Live data from Hacker News

Facebook Says Hackers Stole Detailed Personal Data from 14M People

bloomberg.com

171–180 of 217 posts

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#171
post #161

Facebook posting: https://newsroom.fb.com/news/2018/10/update-on-security-issu... Check if you are affected here: https://www.facebook.com/help/securitynotice (posting because it took 10+ mins to find it - many media outlets are not linking directly to it)

How do I check if I've deleted Facebook? Does deleting Facebook mean I no longer have a right to know if my data was breached while I was a member?

What if I never signed up. I am sure they know about me. Wonder if there is a way to request that information from them...

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#172
post #67

Earlier quoted context omitted.

People are social engineering a random string when talking to customer care. The attacker says “Ah, a bunch of random characters, do I have to say it?” or even worse I have had a customer service rep look at it, laugh and say never mind. I use “batteryhorsestaple” type of passwords stored in a password manager for the security questions. Those are easy to say over the phone and more resistant to social engineering.

>The attacker says “Ah, a bunch of random characters, do I have to say it? The vast majority of users aren't using random characters, so how would they know to say that to begin with? Are you implying they try that line, idk, 10,000 times until it (maybe) works?

one idea:

attacker accesses recovery answers for site A. Sees that it is random characters. Attacker has access to site A.

Attacker phones sites B,C,D and E, trys social engineering. Attacker now has access to site B,C,D,E also.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#173
post #67

Earlier quoted context omitted.

People are social engineering a random string when talking to customer care. The attacker says “Ah, a bunch of random characters, do I have to say it?” or even worse I have had a customer service rep look at it, laugh and say never mind. I use “batteryhorsestaple” type of passwords stored in a password manager for the security questions. Those are easy to say over the phone and more resistant to social engineering.

>The attacker says “Ah, a bunch of random characters, do I have to say it? The vast majority of users aren't using random characters, so how would they know to say that to begin with? Are you implying they try that line, idk, 10,000 times until it (maybe) works?

Nah, it would go like this:

Support: what is your fathers middle name?

Hacker: Michael

Support: sorry that is wrong

Hacker: oh shoot, I forget I always put the incorrect information in this one... i can't remember, did I put a fake name or random characters? Or was this the one I put a bunch of words into?

Support: yeah, it looks like random characters... let's move on

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#174
post #6

This is why I hate not having custom security questions from Banks. What is my fathers middle name? Well, if you have facebook and he puts it up there you can find out. I have no control over that. I could start using fake answers but trying to remember the fake answers vs real answers is tough. Whereas when I get a custom question I have a custom answer that I will always remember. Such as made up on the spot Name o…

It's possibly even worse than that.

I read a comment on HN that they decided to use a random word like "banana" as the answer to a security question like "What's your mother's maiden name?" Within a couple of days, the bank called his house and spoke with a different relative to get the real answer.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#175

Earlier quoted context omitted.

People are social engineering a random string when talking to customer care. The attacker says “Ah, a bunch of random characters, do I have to say it?” or even worse I have had a customer service rep look at it, laugh and say never mind. I use “batteryhorsestaple” type of passwords stored in a password manager for the security questions. Those are easy to say over the phone and more resistant to social engineering.

How about "donotgiveoutoverthephone"?

I like the idea of doing this plus the random characters.

"identity theft high risk 2fZMbjL1lLZgnS8La"

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#176

Earlier quoted context omitted.

I use KeePass for password management and the way I handle this is I generate a random string for each security question answer, then just include it in the Notes field of the entry.

I don't understand what this buys you. If you have access to your password vault, why do you need the security questions? If you lose access to the vault, don't you lose the account?

The problem is that when someone claims to be you and says they've lost your password, the security questions are sometimes the only thing preventing the customer service rep from letting them bypass the password entirely.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#177
Never been a member, but I do receive regular notification emails from a Fb account/person I don't know, and an account I've never had anything to do with.

Yesterday after news of stolen data emerges, I received a "Facebook password reset" email sent to my gmail address. I ignore all and filter as spam, but sometimes I see them. The email headers do show the source is facebook.

Seems like Facebook allows new account sign up from unverified email addresses. That's a flaw in their policy against spam and abuse, making these hacking events worse when they happen. They need to use activation codes in the email used to sign up with.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#178
post #164
post #134

Earlier quoted context omitted.

> This means the credentials from the original implementation of said feature weren't locked down to only data available from your viewable profile. Yeah, that's the entire security incident. So are you saying you expect software companies to never have security incidents? Now that's ridiculous.

Why is that ridiculous?

Let me ask you this: Have you done any programming yourself?

Facebook has some of the best information security researchers, takes bug bounty seriously, and they have got very low hacks compared to the effort hackers put to hack it.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#179
I still think that facebook can be tremendously useful, even if I unfollowed everyone and have zero posts (mostly to see events, access facebook-homepages, let people find my email address or just occasionally tell someone to send me an email instead of writing on messenger) - but heck, this latest breach is a bit too much to swallow.

Re: Facebook Says Hackers Stole Detailed Personal Data from 14M People

#180
post #171
post #161

Earlier quoted context omitted.

How do I check if I've deleted Facebook? Does deleting Facebook mean I no longer have a right to know if my data was breached while I was a member?

What if I never signed up. I am sure they know about me. Wonder if there is a way to request that information from them...

Yes they do, it's called a shadow profile[1].

If you're in Europe you might have some some recourse (GDPR and such), but if you're from the US you are most likely out of luck.

Regardless, Facebook might have a detailed profile on you but not know your name. I doubt there is much you can do.

[1]: https://theconversation.com/shadow-profiles-facebook-knows-a...

Post reply on HN