Live data from Hacker News

Facebook Asking for Some New Users' Email Passwords

thedailybeast.com

221–230 of 377 posts

Re: Facebook Asking for Some New Users' Email Passwords

#221

All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...

Before Plaid there was Yodlee which coordinated password harvesting from all the major financial institutions with their active partnership.

Re: Facebook Asking for Some New Users' Email Passwords

#222

All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...

Mint legitmatized that authorization flow years before Plaid came around and the banks decided that was the best way to move forward instead of adopting something like an oauth2 flow.

I use mint even now. I'm generally technically paranoid, and have just concluded mint is not actually that risky.

Here's why: 1. Most banking companies seem to have a much better security landscape than other places, including tracking where you're logging in from. Even with a password it won't be easy for a hacker to do stuff with my accounts. Almost any change or transaction triggers an email and sms alert too.

2. The main bank I have my money in, doesn't let you do transactions larger than 2000 in a day online, and even that is insured against fraud.

3. For credit card accounts, I have noticed that you actually can't do much with just an online account, except to pay the bill.

4. Mint is owned by Intuit and they know my tax details, most of which are far more important and guard-worthy anyways.

5. Also till now I've been a fairly poor guy with not much in my bank accounts. So I didn't worry too much about losing my cash since I didn't have much. If you have a lot of it, perhaps you need to be careful with such services.

Re: Facebook Asking for Some New Users' Email Passwords

#223
post #65

Earlier quoted context omitted.

Swedish payment processor Klarna does something similar to this as well. If bying something through the platform by direct bank transfer you are asked to sign to your bank to accept the payment using BankID [0], which is normal. What is not normal is that they grab your personal identification number and send a login request using BankID before you open your app. When authenticating the login you authorize one of Kla…

Wait, what? I use Klarna quite regularily and I assumed they were redirecting to my bank's website (in an iframe) where I would enter my credentials. I mean, the web form is even branded with my bank's logo and color scheme. If it's really the case that I was just giving my credentials to Klarna who then logged into my bank account on my behalf, I have been phished, there's no sugar coating this.

Even if it's an iframe, there's no way for a non webdev to confirm it so it's indistinguishable from phishing.

Re: Facebook Asking for Some New Users' Email Passwords

#224

All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...

Mint legitmatized that authorization flow years before Plaid came around and the banks decided that was the best way to move forward instead of adopting something like an oauth2 flow.

Mint was a copy of Yodlee. This stuff is old.

Re: Facebook Asking for Some New Users' Email Passwords

#225
On a somewhat related note, I recently added an external bank account to my E-trade account. They gave me two options for verifying it. The first was to make a small deposit into the external account (which they said would take several days to complete). The second option was to provide my bank account's credentials and they could verify it immediately. I chose the first option.

Re: Facebook Asking for Some New Users' Email Passwords

#226

How is this even implemented safely? The passwords have to be forwarded over to the email provider, so they are flying around log files, unsafe in the database. There's actually a programmer somewhere who can read all of them and put them in a text file and take them home.

In theory, the password doesn't have to be stored at all. I bet it's kept in some sort of job queue, so it might be stored in disk (e.g. Redis AOF), but even that could be avoided. Still, one has to wonder why do it at all, considering the simple alternative of sending a verification email, which was already implemented.

Isn't the motive to get the user's contact lists?

If there's an error isn't there a chance that the password leaks out into an error log somewhere?

Re: Facebook Asking for Some New Users' Email Passwords

#227

Earlier quoted context omitted.

I find it fascinating how big tech companies are intent on spending enormous sums of money seeking out the top tech talent in the world. Then rather than listen to them when they voice concerns they try to beat them down into submission. I get that if you worked at a company whose core mission is evil that you just have to accept that when you sign up, but there's no reason facebook needs to be make these active mora…

It is an authoritarian mentality fundamentally of "social order" - that they are beneath them so it is the "proper order" to obey. Above profitability even. You can see that bit of outright sadism with retail in particular but the pathology exists elsewhere. Rivals of Costco are angry with them for paying their employees more to get better motivated ones and less shrinkage - when if they think it is a waste of money…

> Rivals of Costco are angry with them for paying their employees more to get better motivated ones and less shrinkage - when if they think it is a waste of money be happy about it

Do you have a citation for this claim?

Re: Facebook Asking for Some New Users' Email Passwords

#228

https://www.axios.com/facebook-will-stop-asking-new-users-fo... Facebook told Axios that "a very small group of people have the option of entering their email password to verify their account when they sign up for Facebook," but noted that people could choose instead to confirm their account with a code or link sent to their phone or email. "That said, we understand the password verification option isn't the best way…

They shouldn't need to log in to the user's password account at all through OAuth or any other way!

A side problem with this is that if it's truly easier for the user than clicking on an emailed link, then users are going to expect that from all of us. So you have to do the sleazy shit or from the users' point of view you are "behind" and less good.

I wish there was some good way to educate the user to privacy dangers. I mean, we could make an online workshop but would have to support it by advertising because we would have to reach the people who don't realize there even could be a problem. And the people willing to drop $5 on it are the ones who don't need to (classic problem in education).

Re: Facebook Asking for Some New Users' Email Passwords

#229
post #137

Earlier quoted context omitted.

That's exactly why they spend that much money. They know you can be submitted. They want tech talent. Not revolutionists. It's a rough world out there and it's better to get in line than lose your pot of gold. Doesn't make it right at all. But if you were that engineer, it's easier to say to yourself that you'll work your way up and change things the day you are in charge.

There's a book about the process by which this happens: https://www.goodreads.com/book/show/558867.Disciplined_Minds > Many professionals set out to make a contribution to society and add meaning to their lives. Yet our system of professional education and employment abusively inculcates an acceptance of politically subordinate roles in which professionals typically do not make a significant difference.

Companies are not democracies. Is it a contradiction that we both praise democracy and spend our working time in dictatorships? Probably but we usually don't even notice it.

Re: Facebook Asking for Some New Users' Email Passwords

#230

Earlier quoted context omitted.

I alluded to this in my other comment, but I don't blame Plaid. Blame the banks - Plaid isn't doing this behind their banks, but with their blessings. Again, Mint was doing this for years. When it comes to Credit Card Fraud, the banks are buying all sorts of AI based solutions - after all it's their money. When it comes to customer cash, then its the wild west. I recently found out that my Wells Fargo password isn't…

Why not blame Plaid? Plaid's value is providing the SDK that developers can plug into their app to connect user bank accounts with their app. They have purposefully decided not to show a very common step in the user-facing bank link/onboarding flow of displaying exactly what information you are providing the developer with (e.g. think about FB Connect, Twitter, and Google and how each requires developers to show exac…

People willingly sign up for Plaid. Banks have vendor lockin and special legal rights others don't have
Post reply on HN