I had someone contact me on Facebook marketplace, we agreed upon a time/price and then they asked for my phone number (which I sadly gave them). Then they said "I'm going to text you a code, so I can verify you are legit". The text I got was from Google Voice's 2FA.....
Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
141–150 of 388 posts
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#142Earlier quoted context omitted.
Beating 2FA is almost always SMS hijacking, but sometimes it's social engineering where the attacker has figured out just the right script to tell support ("oh, I dropped my phone and it won't turn on...") to get it disabled. edit: correction, beating 2FA without phishing -- like in the post where he lost his account while asleep.
Wouldn't that be obvious to the victim the moment their phone didn't work? Or will the carrier leave the old SIM activated?
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#143I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#144Earlier quoted context omitted.
“If you lose your key and are still signed in on one of your devices, visit account.google.com to add or replace a key. Otherwise, submit a request to recover your account. Google may take a few days to verify that it’s you and restore your access.” I trust that it would be (potentially much) harder than normal, but it still seems to be possible.
I was under the impression you were screwed in that case, thanks for pointing out that I was wrong. It's lot less secure than I thought.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#145I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…
This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.)
The problem here is that Facebook couldn't tell OP had been impersonated by an abuser -- as you say, "actions outside the user's control."
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#146What is the point of setting up a hardware or Google Authenticator-type 2FA solution when most companies will fallback to SMS? Is there a way to prevent the SMS fallback (last I checked it was 'No' for most sites except maybe Google if I remember, and then you still had to go in and manually delete it)? Does a master list exist of companies that don't use SMS, or allow the user to exclude it? Otherwise it seems like…
One possible point is that you could still log in somewhere that has internet but no cell service
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#147I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…
> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#148I had someone contact me on Facebook marketplace, we agreed upon a time/price and then they asked for my phone number (which I sadly gave them). Then they said "I'm going to text you a code, so I can verify you are legit". The text I got was from Google Voice's 2FA.....
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#149Earlier quoted context omitted.
I think they are at a point where they would rather side with a scammer since they generate more money from this situation. I guess they have data that shows this particular kind of user will almost never buy ads ever again, so at least let a scammer do it. You're right, this is weird, but if you look at the profit model, it makes sense, and there are no laws that would really protect the user.
Those transactions are likely to be reversed thanks to the practically unlimited chargebacks practice which is rampant in our banking system.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#150Earlier quoted context omitted.
Can't they detect that the session cookie is coming from a different IP than the one it was originally issued to?
A carrier-grade NAT could make you change IP address. TOR will do it. You would cause yourself more problems if you would start to bind a session to an IP address.
IPv6 privacy extensions are generally considered a feature