Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

271–280 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#271

Earlier quoted context omitted.

Why are we buying this account-linked physical shit. Just pretend the headsets are not a viable product to purchase if they can be remotely bricked by a company you have no leverage over. Get a competitor product or go without.

Do you use a smartphone?

You can use a smartphone without linking to a faang account. Though it still has a device ID which it uses to talk to some infra if you keep the stock firmware.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#272

Earlier quoted context omitted.

I'm not the person you're responding to, but I would say unequivocally and unironically, yes! The end result is more competition, lower prices, and more options for the end consumer. Sure the raw idea of this mechanism is a little naive and could be refined, but the outcomes you paint sound totally reasonable to me... think of this as a creative way to apply a new kind of tax to the criminally undertaxed big tech beh…

If you come up with a cool service on top of Amazon's API, should Amazon be allowed to use your APIs to scrape your service data and use it in their offering?

If you get above users, sure why not? It doesn't have to be free, maybe some sort of auditing service could determine a "fair" price. But it would be open without the possibility of shutting it down in the future unless maybe Amazon themselves ditches that API internally.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#273

So in this story Facebook was responsible for $50 of charges, a business disruption and a huge and ongoing hassle. And Facebook refuses so much as to pick up the phone to discuss it. In the old days the equivalent would have been one of those roach motel businesses rated 'F' on the Better Business Bureau, buckets arrayed on the floor to catch rain leaking through the roof. And yet in this day it's one of the most pro…

There are many motels, but Facebook has a monopoly on facebook accounts. If you could make a facebook account somewhere else, you could "take your business elsewhere". Last I checked, FB actively banned using their APIs to build a competing product. I wish the government would make it mandatory to offer federation if you had, say, more than a million customers. But alas, governments rarely do what's convenient for cu…

I had an economist friend of mine suggest this a few years ago in a conversation (I don't think it was a novel idea of his, it's just the first time I heard it). At the time I thought it was ridiculous and disagreed. But I've really started to come around to liking the idea over time.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#274
post #22

Here's my guess at what happened: How was the account hijacked? Via cookie theft. The author installed malware, maybe some dodgy windows binaries or malicious browser extensions. No amount or type of 2FA on sign-in will protect you against the session cookie being stolen. (Now, additional 2FA on sensitive actions might). Why was the account was banned with such finality, with no chance of appeal? Probably for somethi…

Unless it used the same IP / UA it seems unlikely? Every time I switch IPs I have to re auth to FB ads. Even on the exact same browser session.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#275
post #107

Earlier quoted context omitted.

And of course client side certificates. It's a pity they are rarely available as an option on public websites.

The UX for client certificates is horrific , especially if you choose the more secure approach of storing them on a smart card.

It certainly would make sense to improve the UX as opposed to coming up with different implementations.

webauthn basically forces use of HTTP as the application level protocol, whereas a client side TLS certificate will work regardless of which application protocol is in use.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#276

Earlier quoted context omitted.

> And Facebook refuses so much as to pick up the phone to discuss it. It's part of the business model - each FB user generates so little revenue for the company that you can't afford to offer anything resembling "real" support channels. The company is massively profitable by sheer scale - by making a small amount of money per year off of a vast number of users. This applies to Google as well - or really any ad-based…

> One of many reasons I pay Google to host my email rather than use a free Gmail - when you are generating a non-negligible revenue stream suddenly companies' willingness to answer emails and pick up phones increases. If you think that does any difference, I hope you good luck. Google is unreachable for support, even if you are a paying user.

I managed to get in touch with a Google engineer once for help with some Adwords API stuff (our company is a large adwords agency).

...They accidentally CC'd in a public mailing list into our discussion and leaked enough information that someone would be able to use the automated support system to change the company AdWords password. There was basically no way of contacting anyone further, the engineer couldn't contact anyone that could help us. We ended up making a new adwords account.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#277

I can't tell you how many obviously-fake profiles and scammers I report, and see other people commenting about reporting, only for them to still be around days, weeks, sometimes even months later. All of these were obvious scammers directing traffic to a single profile - some forex guru or whatever. Shilling get-rich-quick schemes doesn't meet Facebook's definition of "spam", apparently. https://imgur.com/a/xihRPwE W…

I love the rhetoric:

> You anonymously reported ...

> You *anonymously* reported ...

> *You* *anonymously* reported...

"Greetings, human. We have masked your identity from... o̧u͢rs̢e͘lv́e҉s."

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#278

Earlier quoted context omitted.

My smartphone cannot be remotely turned into an overpriced wheel chock by someone in a call center.

Apple at least can absolutely do this, that's what the purpose of reporting a device stolen is.

Apple also has phone numbers you can call with a human at the other end who can help resolve stuff like this.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#280
post #173
post #10

I don't think Facebook 2FA is terribly secure. They definitely err on the side of usability. I was using TOTP on Instagram and I forgot to backup my Google Authenticator before wiping my iPhone. But I was then able to just go the the settings on a logged-in device and disable 2FA without 2FA. And it wasn't like I had logged into that device recently, either. I only had to 2FA Instagram once, years ago.

I wonder if having 2FA made it worse ... I can see the review process taking the enablement of 2FA as proof he really did the abuse and discounting the possibility that his account was hacked.

Oh meep.

I was going to make the following point to the parent comment then read this reply and realized the situation is even worse:

1. (According to parent comment) 2FA can be disabled without 2FA

2. Having 2FA makes you look studious/thorough/decisive

Presumably the tech support is indeed told to pay attention to 2FA.

Presumably the entire management/instruction chain there isn't aware of the fact it can be turned off without 2FA confirmation, which effectively neuters it.

So you have the worst of all the worlds. Niiice.

Post reply on HN