Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

191–200 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#191

Earlier quoted context omitted.

There are many motels, but Facebook has a monopoly on facebook accounts. If you could make a facebook account somewhere else, you could "take your business elsewhere". Last I checked, FB actively banned using their APIs to build a competing product. I wish the government would make it mandatory to offer federation if you had, say, more than a million customers. But alas, governments rarely do what's convenient for cu…

That's pretty silly. Should I be able to use Amazon APIs to host reviews for my competing ecommerce site? Or be able to proxy user search requests to google and then intersperse my own advertisements in the results for my web search service?

If it’s so I can access my own data then yes is should be able to.

Google isn’t remotely comparable, and I believe Amazon has APIs for their store fronts / merchants (still can’t access reviews you leave)

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#193
post #145

Earlier quoted context omitted.

> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…

There's not really an "abuse" reason to stop people from playing single player games though. What malicious thing would they do with them?

They don't have fine grained banning because the abuse system was made for a user base that pays them no money, so it's a blunt instrument optimized towards cost savings. Steam I've heard is more fine grained, and might just do online gaming bans or communication bans.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#194

Earlier quoted context omitted.

WebAuthn (or its predecessor U2F but that's obsolete, so in green field deployments do WebAuthn) is the only practical non-phishable second factor for ordinary users on the web. You can do this two ways, one of which will make more sense for your web site: 1. PCs/ laptops/ etc. can use little USB hardware devices, from outfits like Yubico, the word to Google or type into your preferred hardware source is "FIDO" altho…

> PCs/ laptops/ etc. can use little USB hardware devices, from outfits like Yubico This is actually built into most computers now -- Windows Hello, and Apple has something similar. Websites can check the attestation response to specifically block those, however. (Seems like Github allows it, and I've written code that allows it.) > I think some iPhones do facial recognition instead? Yup, they use whatever you use to…

> Websites can check the attestation response to specifically block those, however. (Seems like Github allows it, and I've written code that allows it.)

For the client side of things WebAuthn contains a standard option to block/allow "platform" authenticators, which I empirically know includes Windows Hello, and I'm not sure about Apple's or other equivalents. Of course you'd still want to verify the attestation on the server side.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#195

Earlier quoted context omitted.

It happened to me. Cellular carriers, in my case T-Mobile, didn't require any confirmation to port a number to a new phone/sim. Eventually some required the last 4 of your social security number to port a number, which we all know at this point are pretty much public anyway. T-Mobile now lets you set an arbitrary pin, which my parents promptly set to their DOB :facepalm: I haven't looked more into it, but as far as I…

You might want to edit out what your parents set their pin to! (You can email hn@ycombinator.com if you're past the edit window.)

Lol, I had made them change it as soon as they told me.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#196
post #145

Earlier quoted context omitted.

> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…

That’s ok with me - FB has enough money.

The problem being described is not FB losing money, it's grifters and scammers gaining money.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#197
Facebook sucks.what else is new.have not had a personal account in a decade after they terminated it. No regrets.i do however own the stock and remain very optimistic about the business but not for me. Sucks to invest to so much time in a platform that can take it all away from you without warning.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#198
post #81
post #36

Earlier quoted context omitted.

Companies like Facebook are as big as Nation States. Any positives that come out of this for the author are just a Facebook PR move. If they did care about users, their support system wouldn't be so anti-user.

It's trite at this point that someone will respond that the users aren't the customers, they're the product, but it's trite because it's often correct, and deserves to be said, so I guess I'll be the one to say it this time. The sad thing is that this person actually is a customer because they bought a product and pay for things on it, but Facebook still doesn't realize that, or more likely these customers are such a…

The guy is a customer in the traditional FB way (pays for ads) and the new oculus way (buys oculus games & hardware).

FB is super annoying when you want to separate the business from any form of a personal account. Eventually you need to have some sort of personal FB account linked to a business to manage some key ad buy things AFAIK, at the small business scale at the very least.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#199

This is what I'm worried about, to be honest. Not necessarily getting hacked but just getting flagged, banned and burned with no recourse. This is why I commented on an article here some weeks ago that if they ever offered any paid user experience they'd be in trouble because they'd actually have to help their users with their issues. These tech companies should offer actual support the moment you spend money with th…

I guess this is the model when the user is the product and not the customer. Flipping this, if this were a paying advertiser (customer) that got locked out, there probably is a valid path to contact someone. Looks like it is time to remove all my Single Sign On from Google, Facebook, GitHub etc. And have individual user/pass for all of them. I have the same fear as you and way more so after reading this article, just…

Per the post, the author is a paying Facebook advertiser. It seems like your theory isn't very predictive.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#200

So in this story Facebook was responsible for $50 of charges, a business disruption and a huge and ongoing hassle. And Facebook refuses so much as to pick up the phone to discuss it. In the old days the equivalent would have been one of those roach motel businesses rated 'F' on the Better Business Bureau, buckets arrayed on the floor to catch rain leaking through the roof. And yet in this day it's one of the most pro…

> And Facebook refuses so much as to pick up the phone to discuss it. It's part of the business model - each FB user generates so little revenue for the company that you can't afford to offer anything resembling "real" support channels. The company is massively profitable by sheer scale - by making a small amount of money per year off of a vast number of users. This applies to Google as well - or really any ad-based…

The guy is an ad buyer although, so they are still missing support for their traditional revenue streams for small customers. Even comcast gives you customer support if you only buy things for $20/month from them ;)
Post reply on HN