Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

181–190 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#181
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

This is not a bad idea as long as Facebook is on the hook for the refunds, not the app developers.

Well it’s have to be both like any normal refund. Hopefully the % of refunds is small as it would be on way ebay or Amazon sales.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#182
post #108

For those who have worked at Facebook - why in the world are their policies like this? Why is customer support so... unfriendly and unhelpful? No escalations possible? No way to reach anyone?

My guess is money.

Facebook has such a MASSIVE user base. And people are getting accounts stolen a LOT, from either social engineering or password reuse.

But there's also a ton of people knowingly breaking rules, getting banned, and then trying to cry that their account was hacked.

Trying to differentiate between someone's account being taken over and abused versus someone just simply being abusive and lying about it to support costs a lot of time, and time is money. And with the scale of Facebook, that adds up to a LOT of money. You have to train a large staff to understand social engineering and be able to tell the difference between someone who actually can't figure out how to log in, versus a jealous ex who is trying to social engineer their way into someone else's account.

It's a lot cheaper to just let the bans stick, even if it loses a few customers.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#183

Earlier quoted context omitted.

> Beating 2FA is almost always SMS hijacking That's most definitely not true, as someone who works in this space. Plain old phishing is much more common, where the hacker tricks a user into entering their code into a malicious website. To echo OP, this is why it's important to support non-phishable types of 2FA.

I wondered about this in regards to Crypto and NFT's in the digital wallet space. It seems like Metamask with a ledger wallet is stadard, but I have a theory that if you're not sophisticated and you get into Crypto/NFT's, it may be safer to just use Coinbase Wallet, as it is less popular target than matamask and you're able to leverage Coinbase's ongoing security updates. and if you're not sophisticated, you're just…

How’s it any relevant?

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#185
post #145

Earlier quoted context omitted.

> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…

An easy way out would be to ban the account from everything except accessing the purchases.

yes ... that's what I hope and expect would be the outcome if this was enforced on Facebook. They will try to claim that the social features are essential to the platform and therefore cannot be disabled but it would not hold up based on current Oculus ecosystem.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#186
Google makes a point in their ads for the chromebook that you need a Google account to login, which my brain immediately translates into "could be randomly bricked at any time".

It's possible that's not true, but there's such an endless stream of these stories, that that's the attitude you have to take.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#187
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

Why are we buying this account-linked physical shit. Just pretend the headsets are not a viable product to purchase if they can be remotely bricked by a company you have no leverage over. Get a competitor product or go without.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#188
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

Why are we buying this account-linked physical shit. Just pretend the headsets are not a viable product to purchase if they can be remotely bricked by a company you have no leverage over. Get a competitor product or go without.

Do you use a smartphone?

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#189

Earlier quoted context omitted.

Why are we buying this account-linked physical shit. Just pretend the headsets are not a viable product to purchase if they can be remotely bricked by a company you have no leverage over. Get a competitor product or go without.

Do you use a smartphone?

Yeah smartphones are unfortunate since with COVID now you have to have one to check in in my country, but the second test is reputation. I’ve not heard of apple or android bricking a phone like this but FB/Google account bans and limitations are common.

I guess we can’t be purist anymore but being pragmatic is still possible and you can divert funds away from FB this way to a company that cares about the headsets they sell and the user experience

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#190

Earlier quoted context omitted.

There are many motels, but Facebook has a monopoly on facebook accounts. If you could make a facebook account somewhere else, you could "take your business elsewhere". Last I checked, FB actively banned using their APIs to build a competing product. I wish the government would make it mandatory to offer federation if you had, say, more than a million customers. But alas, governments rarely do what's convenient for cu…

That's pretty silly. Should I be able to use Amazon APIs to host reviews for my competing ecommerce site? Or be able to proxy user search requests to google and then intersperse my own advertisements in the results for my web search service?

I'm not the person you're responding to, but I would say unequivocally and unironically, yes! The end result is more competition, lower prices, and more options for the end consumer. Sure the raw idea of this mechanism is a little naive and could be refined, but the outcomes you paint sound totally reasonable to me... think of this as a creative way to apply a new kind of tax to the criminally undertaxed big tech behemoths like Amazon and Google.
Post reply on HN