Live data from Hacker News

Facebook Asking for Some New Users' Email Passwords

thedailybeast.com

71–80 of 377 posts

Re: Facebook Asking for Some New Users' Email Passwords

#72
post #65

Earlier quoted context omitted.

Swedish payment processor Klarna does something similar to this as well. If bying something through the platform by direct bank transfer you are asked to sign to your bank to accept the payment using BankID [0], which is normal. What is not normal is that they grab your personal identification number and send a login request using BankID before you open your app. When authenticating the login you authorize one of Kla…

I tried to find more information about this statement: "When authenticating the login you authorize one of Klarnas third parties to log into your bank account as you, allowing them to pull records of all your financial transactions, account statements etc.“ Do you have any source to verify this claim? That they can and do pull down this information. I would like to know if they really have all that information or not…

Perhaps a GDPR takeout request could answer this? Provided they’re doing things by the book.

Re: Facebook Asking for Some New Users' Email Passwords

#73
I noticed that when I was dating around it was extremely important that they could find my Facebook profile if I said I don't use Facebook much they would immediately respond with scepticism.

For that purpose alone I kept it.

And they have a point, it's easy to find out if someone is single or not via Facebook, and you are bound by your friends to be truthful.

I'm not single anymore, but I'm still curious, in those countries where everyone is not sleeping around with everyone what would replace Facebook?

Re: Facebook Asking for Some New Users' Email Passwords

#74
post #65

Earlier quoted context omitted.

Swedish payment processor Klarna does something similar to this as well. If bying something through the platform by direct bank transfer you are asked to sign to your bank to accept the payment using BankID [0], which is normal. What is not normal is that they grab your personal identification number and send a login request using BankID before you open your app. When authenticating the login you authorize one of Kla…

I tried to find more information about this statement: "When authenticating the login you authorize one of Klarnas third parties to log into your bank account as you, allowing them to pull records of all your financial transactions, account statements etc.“ Do you have any source to verify this claim? That they can and do pull down this information. I would like to know if they really have all that information or not…

I don't know if they do have it, but it is absolutely possible after the login. I saw it reported in an IT-security facebook group and made my own purchase from a site that use them (gottebiten.se), paying directly from bank account. The login was indeed done by a Klarna 3rd party using my ID number, and not from my device.

You have to confirm once more for the payment to be sent.

Re: Facebook Asking for Some New Users' Email Passwords

#75

I noticed that when I was dating around it was extremely important that they could find my Facebook profile if I said I don't use Facebook much they would immediately respond with scepticism. For that purpose alone I kept it. And they have a point, it's easy to find out if someone is single or not via Facebook, and you are bound by your friends to be truthful. I'm not single anymore, but I'm still curious, in those c…

>... everyone is not sleeping around with everyone...

wat?

Re: Facebook Asking for Some New Users' Email Passwords

#76
post #59
post #45

Earlier quoted context omitted.

Yeah, I'm starting to think that Google+ could really pick up new users if th-oh wait... right...

Google recognized that social networks are a liability and not an asset.

Youtube is a social network with lots of videos.

Only somewhat joking.

Re: Facebook Asking for Some New Users' Email Passwords

#77
post #72

Earlier quoted context omitted.

I tried to find more information about this statement: "When authenticating the login you authorize one of Klarnas third parties to log into your bank account as you, allowing them to pull records of all your financial transactions, account statements etc.“ Do you have any source to verify this claim? That they can and do pull down this information. I would like to know if they really have all that information or not…

Perhaps a GDPR takeout request could answer this? Provided they’re doing things by the book.

Klarna seems to be under investigation currently for not complying with the GDPR: https://www.insidescandinavianbusiness.com/article.php?id=37...

Re: Facebook Asking for Some New Users' Email Passwords

#78
post #67

I just don't understand how this gets implemented without someone speaking up and saying "hey, wait, isn't this an insane thing to do?". I would guess it's some combination of the complainers being ignored, and people at a higher level thinking "well we're doing this in a secure way, as long as the user trusts us, and why wouldn't they trust us, we're Facebook!".

Move fast and break things!

Re: Facebook Asking for Some New Users' Email Passwords

#79
post #59
post #45

Earlier quoted context omitted.

Yeah, I'm starting to think that Google+ could really pick up new users if th-oh wait... right...

Google recognized that social networks are a liability and not an asset.

Wonder if they would have recognized it if google+ was successful.

Re: Facebook Asking for Some New Users' Email Passwords

#80

All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...

In Australia, there’s POLi Payments, now owned by Australia Post, which gets you to enter your bank username and password, then impersonates you (https://www.polipayments.com/Security is their statement about it, and a substantial fraction of the text on that page is just flat-out lies). Naturally, doing so is entirely against the ToS of all the banks (including you now being liable for literally anything), and a few banks have publicly said “don’t use that” or similar, but they evidently tacitly support it, because I don’t imagine it would be hard for them to block.

I was incredulous when I first tried to use POLi Payments and realised how it worked—I ran away screaming, naturally. That entire business should be shut down with prejudice.

Post reply on HN