Live data from Hacker News

Facebook Asking for Some New Users' Email Passwords

thedailybeast.com

311–320 of 377 posts

Re: Facebook Asking for Some New Users' Email Passwords

#311
post #308

I recently learned that when you connect your Paypal account to your checking account, there's two verification methods you can choose between: 1) the good old fashioned, we'll make two small deposits into your account, tell us what they are; and 2) just give us the login info for your bank's web site. But Mint works the same way, doesn't it?

I believe most if not all legitimate companies that ask for your banking credentials (besides your bank, obviously) are just passing them straight to https://plaid.com/. It's still questionable whether you should trust Plaid with your banking credentials, but at least you probably don't need to trust that Paypal and Mint are both going to store your credentials securely.

Re: Facebook Asking for Some New Users' Email Passwords

#313
post #308

I recently learned that when you connect your Paypal account to your checking account, there's two verification methods you can choose between: 1) the good old fashioned, we'll make two small deposits into your account, tell us what they are; and 2) just give us the login info for your bank's web site. But Mint works the same way, doesn't it?

I worked for a fintech company until 2 years ago.

The CTO/CEO wanted to add a feature that lets users enter their bank password and through a service (Yodlee/TradeIt) lets the company read their stock portfolio and perform actions.

I told them that I don't think people would trust their bank info to some small fintech startup. Boy was I wrong and people with 4M dollar stock trading accounts would enter their credentials all the time for convenience of not having to copy the data over (since brokers didn't have an API with tokens).

Eventually the company grew and it's pretty reputable on its own but I remember this pretty vividly the surprise of people trusting all their money to us.

Re: Facebook Asking for Some New Users' Email Passwords

#314
Last service that I remember asking me for the signup email password was ...wait for it ...MySpace!

It was years ago, but it sounds a bit like a swan song pattern to my ears despite the lack of any rational connection...

...they should find a new WhatsApp or a Snapchat to buy ASAP because sooner or later they'll be too uncool for people to share the interesting content in their garden, so their humongous user base's value will start asymptoting to $0.

Re: Facebook Asking for Some New Users' Email Passwords

#315
post #308

I recently learned that when you connect your Paypal account to your checking account, there's two verification methods you can choose between: 1) the good old fashioned, we'll make two small deposits into your account, tell us what they are; and 2) just give us the login info for your bank's web site. But Mint works the same way, doesn't it?

I believe most if not all legitimate companies that ask for your banking credentials (besides your bank, obviously) are just passing them straight to https://plaid.com/ . It's still questionable whether you should trust Plaid with your banking credentials, but at least you probably don't need to trust that Paypal and Mint are both going to store your credentials securely.

> but at least you probably don't need to trust that Paypal and Mint are both going to store your credentials securely.

Sure you do. They have it in plaintext on their servers. It can end up in logs. It's also not just Plaid - Mint uses Intuit, Yodlee is an option. There's a whole lot of people you need to trust to use these services

For many banks, it also means you need to disable 2fa on your banking account, so using these services directly weakens your security.

Re: Facebook Asking for Some New Users' Email Passwords

#316
post #67

I just don't understand how this gets implemented without someone speaking up and saying "hey, wait, isn't this an insane thing to do?". I would guess it's some combination of the complainers being ignored, and people at a higher level thinking "well we're doing this in a secure way, as long as the user trusts us, and why wouldn't they trust us, we're Facebook!".

I worked at FB briefly so maybe I can explain. FB has a corporate culture that really discourages critique. When things are broken, especially internal things, people look at you funny if you speak up about it. A big part of that is that quarterly bonuses are given for "making an impact" and your group's status (and part of your bonus) is based on delivering a consistent set of "impacts" over time. So it is better for your comp to do things badly really fast since you get (1) did something super fast! and (2) get to record a big impact a few months later when you fix the obvious brokenness.

Pretty quickly, people learn to keep their mouth shut.

Also, many, many FB engineers are early-career folk who are fresh out of school. More senior folk are few and far between and are even more strongly incentivized to keep their mouth shut, because their bonuses are bigger.

Re: Facebook Asking for Some New Users' Email Passwords

#317

https://www.axios.com/facebook-will-stop-asking-new-users-fo... Facebook told Axios that "a very small group of people have the option of entering their email password to verify their account when they sign up for Facebook," but noted that people could choose instead to confirm their account with a code or link sent to their phone or email. "That said, we understand the password verification option isn't the best way…

"That said, we understand the password verification option isn't the best way to go about this, so we are going to stop offering it, now that we've been caught."

Facebook always leaves that part out of its responses to these problems.

Re: Facebook Asking for Some New Users' Email Passwords

#318

Earlier quoted context omitted.

'move fast and break things' ?

What’s the phase after you’ve moved fast and broken the things?

“It was a mistake, and we’re sorry.” Repeat in an infinite loop because the collective media and societal memory is similar to a concussed bee’s.

Re: Facebook Asking for Some New Users' Email Passwords

#319
post #308

I recently learned that when you connect your Paypal account to your checking account, there's two verification methods you can choose between: 1) the good old fashioned, we'll make two small deposits into your account, tell us what they are; and 2) just give us the login info for your bank's web site. But Mint works the same way, doesn't it?

Actually, I was surprised to see yesterday that Google offered this as well, when I set my bank account as a payment method for my Google apps account.

After a bit of consideration I went ahead and did it—I consider Google trustworthy as far as security practices, and to be honest, I didn't expect it to work. Chase forces (!) two step authentication despite my very strong password, and I thought that would prevent Google from logging in.

To my surprise, the process appears to have worked fine—my bank account was verified. I also didn't get a "new sign in from" email from Chase. So I wonder if they actually logged in or did something else...

Re: Facebook Asking for Some New Users' Email Passwords

#320

https://www.axios.com/facebook-will-stop-asking-new-users-fo... Facebook told Axios that "a very small group of people have the option of entering their email password to verify their account when they sign up for Facebook," but noted that people could choose instead to confirm their account with a code or link sent to their phone or email. "That said, we understand the password verification option isn't the best way…

Would be really interesting if one of those non-OAuth email providers scoured their logs to find the Facebook "logins" and see what, if any, requests FB made against the server after successful authentication.
Post reply on HN