For those who have worked at Facebook - why in the world are their policies like this? Why is customer support so... unfriendly and unhelpful? No escalations possible? No way to reach anyone?
3 billion active users. If 0.1% have account issues in a year, that's 8,200 support tickets per day. If each of those takes 20 minutes to resolve, then you'd need 115 support techs ... for three shifts, or about 350 total. Oh, and covering several languages. I'm guessing my 0.1% issue rate is low by a factor of 10--100. Resolution time may also be generous. Increase all other values correspondingly.
Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
251–260 of 388 posts
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#252Earlier quoted context omitted.
Ok, so the scenario is I buy a headset, create a fake account, load up on games, then abuse the account to get all of it refunded so as to effectively have free use of the games for the period of time. But I still had to buy a headset, put in a real credit card, pass Facebooks initial "real identity" checks etc. With real human review and some basic policies to prevent repeat abuse this doesn't seem like something th…
It doesn't have to be planned abuse. Another possibility is "I don't use this much anymore and there's no second hand market for my game purchases so I think I'll just get my library refunded." You were going to lose value anyway on not using it, now you get something back.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#253Earlier quoted context omitted.
It doesn't have to be planned abuse. Another possibility is "I don't use this much anymore and there's no second hand market for my game purchases so I think I'll just get my library refunded." You were going to lose value anyway on not using it, now you get something back.
"there's no second hand market for my game purchases" is an integral part of that reasoning. Why don't we just fix that too.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#254Earlier quoted context omitted.
WebAuthn (or its predecessor U2F but that's obsolete, so in green field deployments do WebAuthn) is the only practical non-phishable second factor for ordinary users on the web. You can do this two ways, one of which will make more sense for your web site: 1. PCs/ laptops/ etc. can use little USB hardware devices, from outfits like Yubico, the word to Google or type into your preferred hardware source is "FIDO" altho…
> if you have spare cash and like cool toys FIDO2 is a more capable second generation of the technology. Why would you want passwordless authentication? Isn't the whole point of 2FA that you have to have something and you have to know something?
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#255Earlier quoted context omitted.
WebAuthn (or its predecessor U2F but that's obsolete, so in green field deployments do WebAuthn) is the only practical non-phishable second factor for ordinary users on the web. You can do this two ways, one of which will make more sense for your web site: 1. PCs/ laptops/ etc. can use little USB hardware devices, from outfits like Yubico, the word to Google or type into your preferred hardware source is "FIDO" altho…
And of course client side certificates. It's a pity they are rarely available as an option on public websites.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#256I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…
> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#257Earlier quoted context omitted.
Beating 2FA is almost always SMS hijacking, but sometimes it's social engineering where the attacker has figured out just the right script to tell support ("oh, I dropped my phone and it won't turn on...") to get it disabled. edit: correction, beating 2FA without phishing -- like in the post where he lost his account while asleep.
> Beating 2FA is almost always SMS hijacking How exactly does this get executed? I'm pretty technical, but I cant fathom exactly how this occurs; You hijack a cell tower, then have some system to listen to un-encrypted SMS traffic?? Plz ELI5
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#258Earlier quoted context omitted.
> It also reflects the non-recoverable portion of the cost to most users And then people wonder why I'm never buying anything digital. That's the reason. Buying digital makes your continued access to the thing dependent on your account being not banned and the servers being up. In other words, even if you "own" it, you're still at the mercy of the seller. But if you bought something on a physical medium (or torrented…
Just think of it as like paying to see a movie. I bought a $10 app once, used it for what it was for, and now several phones later, I don't know or care what's happened to it. I got my value out of it and don't need to hoard every possession I "buy". Remember people who used to have a huge collection of video tapes or CDs? They hardly used them for anything except decoration of their living room. Hoarding old crap th…
People gather enjoyment from different types of things. Not everyone aspires towards minimalism.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#259Earlier quoted context omitted.
> It also reflects the non-recoverable portion of the cost to most users And then people wonder why I'm never buying anything digital. That's the reason. Buying digital makes your continued access to the thing dependent on your account being not banned and the servers being up. In other words, even if you "own" it, you're still at the mercy of the seller. But if you bought something on a physical medium (or torrented…
Just think of it as like paying to see a movie. I bought a $10 app once, used it for what it was for, and now several phones later, I don't know or care what's happened to it. I got my value out of it and don't need to hoard every possession I "buy". Remember people who used to have a huge collection of video tapes or CDs? They hardly used them for anything except decoration of their living room. Hoarding old crap th…
If you're talking about Bezos, all of their wealth was made after they got married. The news can say it's "his wealth" but it always belonged to both of them. It's not "taking half his wealth," it's splitting their co-owned assets.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#260I had someone contact me on Facebook marketplace, we agreed upon a time/price and then they asked for my phone number (which I sadly gave them). Then they said "I'm going to text you a code, so I can verify you are legit". The text I got was from Google Voice's 2FA.....