Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

231–240 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#232
post #145
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…

As long as they don't get the full amount back then piracy will be the path of least resistance for that kind of abuse.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#233
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

> It also reflects the non-recoverable portion of the cost to most users And then people wonder why I'm never buying anything digital. That's the reason. Buying digital makes your continued access to the thing dependent on your account being not banned and the servers being up. In other words, even if you "own" it, you're still at the mercy of the seller. But if you bought something on a physical medium (or torrented…

This depends on how it works.

It is perfectly possible for games to be sold digitally online with no drm, such that you could easily (without requiring uncommon technical know-how) copy it to a flash drive and run it on a computer with no internet connection.

Of course, games sold this way are extremely easy to pirate, because it is, essentially, pre-cracked. But one can distribute a product like this, and on occasion people do.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#234
post #185

Earlier quoted context omitted.

An easy way out would be to ban the account from everything except accessing the purchases.

yes ... that's what I hope and expect would be the outcome if this was enforced on Facebook. They will try to claim that the social features are essential to the platform and therefore cannot be disabled but it would not hold up based on current Oculus ecosystem.

Even if it did their options should be to either

1. Allow the user to play it's purchases, just without social features.

2. Refund the user

If this was the law they'd figure it out I promise you that.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#235
post #165
post #145

Earlier quoted context omitted.

> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…

Ok, so the scenario is I buy a headset, create a fake account, load up on games, then abuse the account to get all of it refunded so as to effectively have free use of the games for the period of time. But I still had to buy a headset, put in a real credit card, pass Facebooks initial "real identity" checks etc. With real human review and some basic policies to prevent repeat abuse this doesn't seem like something th…

It doesn't have to be planned abuse. Another possibility is "I don't use this much anymore and there's no second hand market for my game purchases so I think I'll just get my library refunded." You were going to lose value anyway on not using it, now you get something back.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#236

Earlier quoted context omitted.

> It also reflects the non-recoverable portion of the cost to most users And then people wonder why I'm never buying anything digital. That's the reason. Buying digital makes your continued access to the thing dependent on your account being not banned and the servers being up. In other words, even if you "own" it, you're still at the mercy of the seller. But if you bought something on a physical medium (or torrented…

Just think of it as like paying to see a movie. I bought a $10 app once, used it for what it was for, and now several phones later, I don't know or care what's happened to it. I got my value out of it and don't need to hoard every possession I "buy". Remember people who used to have a huge collection of video tapes or CDs? They hardly used them for anything except decoration of their living room. Hoarding old crap th…

Wow, I really disagree with this. Or, with the implication / point?

Sure, if one buys a newspaper, chances are that one won’t hold on to it for long. But it is important that one can. If one wants to cut out a story from it and hold onto it, perhaps in a scrapbook, one can do so.

It is also important for archival and preservation purposes.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#237
post #48

Earlier quoted context omitted.

Could you describe the types that are non-phishable?

WebAuthn (or its predecessor U2F but that's obsolete, so in green field deployments do WebAuthn) is the only practical non-phishable second factor for ordinary users on the web. You can do this two ways, one of which will make more sense for your web site: 1. PCs/ laptops/ etc. can use little USB hardware devices, from outfits like Yubico, the word to Google or type into your preferred hardware source is "FIDO" altho…

> if you have spare cash and like cool toys FIDO2 is a more capable second generation of the technology.

Why would you want passwordless authentication? Isn't the whole point of 2FA that you have to have something and you have to know something?

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#238
lying piece of snake oil, he is a content writer think about that for a moment.

Facebook spends billions on security, its impossible to hack Facebook, this guy is full of snake oil. his a techie and pretty sure he secured his accounts properly.

i hate these fake as posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#239
post #196

Earlier quoted context omitted.

That’s ok with me - FB has enough money.

The problem being described is not FB losing money, it's grifters and scammers gaining money.

That's preferable to non-grifters and non-scammers losing money.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#240
post #114
post #84

Earlier quoted context omitted.

Nice. I do something similar but forward it to Slack. I also have it auto-answer 2FA calls and automatically hit the # key. Yeah, call it not real 2FA, but it's really companies that choose to not use U2F are at fault.

"I also have it auto-answer 2FA calls and automatically hit the # key." One year at defcon - maybe 20 years ago - the speaker told an anecdote about a user who had set up a webcam and put their RSA token under it. And we all laughed ... "haha what a dummy ... I can't believe users are so stupid" ... But secretly I thought it was genius.

I've done exactly this. Well, my SO did it at my direction since I was in another country and had forgotten to take the token with me.
Post reply on HN