Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

211–220 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#211

Earlier quoted context omitted.

> if you lose them your account is gone IMO, this is way too extreme for almost everybody. There needs to be some sort of happy medium so that a person who's lost everything they own (e.g., house fire) can get their account back somehow still. Two ideas I had: 1. When you set up your account, provide your legal name, date of birth, and a photo. If you need to reset 2FA, go somewhere in person with a government-issued…

I've always thought the Post Office should offer something like Option #1.

In another universe, the Post Office manages the email services, too. Sigh ...

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#212
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

> It also reflects the non-recoverable portion of the cost to most users

And then people wonder why I'm never buying anything digital. That's the reason. Buying digital makes your continued access to the thing dependent on your account being not banned and the servers being up. In other words, even if you "own" it, you're still at the mercy of the seller. But if you bought something on a physical medium (or torrented), no one could take it away from you.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#213

Earlier quoted context omitted.

That's pretty silly. Should I be able to use Amazon APIs to host reviews for my competing ecommerce site? Or be able to proxy user search requests to google and then intersperse my own advertisements in the results for my web search service?

I'm not the person you're responding to, but I would say unequivocally and unironically, yes! The end result is more competition, lower prices, and more options for the end consumer. Sure the raw idea of this mechanism is a little naive and could be refined, but the outcomes you paint sound totally reasonable to me... think of this as a creative way to apply a new kind of tax to the criminally undertaxed big tech beh…

You are allowed to do that(as far as I understand scraping legality), but google/amazon/facebook are also well within their rights to blacklist your IPs, or implement other methods to prevent scraping of their IP(intellectual property in this case).

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#214
post #81

Earlier quoted context omitted.

It's trite at this point that someone will respond that the users aren't the customers, they're the product, but it's trite because it's often correct, and deserves to be said, so I guess I'll be the one to say it this time. The sad thing is that this person actually is a customer because they bought a product and pay for things on it, but Facebook still doesn't realize that, or more likely these customers are such a…

> this person actually is a customer That's the reason the "you're not the customer" line is just a distraction. It totally misses the point that Facebook doesn't have customers any more than any other first world power has. Facebook has treaties with governments and follow laws when it's less costly than breaking them. FTC actions are like one country taking another to the WTO -- not something to ignore, but not rea…

> That's the reason the "you're not the customer" line is just a distraction.

I don't think it is. If Facebook wasn't coming from a place such as that, then we wouldn't necessarily see them act like this. It's not just about size.

> Facebook has treaties with governments and follow laws when it's less costly than breaking them.

So do most large companies, but they don't all act the same to their customers. Apple may be guilty of other ways of mistreating their customers, but to my knowledge they're mostly innocent of this specific brand of it, and anything you want to attribute to Facebook's size that you can't attribute to any of the other tech big 5[1] should be examined for whether that's really the relevant underlying cause.

1: https://www.fastcompany.com/90651160/facebook-is-now-the-fif...

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#215

Earlier quoted context omitted.

Why are we buying this account-linked physical shit. Just pretend the headsets are not a viable product to purchase if they can be remotely bricked by a company you have no leverage over. Get a competitor product or go without.

Do you use a smartphone?

You can disable Google services on Android. There's literally a button to do that if you know where to look.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#216

So in this story Facebook was responsible for $50 of charges, a business disruption and a huge and ongoing hassle. And Facebook refuses so much as to pick up the phone to discuss it. In the old days the equivalent would have been one of those roach motel businesses rated 'F' on the Better Business Bureau, buckets arrayed on the floor to catch rain leaking through the roof. And yet in this day it's one of the most pro…

There are many motels, but Facebook has a monopoly on facebook accounts. If you could make a facebook account somewhere else, you could "take your business elsewhere". Last I checked, FB actively banned using their APIs to build a competing product. I wish the government would make it mandatory to offer federation if you had, say, more than a million customers. But alas, governments rarely do what's convenient for cu…

How would you prevent a Cambridge analytica style data "breach"?

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#217
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

> It also reflects the non-recoverable portion of the cost to most users And then people wonder why I'm never buying anything digital. That's the reason. Buying digital makes your continued access to the thing dependent on your account being not banned and the servers being up. In other words, even if you "own" it, you're still at the mercy of the seller. But if you bought something on a physical medium (or torrented…

Just think of it as like paying to see a movie. I bought a $10 app once, used it for what it was for, and now several phones later, I don't know or care what's happened to it. I got my value out of it and don't need to hoard every possession I "buy".

Remember people who used to have a huge collection of video tapes or CDs? They hardly used them for anything except decoration of their living room. Hoarding old crap that you never use isn't the best use of money.

Physical things can readily be taken away in divorces and debt recovery or less common things like police seizure if you're suspected of a crime. The world's richest man had half his wealth taken like that. Property rights aren't as secure as you think.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#218

So in this story Facebook was responsible for $50 of charges, a business disruption and a huge and ongoing hassle. And Facebook refuses so much as to pick up the phone to discuss it. In the old days the equivalent would have been one of those roach motel businesses rated 'F' on the Better Business Bureau, buckets arrayed on the floor to catch rain leaking through the roof. And yet in this day it's one of the most pro…

There are many motels, but Facebook has a monopoly on facebook accounts. If you could make a facebook account somewhere else, you could "take your business elsewhere". Last I checked, FB actively banned using their APIs to build a competing product. I wish the government would make it mandatory to offer federation if you had, say, more than a million customers. But alas, governments rarely do what's convenient for cu…

I'm thinking Facebook should be subject to an anti-trust investigation and breakup.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#219

What is the point of setting up a hardware or Google Authenticator-type 2FA solution when most companies will fallback to SMS? Is there a way to prevent the SMS fallback (last I checked it was 'No' for most sites except maybe Google if I remember, and then you still had to go in and manually delete it)? Does a master list exist of companies that don't use SMS, or allow the user to exclude it? Otherwise it seems like…

> What is the point of setting up a hardware or Google Authenticator-type 2FA solution when most companies will fallback to SMS?

Most people probably use it because it’s more convenient and reliable than SMS, not because it’s more secure.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#220

Earlier quoted context omitted.

A simplified and inaccurate version: - You and I share a secret at my first login. Let's say our shared secret is "wibble". - For any subsequent successful login with my username and password, for the second factor I send you the last six digits of the SHA1-hash of ("wibble" XOR current timestamp) - You calculate the second factor yourself as well by doing the same operation (you have stored "wibble" for my username,…

I always wondered, doesn't that require the clocks to be synchronized? Like, what happens if I set my phone to a different time? What if the server has lost connectivity to an NTP service and its clock is a few minutes off?

In practice, it's not the exact timestamp, down to the millisecond--there's a window of 30 seconds or so for each code. On top of that, some services will also accept one of the last (or next) few valid codes too. So it needs to be roughly synchronized, but not impractically so.

Some systems have some extra magic that allow the server to adjust for each device's clock skew; this was particularly important for hardware tokens that didn't have network connections. To imagine how that might work, suppose the server normally accepts responses that are valid at times t-2, t-1, t (the current time, per the server), t+1, and t+2. If a user consistently replies with the t-1 token, we know that her device is running slightly behind and we can instead authenticate against t-3, t-2, t-1, t, t+1.

Post reply on HN