theconversation.com/shadow-profiles-facebook-knows-a...