Live data from Hacker News

Facebook Asking for Some New Users' Email Passwords

thedailybeast.com

1–10 of 377 posts

Re: Facebook Asking for Some New Users' Email Passwords

#3

Title seems misleading. Per the article it seems they demand email confirmation, but merely offer to access your email for you in order to accomplish that. (This is not a defense of Facebook's actions here)

Ok, we'll s/demanding/asking for/ above.

Re: Facebook Asking for Some New Users' Email Passwords

#4

Title seems misleading. Per the article it seems they demand email confirmation, but merely offer to access your email for you in order to accomplish that. (This is not a defense of Facebook's actions here)

Yeah and they surely won't use those passwords for anything else, like the phone numbers which they promised would be used for 2FA only.

Re: Facebook Asking for Some New Users' Email Passwords

#6

Title seems misleading. Per the article it seems they demand email confirmation, but merely offer to access your email for you in order to accomplish that. (This is not a defense of Facebook's actions here)

> Per the article it seems they demand email confirmation, but merely offer to access your email for you in order to accomplish that.

It's definitely a dark pattern though. And Facebook rarely seems content to only use data for the purpose they advertise when asking for it. For instance, there was an article recently that proved they were using phone numbers collected for 2FA to do ad-targeting as well.

Re: Facebook Asking for Some New Users' Email Passwords

#8
https://www.axios.com/facebook-will-stop-asking-new-users-fo...

Facebook told Axios that "a very small group of people have the option of entering their email password to verify their account when they sign up for Facebook," but noted that people could choose instead to confirm their account with a code or link sent to their phone or email.

"That said, we understand the password verification option isn't the best way to go about this, so we are going to stop offering it,” the company said in a statement.

Those being asked for their e-mail passwords were users who listed an e-mail address that doesn't use the secure OAuth protocol, which allows users to verify their identity to a third party without sharing their passwords.

Post reply on HN