Live data from Hacker News

Facebook Asking for Some New Users' Email Passwords

thedailybeast.com

191–200 of 377 posts

Re: Facebook Asking for Some New Users' Email Passwords

#191

Earlier quoted context omitted.

LinkedIn has been doing this for years. It's the reason why I don't use it (and the spam they send is the reason why everybody hates them).

You mean emails? I've managed to turn them all off; if that doesn't work, you can file a complaint with the EU who have strict laws against e-mail spam, and the requirement to unsubscribe with as few actions as possible.

Yeah i've managed to stop all emails with my active LI account, they do occasionally add stuff that triggers them again so I just go into the settings and they're gone.

LI are awful for many reasons, but they do honour these things.

Re: Facebook Asking for Some New Users' Email Passwords

#193
post #66

All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...

wait, Plaid mines my transaction history? I assumed they made all their money from API customers paying fees. Is this true?

I haven't heard any reports of Plaid doing bad stuff with user transaction data, so I suspect there's a bit of paranoia in the comments here.

On the other hand, there's an underlying (and valid) concern that handing over bank credentials to a third party is risky and, even assuming good faith from Plaid, they have to store passwords on their servers somehow (probably encrypted). Since they make money from integrations with startups/big banks, there is definitely a conflict of interest between keeping user credentials safe and growing their revenue.

I think as a whole, relying on a modern company which specializes in authentication is better than trusting that thousands of app developers, some of which might big legacy banks with woefully understaffed IT departments, will keep your credentials safe. I'm aware that I'm more optimistic than most people in this thread (and on HN) though.

Here's a stackexchange question with some good discussion about Plaid security:

https://security.stackexchange.com/questions/198005/is-plaid...

Here's a github issue on Plaid's repo, showing that they are at least considering oauth on their roadmap:

https://github.com/plaid/link/issues/68

And here's Plaid's page on security, which is frankly short and a bit vague:

https://plaid.com/security/

Re: Facebook Asking for Some New Users' Email Passwords

#194
post #65

Earlier quoted context omitted.

Swedish payment processor Klarna does something similar to this as well. If bying something through the platform by direct bank transfer you are asked to sign to your bank to accept the payment using BankID [0], which is normal. What is not normal is that they grab your personal identification number and send a login request using BankID before you open your app. When authenticating the login you authorize one of Kla…

POLi in Australia also asks for your bank username and password, logs into your bank's online portal, and performs a bank transfer on your behalf; which is of course in violation of the bank's policies. It's truly insane, if I see any company accepting payment via POLi it's instant verification the company in question is clueless and that I should avoid using their services whenever possible, because they have zero i…

> if I see any company accepting payment via POLi it's instant verification the company in question is clueless and that I should avoid using their services whenever possible, because they have zero idea about security.

They just don't care; if something happens, people (including the press) won't really blame Microsoft or Qantas, so they don't have an incentive to vet those payment systems.

Re: Facebook Asking for Some New Users' Email Passwords

#195
It’s interesting to note, that in order for a feature or capability to be implemented, it has to provide value to the end user. So at the planing phase of this feature, didn’t anyone in their right mind thought that this was a bad idea. Given the current situation that Facebook (Fakebook) is in with security missteps why even invest time and money just to hope that users (at least the ones that are concerned) won’t complain. Hope it’s not a strategy.

Re: Facebook Asking for Some New Users' Email Passwords

#196
post #151

All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...

> a service where millions of people are giving their banking credentials so some random startup can mine your transaction data Wow, that's insane. I didn't think I'd ever be happy that all banks here in Brazil require you to install an invasive piece of software to validate your computer before allowing you to use online banking, which as far as I can see makes that sort of business model non-viable here.

That's equally as bad for the consumer.

Re: Facebook Asking for Some New Users' Email Passwords

#197
post #137

Earlier quoted context omitted.

That's exactly why they spend that much money. They know you can be submitted. They want tech talent. Not revolutionists. It's a rough world out there and it's better to get in line than lose your pot of gold. Doesn't make it right at all. But if you were that engineer, it's easier to say to yourself that you'll work your way up and change things the day you are in charge.

There's a book about the process by which this happens: https://www.goodreads.com/book/show/558867.Disciplined_Minds > Many professionals set out to make a contribution to society and add meaning to their lives. Yet our system of professional education and employment abusively inculcates an acceptance of politically subordinate roles in which professionals typically do not make a significant difference.

The book Moral Mazes also deals with this topic.

Re: Facebook Asking for Some New Users' Email Passwords

#198
post #183
post #72

Earlier quoted context omitted.

Perhaps a GDPR takeout request could answer this? Provided they’re doing things by the book.

Klarna shits on GDPR and giggles while doing so. Ive been asking them singe GDPR took effect to provide me with all details they have about me, and to delete my account. Not even a response. They claim "financial institutions" are exempt due to money laundering laws. That I understand, financial transactions they can keep, but I know a friend works there, they dont only keep financial transactions, they keep data of…

Have you sent a complaint to the regulator? At least the Portuguese data protection commission is quite responsive, a clear email containing all the information I could gather was enough to trigger investigations, which resulted in warnings and even a couple of fines.

Re: Facebook Asking for Some New Users' Email Passwords

#200
post #67

I just don't understand how this gets implemented without someone speaking up and saying "hey, wait, isn't this an insane thing to do?". I would guess it's some combination of the complainers being ignored, and people at a higher level thinking "well we're doing this in a secure way, as long as the user trusts us, and why wouldn't they trust us, we're Facebook!".

Developers did it for whatever reason.
Post reply on HN