Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

151–160 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#151
post #66

In other news, I built and deployed a "2FA Mule" last weekend. It's a stock android phone with no google account and no apps installed except for "SMS Forwarder"[1]. It is configured to forward all SMS to an email address via encrypted SMTP. This means that I can receive these 2FA codes anywhere I have Internet access - such as an airplane or newly arrived in a foreign country where my SIM card does not work. The "2F…

Google Voice works for many services which is protectable with 2FA (hardware tokens) and accessible most anywhere in the world--you're at the mercy of Google, though

That should help against SIM swap attacks

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#152
post #145
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…

That’s ok with me - FB has enough money.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#154
post #114
post #84

Earlier quoted context omitted.

Nice. I do something similar but forward it to Slack. I also have it auto-answer 2FA calls and automatically hit the # key. Yeah, call it not real 2FA, but it's really companies that choose to not use U2F are at fault.

"I also have it auto-answer 2FA calls and automatically hit the # key." One year at defcon - maybe 20 years ago - the speaker told an anecdote about a user who had set up a webcam and put their RSA token under it. And we all laughed ... "haha what a dummy ... I can't believe users are so stupid" ... But secretly I thought it was genius.

Oh I've done that too before. If they only give me one RSA token and no backup, then that's what i do.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#155
post #82

Earlier quoted context omitted.

> it is generated on a separate device which does not communicate with your browser, and does not know the target domain. No, not always and many password manager solutions do integrate with your browser and know the domain for the password.

Then that's not TOTP https://datatracker.ietf.org/doc/html/rfc6238 but something different. Do you know how it is called and which products support it? I'd love to read up about it!

Bitwarden has TOTP support in paid plan. And it works with browser extension which recognises domains.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#156

What is the point of setting up a hardware or Google Authenticator-type 2FA solution when most companies will fallback to SMS? Is there a way to prevent the SMS fallback (last I checked it was 'No' for most sites except maybe Google if I remember, and then you still had to go in and manually delete it)? Does a master list exist of companies that don't use SMS, or allow the user to exclude it? Otherwise it seems like…

It seems like the places that rely on SMS generally don't have hardware 2FA. Or, most websites that allow configuring multiple 2FA methods support disabling SMS

The ones that let you configure a single MFA method or single with backup are usually where I run into issues, personally

For instance, on Github, I have 2x U2F tokens and paper recovery codes but there's not even a phone number configured on the account

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#157
post #25

So in this story Facebook was responsible for $50 of charges, a business disruption and a huge and ongoing hassle. And Facebook refuses so much as to pick up the phone to discuss it. In the old days the equivalent would have been one of those roach motel businesses rated 'F' on the Better Business Bureau, buckets arrayed on the floor to catch rain leaking through the roof. And yet in this day it's one of the most pro…

I think they are at a point where they would rather side with a scammer since they generate more money from this situation. I guess they have data that shows this particular kind of user will almost never buy ads ever again, so at least let a scammer do it. You're right, this is weird, but if you look at the profit model, it makes sense, and there are no laws that would really protect the user.

Exactly. From the article, "Personally, I think it’s very telling that Facebook acts so swiftly to block out the original user who can stop an ad scam, and so slowly to stop a scam ad that they can still bill for."

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#158
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

> they should be on the hook for refunding a significant portion of the cost of the user's Oculus library

If the purchases were < 6 months ago, I would do credit card charge backs...

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#159

So in this story Facebook was responsible for $50 of charges, a business disruption and a huge and ongoing hassle. And Facebook refuses so much as to pick up the phone to discuss it. In the old days the equivalent would have been one of those roach motel businesses rated 'F' on the Better Business Bureau, buckets arrayed on the floor to catch rain leaking through the roof. And yet in this day it's one of the most pro…

There are many motels, but Facebook has a monopoly on facebook accounts. If you could make a facebook account somewhere else, you could "take your business elsewhere". Last I checked, FB actively banned using their APIs to build a competing product. I wish the government would make it mandatory to offer federation if you had, say, more than a million customers. But alas, governments rarely do what's convenient for cu…

That's pretty silly. Should I be able to use Amazon APIs to host reviews for my competing ecommerce site? Or be able to proxy user search requests to google and then intersperse my own advertisements in the results for my web search service?

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#160
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

Or have ban groups. Ban someone from having a Facebook profile, buying ads, sending Messages, or having an Instagram profile based on their behavior on those respective sections of the site. Maybe disable a person's multiplayer capabilities if they have a reputation for harassment.

But let them keep their hardware running, and access their game library.

Seems good for business, tbh. You might not want neo-nazis posting whatever they want on their profiles, but who cares if they're buying video games?

Post reply on HN