Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

201–210 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#201
post #167
post #160

Earlier quoted context omitted.

Or have ban groups. Ban someone from having a Facebook profile, buying ads, sending Messages, or having an Instagram profile based on their behavior on those respective sections of the site. Maybe disable a person's multiplayer capabilities if they have a reputation for harassment. But let them keep their hardware running, and access their game library. Seems good for business, tbh. You might not want neo-nazis posti…

Yes, Facebook really doesn't have a convincing argument why they will not just disable the social interaction features when the ban is made on that basis. They will say that they want to build social features into all their software as integral and therefore it is not possible but it doesn't pass muster to me .... it simply isn't that hard to make it conditionally available within apps and if it is that hard then it…

Perhaps they're trying to avoid a situation where banned people get a better experience because they don't have to deal with the social features.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#202
post #108

For those who have worked at Facebook - why in the world are their policies like this? Why is customer support so... unfriendly and unhelpful? No escalations possible? No way to reach anyone?

3 billion active users.

If 0.1% have account issues in a year, that's 8,200 support tickets per day.

If each of those takes 20 minutes to resolve, then you'd need 115 support techs ... for three shifts, or about 350 total.

Oh, and covering several languages.

I'm guessing my 0.1% issue rate is low by a factor of 10--100. Resolution time may also be generous. Increase all other values correspondingly.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#203

Earlier quoted context omitted.

For work things I often have to enter a code from one or another app that expires every few seconds. I've always wondered how exactly that works. Where might I go to find out about that? Is it as straight forward as googling "how two factor authentication works" or is there some other terminology?

A simplified and inaccurate version: - You and I share a secret at my first login. Let's say our shared secret is "wibble". - For any subsequent successful login with my username and password, for the second factor I send you the last six digits of the SHA1-hash of ("wibble" XOR current timestamp) - You calculate the second factor yourself as well by doing the same operation (you have stored "wibble" for my username,…

I always wondered, doesn't that require the clocks to be synchronized?

Like, what happens if I set my phone to a different time?

What if the server has lost connectivity to an NTP service and its clock is a few minutes off?

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#204

Earlier quoted context omitted.

Google is better than all other alternatives in that regard. They have a feature called Advanced Protection where you add your 2FA U2F keys and if you lose them your account is gone. No social engineering possible. https://landing.google.com/advancedprotection/

> if you lose them your account is gone IMO, this is way too extreme for almost everybody. There needs to be some sort of happy medium so that a person who's lost everything they own (e.g., house fire) can get their account back somehow still. Two ideas I had: 1. When you set up your account, provide your legal name, date of birth, and a photo. If you need to reset 2FA, go somewhere in person with a government-issued…

I've always thought the Post Office should offer something like Option #1.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#205
post #193

Earlier quoted context omitted.

There's not really an "abuse" reason to stop people from playing single player games though. What malicious thing would they do with them?

They don't have fine grained banning because the abuse system was made for a user base that pays them no money, so it's a blunt instrument optimized towards cost savings. Steam I've heard is more fine grained, and might just do online gaming bans or communication bans.

Most games I’ve played on my Oculus have been paid, the same as Stream.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#206
post #196

Earlier quoted context omitted.

That’s ok with me - FB has enough money.

The problem being described is not FB losing money, it's grifters and scammers gaining money.

That's ok with me - grifters and scammers don't have enough money.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#207
post #136
post #112

Earlier quoted context omitted.

They don’t. They want to link a new GV account to a real phone number that is not theirs, so that they can use the GV number for other scams. It only works when your phone number doesn’t already have a GV linked to it.

Wouldn't the victim have to send the code back to the scammer for it all to work?

Hey! I want to buy your used Ikea furniture!

Just a quick safety precaution to make sure: I'm going to text you a code, can you just send it back to me to confirm?

Thanks!

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#208
post #108

For those who have worked at Facebook - why in the world are their policies like this? Why is customer support so... unfriendly and unhelpful? No escalations possible? No way to reach anyone?

"Customer support" is someone in third world paid 1 dollar per hour, who barely speaks English and does not care about anything - nobody reviews quality of their work, and even if quality is reviewed, they are fired, but nobody reviews "old cases".

Probably some person randomly clicking "accept" and "deny".

Other question is, why there is no escalation; even paid one. Although probably everyone would escalate.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#209
post #145
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…

> This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior.

The status who incentivizes abusive behaviour from the company, and cheapens the cost of mistreating users

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#210
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

This is why you should never buy devices that have to be tethered to a company's servers.

Logitech Harmony remote users just learned this the hard way too. It means you can be ripped off at any moment. People need to stop voting for this offensive BS.

Speaking of offensive: Two posts closer together than an hour and 10 minutes is "too fast" for this bullshit forum. Talk about offensive: They let you type out a question, comment, or reply and THEN say, NO, YOU CAN'T POST.

First of all, fuck you HN. Second, FUCK YOU MORE for deliberately WASTING PEOPLE'S TIME by letting them invoke the comment function when you know you're not going to let them post. Unbelievable.

Post reply on HN