Live data from Hacker News

Facebook Asking for Some New Users' Email Passwords

thedailybeast.com

251–260 of 377 posts

Re: Facebook Asking for Some New Users' Email Passwords

#251

I don't understand how they can login for you on any of the popular email providers. Gmail, for example, detects a new computer by cookie and "fingerprint" (ip address, browser, UA, etc). You then get 2fa'd or at least "robot checked". How did they make this a smooth experience?

On accounts with 2FA not activated I just get an email on my backup account that a new computer has logged in.

Re: Facebook Asking for Some New Users' Email Passwords

#252
I don't get the outrage. No comment mentions this, but most non-tech people already give Facebook their e-mail password. All Facebook needs to do is try to use it.

Lookup the password re-use rates among users of the Internet.

People may have weak and strong password for less and more important services. Guess how would they rate the Facebook...

Re: Facebook Asking for Some New Users' Email Passwords

#254

Earlier quoted context omitted.

Easy. The engineers who built it care mostly about their total compensation and getting promoted. They therefore gleefully implement the product requirements. The PMs behind the idea also care about the above, except they are held to account by business objectives. By narrowly optimizing for a particular objective (reducing account fraud) in an unprincipled manner, they come up with an insane feature idea like this.…

The finance industry gets (often rightfully) vilified for having flexible morals and reckless profit seeking, but this is not something unique to finance. Finance was traditionally the environment that enabled this sort of behavior, but the root cause is that fundamental human behavior is still fairly reptilian in nature. As technologists we like to think that we are above this behavior, but we are not. All it takes…

I agree partially. First of, I don't think the finance industry gets vilified for having flexible morals, they attract hate for having no morals at all.

Certainly, you're right that we depend on each one to say "no, I won't do that", but I feel like there's a difference in quality: evil intent vs willful ignorance/negligence. There might be borderline illegal tax-dodging with large tech companies, there might be irresponsible data security, but there's not a lot that is comparable to the cum-ex-trades that large banks engaged in: no active defrauding of the government and/or citizens. Granted, it may happen once tech corporations have as strong a grip on governments as banks do, and feel secure enough that they won't have to face repercussions if it blows up.

Plenty of banks, and not just the large, global ones have actively engaged in tricking their customers by selling them junk and hiding and/or downplaying important details to get their sales provision, and it wasn't something that was "only known at the top". I've yet to hear of scandals of a similar magnitude in tech. Chrome doesn't contain any hidden crypto-miner, and if it ever will, I doubt that an investigation would reveal everybody on the team knew about it - it would likely just reveal a security breach or a small amount of people subverting the processes.

I do completely agree that tech isn't all sunshine, however. Behind pretty much every large scale data leak is an engineer that said "well okay if you want me to put this database server on the public internet and remove the password, I'm happy to do it" instead of refusing, and behind every horrible overreach in surveillance is an engineer that just blocks out the impact his work has on real people. There are people working on killer drones after all, and I don't think any of them are naive enough to believe that "they only target the bad guys".

Re: Facebook Asking for Some New Users' Email Passwords

#255

Earlier quoted context omitted.

Easy. The engineers who built it care mostly about their total compensation and getting promoted. They therefore gleefully implement the product requirements. The PMs behind the idea also care about the above, except they are held to account by business objectives. By narrowly optimizing for a particular objective (reducing account fraud) in an unprincipled manner, they come up with an insane feature idea like this.…

The finance industry gets (often rightfully) vilified for having flexible morals and reckless profit seeking, but this is not something unique to finance. Finance was traditionally the environment that enabled this sort of behavior, but the root cause is that fundamental human behavior is still fairly reptilian in nature. As technologists we like to think that we are above this behavior, but we are not. All it takes…

And in finance, they've developed entire management wings called "compliance" to watch over things and make sure that laws are not broken/the firm is not put at risk. I wonder if that will happen here (there is a distinctly smaller set of laws that can be broken, but Zuck apparently is asking for that now...)

Re: Facebook Asking for Some New Users' Email Passwords

#256

Earlier quoted context omitted.

I find it fascinating how big tech companies are intent on spending enormous sums of money seeking out the top tech talent in the world. Then rather than listen to them when they voice concerns they try to beat them down into submission. I get that if you worked at a company whose core mission is evil that you just have to accept that when you sign up, but there's no reason facebook needs to be make these active mora…

Steve Jobs understood the problem. https://youtu.be/fuZ6ypueK8M

I was looking for the Steve Jobs quote in this thread, thought this was going to be "It doesn't make sense to hire smart people and tell them what to do; we hire smart people so they can tell us what to do."

Re: Facebook Asking for Some New Users' Email Passwords

#257

I don't understand how they can login for you on any of the popular email providers. Gmail, for example, detects a new computer by cookie and "fingerprint" (ip address, browser, UA, etc). You then get 2fa'd or at least "robot checked". How did they make this a smooth experience?

According to the article it was only offered to a subset of providers that don’t have OAuth APIs.

Presumably google and other high security email providers got the OAuth option and this more insecure option was offered to users with ESPs that don’t have the gmail security features you mentioned.

Re: Facebook Asking for Some New Users' Email Passwords

#259
post #171

Earlier quoted context omitted.

Ignoring their recent fail at logging passwords. It has been established as minimal practice, that NO ONE should be asking you about your password. If this would become a normal, it would also make regular people more likely to give out their passwords. And email is key to your online kingdom, so it's a big deal, if it gets compromised.

At the very least, your mail client has to ask you for your email password. Might sound like I'm splitting hairs but I don't think most users have a strong sense of why that's different from Facebook doing it. And with wizzy online features crammed into more and more desktop software (seen Photoshop lately?) you can't really fault them for it.

Especially when most users are probably using the same password for both, or are just warming up to the concept that you shouldn’t do that.

Re: Facebook Asking for Some New Users' Email Passwords

#260

Earlier quoted context omitted.

You mean emails? I've managed to turn them all off; if that doesn't work, you can file a complaint with the EU who have strict laws against e-mail spam, and the requirement to unsubscribe with as few actions as possible.

Where can I file these complaints? I have looked for this before, but wasn’t able to find out

IANAL, but usually you file a complaint with your national regulator, so it would depend on your country (of residence, I guess).
Post reply on HN