Earlier quoted context omitted.
> if you lose them your account is gone IMO, this is way too extreme for almost everybody. There needs to be some sort of happy medium so that a person who's lost everything they own (e.g., house fire) can get their account back somehow still. Two ideas I had: 1. When you set up your account, provide your legal name, date of birth, and a photo. If you need to reset 2FA, go somewhere in person with a government-issued…
I've always thought the Post Office should offer something like Option #1.
Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
211–220 of 388 posts
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#212I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…
And then people wonder why I'm never buying anything digital. That's the reason. Buying digital makes your continued access to the thing dependent on your account being not banned and the servers being up. In other words, even if you "own" it, you're still at the mercy of the seller. But if you bought something on a physical medium (or torrented), no one could take it away from you.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#213Earlier quoted context omitted.
That's pretty silly. Should I be able to use Amazon APIs to host reviews for my competing ecommerce site? Or be able to proxy user search requests to google and then intersperse my own advertisements in the results for my web search service?
I'm not the person you're responding to, but I would say unequivocally and unironically, yes! The end result is more competition, lower prices, and more options for the end consumer. Sure the raw idea of this mechanism is a little naive and could be refined, but the outcomes you paint sound totally reasonable to me... think of this as a creative way to apply a new kind of tax to the criminally undertaxed big tech beh…
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#214Earlier quoted context omitted.
It's trite at this point that someone will respond that the users aren't the customers, they're the product, but it's trite because it's often correct, and deserves to be said, so I guess I'll be the one to say it this time. The sad thing is that this person actually is a customer because they bought a product and pay for things on it, but Facebook still doesn't realize that, or more likely these customers are such a…
> this person actually is a customer That's the reason the "you're not the customer" line is just a distraction. It totally misses the point that Facebook doesn't have customers any more than any other first world power has. Facebook has treaties with governments and follow laws when it's less costly than breaking them. FTC actions are like one country taking another to the WTO -- not something to ignore, but not rea…
I don't think it is. If Facebook wasn't coming from a place such as that, then we wouldn't necessarily see them act like this. It's not just about size.
> Facebook has treaties with governments and follow laws when it's less costly than breaking them.
So do most large companies, but they don't all act the same to their customers. Apple may be guilty of other ways of mistreating their customers, but to my knowledge they're mostly innocent of this specific brand of it, and anything you want to attribute to Facebook's size that you can't attribute to any of the other tech big 5[1] should be examined for whether that's really the relevant underlying cause.
1: https://www.fastcompany.com/90651160/facebook-is-now-the-fif...
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#215Earlier quoted context omitted.
Why are we buying this account-linked physical shit. Just pretend the headsets are not a viable product to purchase if they can be remotely bricked by a company you have no leverage over. Get a competitor product or go without.
Do you use a smartphone?
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#216So in this story Facebook was responsible for $50 of charges, a business disruption and a huge and ongoing hassle. And Facebook refuses so much as to pick up the phone to discuss it. In the old days the equivalent would have been one of those roach motel businesses rated 'F' on the Better Business Bureau, buckets arrayed on the floor to catch rain leaking through the roof. And yet in this day it's one of the most pro…
There are many motels, but Facebook has a monopoly on facebook accounts. If you could make a facebook account somewhere else, you could "take your business elsewhere". Last I checked, FB actively banned using their APIs to build a competing product. I wish the government would make it mandatory to offer federation if you had, say, more than a million customers. But alas, governments rarely do what's convenient for cu…
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#217I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…
> It also reflects the non-recoverable portion of the cost to most users And then people wonder why I'm never buying anything digital. That's the reason. Buying digital makes your continued access to the thing dependent on your account being not banned and the servers being up. In other words, even if you "own" it, you're still at the mercy of the seller. But if you bought something on a physical medium (or torrented…
Remember people who used to have a huge collection of video tapes or CDs? They hardly used them for anything except decoration of their living room. Hoarding old crap that you never use isn't the best use of money.
Physical things can readily be taken away in divorces and debt recovery or less common things like police seizure if you're suspected of a crime. The world's richest man had half his wealth taken like that. Property rights aren't as secure as you think.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#218So in this story Facebook was responsible for $50 of charges, a business disruption and a huge and ongoing hassle. And Facebook refuses so much as to pick up the phone to discuss it. In the old days the equivalent would have been one of those roach motel businesses rated 'F' on the Better Business Bureau, buckets arrayed on the floor to catch rain leaking through the roof. And yet in this day it's one of the most pro…
There are many motels, but Facebook has a monopoly on facebook accounts. If you could make a facebook account somewhere else, you could "take your business elsewhere". Last I checked, FB actively banned using their APIs to build a competing product. I wish the government would make it mandatory to offer federation if you had, say, more than a million customers. But alas, governments rarely do what's convenient for cu…
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#219What is the point of setting up a hardware or Google Authenticator-type 2FA solution when most companies will fallback to SMS? Is there a way to prevent the SMS fallback (last I checked it was 'No' for most sites except maybe Google if I remember, and then you still had to go in and manually delete it)? Does a master list exist of companies that don't use SMS, or allow the user to exclude it? Otherwise it seems like…
Most people probably use it because it’s more convenient and reliable than SMS, not because it’s more secure.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#220Earlier quoted context omitted.
A simplified and inaccurate version: - You and I share a secret at my first login. Let's say our shared secret is "wibble". - For any subsequent successful login with my username and password, for the second factor I send you the last six digits of the SHA1-hash of ("wibble" XOR current timestamp) - You calculate the second factor yourself as well by doing the same operation (you have stored "wibble" for my username,…
I always wondered, doesn't that require the clocks to be synchronized? Like, what happens if I set my phone to a different time? What if the server has lost connectivity to an NTP service and its clock is a few minutes off?
Some systems have some extra magic that allow the server to adjust for each device's clock skew; this was particularly important for hardware tokens that didn't have network connections. To imagine how that might work, suppose the server normally accepts responses that are valid at times t-2, t-1, t (the current time, per the server), t+1, and t+2. If a user consistently replies with the t-1 token, we know that her device is running slightly behind and we can instead authenticate against t-3, t-2, t-1, t, t+1.