Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

171–180 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#171
post #151
post #66

In other news, I built and deployed a "2FA Mule" last weekend. It's a stock android phone with no google account and no apps installed except for "SMS Forwarder"[1]. It is configured to forward all SMS to an email address via encrypted SMTP. This means that I can receive these 2FA codes anywhere I have Internet access - such as an airplane or newly arrived in a foreign country where my SIM card does not work. The "2F…

Google Voice works for many services which is protectable with 2FA (hardware tokens) and accessible most anywhere in the world--you're at the mercy of Google, though That should help against SIM swap attacks

Lately more and more of my accounts aren't accepting GV as a phone number linked with the account.

Recent memory: 7-11 app and eBay both made me use a number that's associated with an actual SIM card.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#172
IDEA: Build a service that identifies all the Single Sign On accounts tied to your Facebook/Google/GitHub/Twitter accounts for you and gives you a nice list and instructions on how to separate out the accounts with links if possible.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#173
post #10

I don't think Facebook 2FA is terribly secure. They definitely err on the side of usability. I was using TOTP on Instagram and I forgot to backup my Google Authenticator before wiping my iPhone. But I was then able to just go the the settings on a logged-in device and disable 2FA without 2FA. And it wasn't like I had logged into that device recently, either. I only had to 2FA Instagram once, years ago.

I wonder if having 2FA made it worse ... I can see the review process taking the enablement of 2FA as proof he really did the abuse and discounting the possibility that his account was hacked.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#174
post #2

> I want to start by pointing out I use two-factor authentication just about everywhere and Facebook is not an exception. I wish he'd mention what kind of 2FA. The reason you _really_ should use U2F/WebAuthn is because it does origin binding which, unlike entering a TOTP, a code from your hardware token/authenticator app on your phone/SMS/etc is not phishable, i.e. you can't enter it by accident on accounts.google.co…

> I wish he'd mention what kind of 2FA...U2F/WebAuthn...origin binding...SMS It shouldn't matter, because it's irrelevant to the point of the article, which is that Facebook (at least as reported) leaves a hacking victim with little or no recourse to get their account, and sometimes livelihood back. An imperfect real-world analogy of your question is like asking about what precise brand of bear mace an assault victim…

I for one would appreciate knowing what brands of bear mace are ineffective and worth avoiding.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#175
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

This is not a bad idea as long as Facebook is on the hook for the refunds, not the app developers.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#176
i love how they say it cant be reversed in the warning. that is an absolute falsehood. its worded in a way that leads you to believe its final and not possible to undo, which is entirely false.

source: recently had to help someone get a developer account out of this position, account was reinstated. just gotta know the right people i guess?

this is the biggest example of all, to me, why big tech needs regulating... if you are going to take away access to things i paid for(or worse yet, my families livelihood depends on), you dang well better be willing to explain very explicitly why and provide me with a real person to appeal to. not some automated system(im looking at you too Google and Apple!)

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#177
post #151

Earlier quoted context omitted.

Google Voice works for many services which is protectable with 2FA (hardware tokens) and accessible most anywhere in the world--you're at the mercy of Google, though That should help against SIM swap attacks

Lately more and more of my accounts aren't accepting GV as a phone number linked with the account. Recent memory: 7-11 app and eBay both made me use a number that's associated with an actual SIM card.

It's hit or miss and that is why I am basing this on an honest-to-god mobile number on a SIM card. I don't want to deal with the finnicky number validation that is done ...

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#178
post #145
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…

There's not really an "abuse" reason to stop people from playing single player games though. What malicious thing would they do with them?

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#179
post #145
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…

Any system that wants to identify a pattern will have false positives and negatives.

In this case we can’t accurately identify cases where a user has legitimate cause for refund without false positives letting through a few abusive users.

The decision to be made is whether we skew the system to be in favor of the corporation or the consumer.

In this age where we no longer own the software we run I find it strange when people advocate for less protection of the digital goods they use.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#180
post #145
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…

An easy way out would be to ban the account from everything except accessing the purchases.
Post reply on HN