Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

141–150 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#141

I had someone contact me on Facebook marketplace, we agreed upon a time/price and then they asked for my phone number (which I sadly gave them). Then they said "I'm going to text you a code, so I can verify you are legit". The text I got was from Google Voice's 2FA.....

The last time I posted something on craigslist for sale, the majority of responses were trying to get me to send them 2fa codes.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#142

Earlier quoted context omitted.

Beating 2FA is almost always SMS hijacking, but sometimes it's social engineering where the attacker has figured out just the right script to tell support ("oh, I dropped my phone and it won't turn on...") to get it disabled. edit: correction, beating 2FA without phishing -- like in the post where he lost his account while asleep.

Wouldn't that be obvious to the victim the moment their phone didn't work? Or will the carrier leave the old SIM activated?

IIRC, in the US, sometimes just give the old sim some random phone number (to keep you paying the bill) and don't cancel the line. In the EU, I'm pretty sure they cancel the old line.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#143
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

This is another good part of steam - even if your account is banned from the entire community for site-wide spam, you don’t lose access to your game library.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#144
post #42

Earlier quoted context omitted.

“If you lose your key and are still signed in on one of your devices, visit account.google.com to add or replace a key. Otherwise, submit a request to recover your account. Google may take a few days to verify that it’s you and restore your access.” I trust that it would be (potentially much) harder than normal, but it still seems to be possible.

I was under the impression you were screwed in that case, thanks for pointing out that I was wrong. It's lot less secure than I thought.

Still sounds like a significant barrier to most phishing attacks.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#145
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

> refunding a significant portion of the cost of the user's Oculus library when they ban the account

This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.)

The problem here is that Facebook couldn't tell OP had been impersonated by an abuser -- as you say, "actions outside the user's control."

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#146

What is the point of setting up a hardware or Google Authenticator-type 2FA solution when most companies will fallback to SMS? Is there a way to prevent the SMS fallback (last I checked it was 'No' for most sites except maybe Google if I remember, and then you still had to go in and manually delete it)? Does a master list exist of companies that don't use SMS, or allow the user to exclude it? Otherwise it seems like…

> What is the point of setting up a hardware or Google Authenticator-type 2FA solution when most companies will fallback to SMS?

One possible point is that you could still log in somewhere that has internet but no cell service

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#147
post #145
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…

[deleted]

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#148

I had someone contact me on Facebook marketplace, we agreed upon a time/price and then they asked for my phone number (which I sadly gave them). Then they said "I'm going to text you a code, so I can verify you are legit". The text I got was from Google Voice's 2FA.....

This happened to my mother in law but luckily she was wise to the scam. She said the reply was almost immediately.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#149
post #25

Earlier quoted context omitted.

I think they are at a point where they would rather side with a scammer since they generate more money from this situation. I guess they have data that shows this particular kind of user will almost never buy ads ever again, so at least let a scammer do it. You're right, this is weird, but if you look at the profit model, it makes sense, and there are no laws that would really protect the user.

Those transactions are likely to be reversed thanks to the practically unlimited chargebacks practice which is rampant in our banking system.

Sure but then the question is "Should we leave an account with history of compromise in place that will lead to chargebacks or should we just permanently disable it"

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#150
post #96
post #74

Earlier quoted context omitted.

Can't they detect that the session cookie is coming from a different IP than the one it was originally issued to?

A carrier-grade NAT could make you change IP address. TOR will do it. You would cause yourself more problems if you would start to bind a session to an IP address.

Yeah and turns out CGNAT is ubiquitous among U.S. mobile phone carriers (which is a huge market for Facebook)

IPv6 privacy extensions are generally considered a feature

Post reply on HN