Here's my guess at what happened: How was the account hijacked? Via cookie theft. The author installed malware, maybe some dodgy windows binaries or malicious browser extensions. No amount or type of 2FA on sign-in will protect you against the session cookie being stolen. (Now, additional 2FA on sensitive actions might). Why was the account was banned with such finality, with no chance of appeal? Probably for somethi…
That is correct; ads keep running while account is blocked.
Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
261–270 of 388 posts
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#262Earlier quoted context omitted.
> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…
Ok, so the scenario is I buy a headset, create a fake account, load up on games, then abuse the account to get all of it refunded so as to effectively have free use of the games for the period of time. But I still had to buy a headset, put in a real credit card, pass Facebooks initial "real identity" checks etc. With real human review and some basic policies to prevent repeat abuse this doesn't seem like something th…
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#263What is the point of setting up a hardware or Google Authenticator-type 2FA solution when most companies will fallback to SMS? Is there a way to prevent the SMS fallback (last I checked it was 'No' for most sites except maybe Google if I remember, and then you still had to go in and manually delete it)? Does a master list exist of companies that don't use SMS, or allow the user to exclude it? Otherwise it seems like…
2FA (is supposed to) mean you have both factors, not one or the other. It's strictly more secure that either alone, even if SMS sucks.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#264Earlier quoted context omitted.
> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…
An easy way out would be to ban the account from everything except accessing the purchases.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#265I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…
Why are we buying this account-linked physical shit. Just pretend the headsets are not a viable product to purchase if they can be remotely bricked by a company you have no leverage over. Get a competitor product or go without.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#266Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#267In other news, I built and deployed a "2FA Mule" last weekend. It's a stock android phone with no google account and no apps installed except for "SMS Forwarder"[1]. It is configured to forward all SMS to an email address via encrypted SMTP. This means that I can receive these 2FA codes anywhere I have Internet access - such as an airplane or newly arrived in a foreign country where my SIM card does not work. The "2F…
I'm going to have to steal that.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#268Google makes a point in their ads for the chromebook that you need a Google account to login, which my brain immediately translates into "could be randomly bricked at any time". It's possible that's not true, but there's such an endless stream of these stories, that that's the attitude you have to take.
If your Google account is borked, nothing is unrecoverable from the computer and any other account can log into it.
That being said, you will be screwed in various other ways, mainly that all of the information you'd lose because it was normally stored on the you've now lost because you got the ban hammer
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#269Earlier quoted context omitted.
3 billion active users. If 0.1% have account issues in a year, that's 8,200 support tickets per day. If each of those takes 20 minutes to resolve, then you'd need 115 support techs ... for three shifts, or about 350 total. Oh, and covering several languages. I'm guessing my 0.1% issue rate is low by a factor of 10--100. Resolution time may also be generous. Increase all other values correspondingly.
10 billions profit a year, seems like enough money for user support
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#270i love how they say it cant be reversed in the warning. that is an absolute falsehood. its worded in a way that leads you to believe its final and not possible to undo, which is entirely false. source: recently had to help someone get a developer account out of this position, account was reinstated. just gotta know the right people i guess? this is the biggest example of all, to me, why big tech needs regulating... i…