Live data from Hacker News

Facebook Asking for Some New Users' Email Passwords

thedailybeast.com

91–100 of 377 posts

Re: Facebook Asking for Some New Users' Email Passwords

#91

Earlier quoted context omitted.

It also implies saving passwords without hashing... Not good.

Sure, but is that not what an online password manager is? :P

If the on-line component goes anywhere beyond the ability to sync an opaque binary blob that only your local machines can decrypt and reencrypt, there's a problem there.

Re: Facebook Asking for Some New Users' Email Passwords

#92

Earlier quoted context omitted.

It also implies saving passwords without hashing... Not good.

Sure, but is that not what an online password manager is? :P

I want to believe that LastLass uses client side JS to decrypt based on your login credentials, not a plain text database.

Re: Facebook Asking for Some New Users' Email Passwords

#93
post #65

All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...

Swedish payment processor Klarna does something similar to this as well. If bying something through the platform by direct bank transfer you are asked to sign to your bank to accept the payment using BankID [0], which is normal. What is not normal is that they grab your personal identification number and send a login request using BankID before you open your app. When authenticating the login you authorize one of Kla…

>The scammers were ruled in the wrong, but the logins themselves were ruled to be an ok way of doing business.

This seems like something that the Riksdagen should step-in on. BankId was meant as validating a legal entity (I am who I say I am) and a third-party presenting that they are they are that legal entity (in this case, the person in question) would certainly seem to circumvent the intention behind that.

Re: Facebook Asking for Some New Users' Email Passwords

#94
post #67

I just don't understand how this gets implemented without someone speaking up and saying "hey, wait, isn't this an insane thing to do?". I would guess it's some combination of the complainers being ignored, and people at a higher level thinking "well we're doing this in a secure way, as long as the user trusts us, and why wouldn't they trust us, we're Facebook!".

Why is this insane? It's just asking. If you don't want to, don't give your pw to facebook. You make a proposition to an entity, they evaluate the risk-benefit and respond. Unless of course, you think adults are actually childiren and should be protected from themselves by the technocrats.

Ignoring their recent fail at logging passwords.

It has been established as minimal practice, that NO ONE should be asking you about your password. If this would become a normal, it would also make regular people more likely to give out their passwords.

And email is key to your online kingdom, so it's a big deal, if it gets compromised.

Re: Facebook Asking for Some New Users' Email Passwords

#97
post #67

I just don't understand how this gets implemented without someone speaking up and saying "hey, wait, isn't this an insane thing to do?". I would guess it's some combination of the complainers being ignored, and people at a higher level thinking "well we're doing this in a secure way, as long as the user trusts us, and why wouldn't they trust us, we're Facebook!".

People with any sense of ethics don't work at Facebook.

Re: Facebook Asking for Some New Users' Email Passwords

#98

I noticed that when I was dating around it was extremely important that they could find my Facebook profile if I said I don't use Facebook much they would immediately respond with scepticism. For that purpose alone I kept it. And they have a point, it's easy to find out if someone is single or not via Facebook, and you are bound by your friends to be truthful. I'm not single anymore, but I'm still curious, in those c…

> it's easy to find out if someone is single or not via Facebook

That was many, many years ago. Ever since, they've been tightening up privacy defaults, and now when checking out that person you met, the best you'll get is a profile picture and a list of mutual friends. Everything else tends to be locked down by default for non-friends, and Facebook keeps regularly reminding people posting widely that they could tighten their posting range.

Whether that's a good or bad evolution depends on one's use cases and the views on whether being able to do little background checks on other people is OK or not.

Re: Facebook Asking for Some New Users' Email Passwords

#99
post #65

All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...

Swedish payment processor Klarna does something similar to this as well. If bying something through the platform by direct bank transfer you are asked to sign to your bank to accept the payment using BankID [0], which is normal. What is not normal is that they grab your personal identification number and send a login request using BankID before you open your app. When authenticating the login you authorize one of Kla…

Saltedge build their whole business on gathering bank account password and provide "API" access to transactions.

https://www.saltedge.com/

Post reply on HN