Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

41–50 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#41
I can't tell you how many obviously-fake profiles and scammers I report, and see other people commenting about reporting, only for them to still be around days, weeks, sometimes even months later.

All of these were obvious scammers directing traffic to a single profile - some forex guru or whatever. Shilling get-rich-quick schemes doesn't meet Facebook's definition of "spam", apparently.

https://imgur.com/a/xihRPwE

What a garbage app.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#42

Earlier quoted context omitted.

Beating 2FA is almost always SMS hijacking, but sometimes it's social engineering where the attacker has figured out just the right script to tell support ("oh, I dropped my phone and it won't turn on...") to get it disabled. edit: correction, beating 2FA without phishing -- like in the post where he lost his account while asleep.

Google is better than all other alternatives in that regard. They have a feature called Advanced Protection where you add your 2FA U2F keys and if you lose them your account is gone. No social engineering possible. https://landing.google.com/advancedprotection/

“If you lose your key and are still signed in on one of your devices, visit account.google.com to add or replace a key. Otherwise, submit a request to recover your account. Google may take a few days to verify that it’s you and restore your access.”

I trust that it would be (potentially much) harder than normal, but it still seems to be possible.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#43

Earlier quoted context omitted.

How does an sms hijacking attack typically work? I know sms isn't secure, but how does one go from having a password to bypassing the sms confirmation? Is it as easy as having the number and carrier?

It happened to me. Cellular carriers, in my case T-Mobile, didn't require any confirmation to port a number to a new phone/sim. Eventually some required the last 4 of your social security number to port a number, which we all know at this point are pretty much public anyway. T-Mobile now lets you set an arbitrary pin, which my parents promptly set to their DOB :facepalm: I haven't looked more into it, but as far as I…

[deleted]

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#44
post #22

Here's my guess at what happened: How was the account hijacked? Via cookie theft. The author installed malware, maybe some dodgy windows binaries or malicious browser extensions. No amount or type of 2FA on sign-in will protect you against the session cookie being stolen. (Now, additional 2FA on sensitive actions might). Why was the account was banned with such finality, with no chance of appeal? Probably for somethi…

The attacker should have replicated the browser fingerprint and IP on top of stealing the cookie - or just flat out used his computer remotely while he was sleeping.

I haven't used FB in a while but I remember login from other places were detected.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#45

Earlier quoted context omitted.

Beating 2FA is almost always SMS hijacking, but sometimes it's social engineering where the attacker has figured out just the right script to tell support ("oh, I dropped my phone and it won't turn on...") to get it disabled. edit: correction, beating 2FA without phishing -- like in the post where he lost his account while asleep.

Google is better than all other alternatives in that regard. They have a feature called Advanced Protection where you add your 2FA U2F keys and if you lose them your account is gone. No social engineering possible. https://landing.google.com/advancedprotection/

> if you lose them your account is gone

IMO, this is way too extreme for almost everybody. There needs to be some sort of happy medium so that a person who's lost everything they own (e.g., house fire) can get their account back somehow still. Two ideas I had:

1. When you set up your account, provide your legal name, date of birth, and a photo. If you need to reset 2FA, go somewhere in person with a government-issued photo ID (which we already have procedures to replace) that all of the details of match.

2. When you set up your account, provide 5 trusted contacts. If you need to reset 2FA, get 3 of them to agree.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#47
post #25

So in this story Facebook was responsible for $50 of charges, a business disruption and a huge and ongoing hassle. And Facebook refuses so much as to pick up the phone to discuss it. In the old days the equivalent would have been one of those roach motel businesses rated 'F' on the Better Business Bureau, buckets arrayed on the floor to catch rain leaking through the roof. And yet in this day it's one of the most pro…

I think they are at a point where they would rather side with a scammer since they generate more money from this situation. I guess they have data that shows this particular kind of user will almost never buy ads ever again, so at least let a scammer do it. You're right, this is weird, but if you look at the profit model, it makes sense, and there are no laws that would really protect the user.

Those transactions are likely to be reversed thanks to the practically unlimited chargebacks practice which is rampant in our banking system.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#48

Earlier quoted context omitted.

Beating 2FA is almost always SMS hijacking, but sometimes it's social engineering where the attacker has figured out just the right script to tell support ("oh, I dropped my phone and it won't turn on...") to get it disabled. edit: correction, beating 2FA without phishing -- like in the post where he lost his account while asleep.

> Beating 2FA is almost always SMS hijacking That's most definitely not true, as someone who works in this space. Plain old phishing is much more common, where the hacker tricks a user into entering their code into a malicious website. To echo OP, this is why it's important to support non-phishable types of 2FA.

Could you describe the types that are non-phishable?

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#49
post #22

Here's my guess at what happened: How was the account hijacked? Via cookie theft. The author installed malware, maybe some dodgy windows binaries or malicious browser extensions. No amount or type of 2FA on sign-in will protect you against the session cookie being stolen. (Now, additional 2FA on sensitive actions might). Why was the account was banned with such finality, with no chance of appeal? Probably for somethi…

The attacker should have replicated the browser fingerprint and IP on top of stealing the cookie - or just flat out used his computer remotely while he was sleeping. I haven't used FB in a while but I remember login from other places were detected.

If the session cookie was stolen, there's no new login to detect and send a security notification about.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#50
post #42

Earlier quoted context omitted.

Google is better than all other alternatives in that regard. They have a feature called Advanced Protection where you add your 2FA U2F keys and if you lose them your account is gone. No social engineering possible. https://landing.google.com/advancedprotection/

“If you lose your key and are still signed in on one of your devices, visit account.google.com to add or replace a key. Otherwise, submit a request to recover your account. Google may take a few days to verify that it’s you and restore your access.” I trust that it would be (potentially much) harder than normal, but it still seems to be possible.

I was under the impression you were screwed in that case, thanks for pointing out that I was wrong. It's lot less secure than I thought.
Post reply on HN