Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

251–260 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#251
post #108

For those who have worked at Facebook - why in the world are their policies like this? Why is customer support so... unfriendly and unhelpful? No escalations possible? No way to reach anyone?

3 billion active users. If 0.1% have account issues in a year, that's 8,200 support tickets per day. If each of those takes 20 minutes to resolve, then you'd need 115 support techs ... for three shifts, or about 350 total. Oh, and covering several languages. I'm guessing my 0.1% issue rate is low by a factor of 10--100. Resolution time may also be generous. Increase all other values correspondingly.

10 billions profit a year, seems like enough money for user support

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#252
post #235
post #165

Earlier quoted context omitted.

Ok, so the scenario is I buy a headset, create a fake account, load up on games, then abuse the account to get all of it refunded so as to effectively have free use of the games for the period of time. But I still had to buy a headset, put in a real credit card, pass Facebooks initial "real identity" checks etc. With real human review and some basic policies to prevent repeat abuse this doesn't seem like something th…

It doesn't have to be planned abuse. Another possibility is "I don't use this much anymore and there's no second hand market for my game purchases so I think I'll just get my library refunded." You were going to lose value anyway on not using it, now you get something back.

"there's no second hand market for my game purchases" is an integral part of that reasoning. Why don't we just fix that too.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#253
post #235

Earlier quoted context omitted.

It doesn't have to be planned abuse. Another possibility is "I don't use this much anymore and there's no second hand market for my game purchases so I think I'll just get my library refunded." You were going to lose value anyway on not using it, now you get something back.

"there's no second hand market for my game purchases" is an integral part of that reasoning. Why don't we just fix that too.

It would still be simpler to go bulk rather than selling piecemeal. But yes, fixing it would be nice regardless.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#254

Earlier quoted context omitted.

WebAuthn (or its predecessor U2F but that's obsolete, so in green field deployments do WebAuthn) is the only practical non-phishable second factor for ordinary users on the web. You can do this two ways, one of which will make more sense for your web site: 1. PCs/ laptops/ etc. can use little USB hardware devices, from outfits like Yubico, the word to Google or type into your preferred hardware source is "FIDO" altho…

> if you have spare cash and like cool toys FIDO2 is a more capable second generation of the technology. Why would you want passwordless authentication? Isn't the whole point of 2FA that you have to have something and you have to know something?

Some people care more about convenience than security. And for everyone else, it doesn't have to be passwordless. You can use a regular password and a FIDO authenticator.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#255
post #107

Earlier quoted context omitted.

WebAuthn (or its predecessor U2F but that's obsolete, so in green field deployments do WebAuthn) is the only practical non-phishable second factor for ordinary users on the web. You can do this two ways, one of which will make more sense for your web site: 1. PCs/ laptops/ etc. can use little USB hardware devices, from outfits like Yubico, the word to Google or type into your preferred hardware source is "FIDO" altho…

And of course client side certificates. It's a pity they are rarely available as an option on public websites.

The UX for client certificates is horrific, especially if you choose the more secure approach of storing them on a smart card.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#256
post #145
post #135

I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…

> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…

They should decouple Facebook and Oculus from each other. They could share the login but should be separate services. I am sure he violated FB terms but did he violate Oculus terms?

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#257

Earlier quoted context omitted.

Beating 2FA is almost always SMS hijacking, but sometimes it's social engineering where the attacker has figured out just the right script to tell support ("oh, I dropped my phone and it won't turn on...") to get it disabled. edit: correction, beating 2FA without phishing -- like in the post where he lost his account while asleep.

> Beating 2FA is almost always SMS hijacking How exactly does this get executed? I'm pretty technical, but I cant fathom exactly how this occurs; You hijack a cell tower, then have some system to listen to un-encrypted SMS traffic?? Plz ELI5

It's an attack on humans, not on technology. You trick their phone carrier's employees into thinking that you're them and that you lost your phone. Then you end up with a SIM card assigned to their phone number, so you receive all of their calls and texts instead of them.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#258

Earlier quoted context omitted.

> It also reflects the non-recoverable portion of the cost to most users And then people wonder why I'm never buying anything digital. That's the reason. Buying digital makes your continued access to the thing dependent on your account being not banned and the servers being up. In other words, even if you "own" it, you're still at the mercy of the seller. But if you bought something on a physical medium (or torrented…

Just think of it as like paying to see a movie. I bought a $10 app once, used it for what it was for, and now several phones later, I don't know or care what's happened to it. I got my value out of it and don't need to hoard every possession I "buy". Remember people who used to have a huge collection of video tapes or CDs? They hardly used them for anything except decoration of their living room. Hoarding old crap th…

You know, many people find collecting things to be a pleasant and relaxing hobby. Perhaps, for some people, having a large collection of tapes or CDs, displaying the collection is part of the point.

People gather enjoyment from different types of things. Not everyone aspires towards minimalism.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#259

Earlier quoted context omitted.

> It also reflects the non-recoverable portion of the cost to most users And then people wonder why I'm never buying anything digital. That's the reason. Buying digital makes your continued access to the thing dependent on your account being not banned and the servers being up. In other words, even if you "own" it, you're still at the mercy of the seller. But if you bought something on a physical medium (or torrented…

Just think of it as like paying to see a movie. I bought a $10 app once, used it for what it was for, and now several phones later, I don't know or care what's happened to it. I got my value out of it and don't need to hoard every possession I "buy". Remember people who used to have a huge collection of video tapes or CDs? They hardly used them for anything except decoration of their living room. Hoarding old crap th…

> The world's richest man had half his wealth taken like that.

If you're talking about Bezos, all of their wealth was made after they got married. The news can say it's "his wealth" but it always belonged to both of them. It's not "taking half his wealth," it's splitting their co-owned assets.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#260

I had someone contact me on Facebook marketplace, we agreed upon a time/price and then they asked for my phone number (which I sadly gave them). Then they said "I'm going to text you a code, so I can verify you are legit". The text I got was from Google Voice's 2FA.....

this happened to me the other day for an item i was selling. at the first mention of a “code”, i told them first come first served and i have other people interested. that ended the conversation.
Post reply on HN