Live data from Hacker News

Facebook Asking for Some New Users' Email Passwords

thedailybeast.com

51–60 of 377 posts

Re: Facebook Asking for Some New Users' Email Passwords

#51

All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...

Plaid might be my least favorite company ever. It's such a privacy nightmare and they do not even tell you basic information about what you are sharing (or how to revoke sharing rights) going through their typical flow on some random fintech app. If you look at their website, you could be giving away just the bank and routing number, or potentially your entire bank transaction history, balance, identity information,…

> Or sued.

Except that like all no-longer-a-startup companies who can make your life a living nightmare if they are not spot-on perfect with their security, Plaid have slapped a mandatory, binding arbitration clause in their user agreement.

Thus, if they do drop the ball in some catastrophic way, your ability to recover anything beyond a firm handshake and maybe an "oops, our bad" on the way to an "Our Incredible Journey" blog post is on the same level of probability as my winning a gold medal in curling at the Olympics: it statistically could happen, but very likely won't.

Re: Facebook Asking for Some New Users' Email Passwords

#52

Earlier quoted context omitted.

Mint legitmatized that authorization flow years before Plaid came around and the banks decided that was the best way to move forward instead of adopting something like an oauth2 flow.

I remember when Mint first came around, and a coworker was telling me about how cool it was. I started completing the the signup process, but I stopped cold once I realized they needed to be provided account credentials from my bank. Never completed it, and never went back to it. I never thought it would last as long as it had. I guess I gave the public too much credit.

The general public is extremely myopic and lazy. They will hand over anything you ask for if it means they have to do less work in the short-term.

Convenience trumps all. It's how we've ended up with people voluntarily purchasing, maintaining, carrying around at all times, keeping charged and powered on, their own personal surveillance devices running heaps of software they have no control over.

Re: Facebook Asking for Some New Users' Email Passwords

#53
post #7

This must be part of Zuckerberg's new pro-privacy makeover. Maybe they can also scan users' e-mails for "suicidal ideation" and have their swatting algorithm send in the police to "protect" them.

It is perhaps the way you've presented the argument that is generating downvotes, but I fail to see how this is outside the realm of Facebook's pursuits given past behaviour and current activity. Or is it that people would support this use because of a 'noble intention?' (ends justify means)

Would Facebook then start making calls to the police for welfare checks when a user stops using Facebook without closing their account? Surely, something must have happened to the user if they stopped logging in frequently. After all, users don't just stop using the service.

Re: Facebook Asking for Some New Users' Email Passwords

#54

Earlier quoted context omitted.

It also implies saving passwords without hashing... Not good.

Sure, but is that not what an online password manager is? :P

The data is encrypted with a key that you have not one that the server has which is much much better. If someone breaks in to the server they are not able to very quickly grab all the data. They have to be able to deploy some malware on the server and allow it to run for a while to collect passwords.

Re: Facebook Asking for Some New Users' Email Passwords

#56

https://www.axios.com/facebook-will-stop-asking-new-users-fo... Facebook told Axios that "a very small group of people have the option of entering their email password to verify their account when they sign up for Facebook," but noted that people could choose instead to confirm their account with a code or link sent to their phone or email. "That said, we understand the password verification option isn't the best way…

And so what if they are going to stop? Why were they offering it in the first place? It is such an obviously terrible idea

'move fast and break things' ?

Re: Facebook Asking for Some New Users' Email Passwords

#57

https://www.axios.com/facebook-will-stop-asking-new-users-fo... Facebook told Axios that "a very small group of people have the option of entering their email password to verify their account when they sign up for Facebook," but noted that people could choose instead to confirm their account with a code or link sent to their phone or email. "That said, we understand the password verification option isn't the best way…

And so what if they are going to stop? Why were they offering it in the first place? It is such an obviously terrible idea

They did something similar around 2010 when they (repeatadly) asked users to enter their email address and password "to see if any of your contacts are on Facebook so you can connect with them" with a "don't sorry, we won't save your password" note next to it. What they didn't say was that they pulled in all of the user's contacts and added also them to their "super graph".

Re: Facebook Asking for Some New Users' Email Passwords

#58

Earlier quoted context omitted.

I remember when Mint first came around, and a coworker was telling me about how cool it was. I started completing the the signup process, but I stopped cold once I realized they needed to be provided account credentials from my bank. Never completed it, and never went back to it. I never thought it would last as long as it had. I guess I gave the public too much credit.

The general public is extremely myopic and lazy . They will hand over anything you ask for if it means they have to do less work in the short-term. Convenience trumps all. It's how we've ended up with people voluntarily purchasing, maintaining, carrying around at all times, keeping charged and powered on, their own personal surveillance devices running heaps of software they have no control over.

Counterpoint: Many people of the "general public" are at least vaguely aware of the fact that they're making risky decisions, but proceed regardless in order to reap the short-term rewards that you mention, calculating that the benefits are worth the hypothetical costs, and many of them will live and die having been right about making that tradeoff.

Re: Facebook Asking for Some New Users' Email Passwords

#59
post #45

Honest question - is it the time for a new social network already??

Yeah, I'm starting to think that Google+ could really pick up new users if th-oh wait... right...

Google recognized that social networks are a liability and not an asset.

Re: Facebook Asking for Some New Users' Email Passwords

#60

All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...

During demonetisation in India (2016), Mobile wallet startups threw the privacy out of window.

Paytm (India's largest e-Wallet), asked customers to enter their credit card details on their app on merchant's smartphone. I reported the security risk to them with a POC to their bounty hunting[1], they asked me to wait, removed the feature & the CEO told media that I was lying, there was never a security risk.

Mobiwik, read customer's SMS of bank transactions to inform its users which ATMs had cash.

[1]:https://abishekmuthian.com/paytm-says-to-me-that-its-pos-fea...

Post reply on HN