Live data from Hacker News

Facebook introduces Two Factor Authentication

facebook.com

11–20 of 24 posts

Re: Facebook introduces Two Factor Authentication

#13
Interesting point "If you ever lose or forget your phone and have login approvals turned on, you will still have the option to authorize your login provided you are accessing your account from a saved device."

In contrast to Google's solution which provides you with a set of fallback codes.

Re: Facebook introduces Two Factor Authentication

#14
This seems to me like just another backdoor way of being able to build a more robust database of personal information on you. With your mobile number and the numbers of all your friends, in coordination with the cell carriers (or NSA, whichever you prefer) they can tie together data about who you call & how often with your friend activity on Facebook. Google has been doing it too, asking for a "mobile number backup" when you log into Gmail.

Just the next erosion of our privacy, disguised as a protection of our privacy.

Re: Facebook introduces Two Factor Authentication

#15
post #14

This seems to me like just another backdoor way of being able to build a more robust database of personal information on you. With your mobile number and the numbers of all your friends, in coordination with the cell carriers (or NSA, whichever you prefer) they can tie together data about who you call & how often with your friend activity on Facebook. Google has been doing it too, asking for a "mobile number backup"…

And/or facebook's solution to the Firesheep vulnerability. (Can someone confirm that this solves the firesheep problem?)

Re: Facebook introduces Two Factor Authentication

#16
post #14

This seems to me like just another backdoor way of being able to build a more robust database of personal information on you. With your mobile number and the numbers of all your friends, in coordination with the cell carriers (or NSA, whichever you prefer) they can tie together data about who you call & how often with your friend activity on Facebook. Google has been doing it too, asking for a "mobile number backup"…

Bullshit conspiracy theories. How can something that is opt-in be an erosion of privacy? By default it is not enabled. Just don't use it and you're fine.

Re: Facebook introduces Two Factor Authentication

#17
post #15
post #14

This seems to me like just another backdoor way of being able to build a more robust database of personal information on you. With your mobile number and the numbers of all your friends, in coordination with the cell carriers (or NSA, whichever you prefer) they can tie together data about who you call & how often with your friend activity on Facebook. Google has been doing it too, asking for a "mobile number backup"…

And/or facebook's solution to the Firesheep vulnerability. (Can someone confirm that this solves the firesheep problem?)

Firesheep is solved by enabling HTTPS on Facebook. This was released several months ago:

https://www.facebook.com/blog.php?post=486790652130

Re: Facebook introduces Two Factor Authentication

#18
post #16
post #14

This seems to me like just another backdoor way of being able to build a more robust database of personal information on you. With your mobile number and the numbers of all your friends, in coordination with the cell carriers (or NSA, whichever you prefer) they can tie together data about who you call & how often with your friend activity on Facebook. Google has been doing it too, asking for a "mobile number backup"…

Bullshit conspiracy theories. How can something that is opt-in be an erosion of privacy? By default it is not enabled. Just don't use it and you're fine.

It's pretty standard practice to roll out a feature as optional and gauge reaction before making it mandatory.

Re: Facebook introduces Two Factor Authentication

#19
post #17
post #15

Earlier quoted context omitted.

And/or facebook's solution to the Firesheep vulnerability. (Can someone confirm that this solves the firesheep problem?)

Firesheep is solved by enabling HTTPS on Facebook. This was released several months ago: https://www.facebook.com/blog.php?post=486790652130

Well yeah but that slows everything down a lot. This wouldn't slow it down at all.

Re: Facebook introduces Two Factor Authentication

#20
post #14

This seems to me like just another backdoor way of being able to build a more robust database of personal information on you. With your mobile number and the numbers of all your friends, in coordination with the cell carriers (or NSA, whichever you prefer) they can tie together data about who you call & how often with your friend activity on Facebook. Google has been doing it too, asking for a "mobile number backup"…

Wow, this is some crazy.

If you start by assuming they have access to the cell carrier data (which is a super-mega-wacky assumption), why do they need you to provide your number in the first place? They can just look it up in the billing, which ties to a verified address.

And even if you really are this paranoid, you can just use a $10 burner phone for this authentication.

Post reply on HN