Earlier quoted context omitted.
Why are we buying this account-linked physical shit. Just pretend the headsets are not a viable product to purchase if they can be remotely bricked by a company you have no leverage over. Get a competitor product or go without.
Do you use a smartphone?
Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
271–280 of 388 posts
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#272Earlier quoted context omitted.
I'm not the person you're responding to, but I would say unequivocally and unironically, yes! The end result is more competition, lower prices, and more options for the end consumer. Sure the raw idea of this mechanism is a little naive and could be refined, but the outcomes you paint sound totally reasonable to me... think of this as a creative way to apply a new kind of tax to the criminally undertaxed big tech beh…
If you come up with a cool service on top of Amazon's API, should Amazon be allowed to use your APIs to scrape your service data and use it in their offering?
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#273So in this story Facebook was responsible for $50 of charges, a business disruption and a huge and ongoing hassle. And Facebook refuses so much as to pick up the phone to discuss it. In the old days the equivalent would have been one of those roach motel businesses rated 'F' on the Better Business Bureau, buckets arrayed on the floor to catch rain leaking through the roof. And yet in this day it's one of the most pro…
There are many motels, but Facebook has a monopoly on facebook accounts. If you could make a facebook account somewhere else, you could "take your business elsewhere". Last I checked, FB actively banned using their APIs to build a competing product. I wish the government would make it mandatory to offer federation if you had, say, more than a million customers. But alas, governments rarely do what's convenient for cu…
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#274Here's my guess at what happened: How was the account hijacked? Via cookie theft. The author installed malware, maybe some dodgy windows binaries or malicious browser extensions. No amount or type of 2FA on sign-in will protect you against the session cookie being stolen. (Now, additional 2FA on sensitive actions might). Why was the account was banned with such finality, with no chance of appeal? Probably for somethi…
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#275Earlier quoted context omitted.
And of course client side certificates. It's a pity they are rarely available as an option on public websites.
The UX for client certificates is horrific , especially if you choose the more secure approach of storing them on a smart card.
webauthn basically forces use of HTTP as the application level protocol, whereas a client side TLS certificate will work regardless of which application protocol is in use.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#276Earlier quoted context omitted.
> And Facebook refuses so much as to pick up the phone to discuss it. It's part of the business model - each FB user generates so little revenue for the company that you can't afford to offer anything resembling "real" support channels. The company is massively profitable by sheer scale - by making a small amount of money per year off of a vast number of users. This applies to Google as well - or really any ad-based…
> One of many reasons I pay Google to host my email rather than use a free Gmail - when you are generating a non-negligible revenue stream suddenly companies' willingness to answer emails and pick up phones increases. If you think that does any difference, I hope you good luck. Google is unreachable for support, even if you are a paying user.
...They accidentally CC'd in a public mailing list into our discussion and leaked enough information that someone would be able to use the automated support system to change the company AdWords password. There was basically no way of contacting anyone further, the engineer couldn't contact anyone that could help us. We ended up making a new adwords account.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#277I can't tell you how many obviously-fake profiles and scammers I report, and see other people commenting about reporting, only for them to still be around days, weeks, sometimes even months later. All of these were obvious scammers directing traffic to a single profile - some forex guru or whatever. Shilling get-rich-quick schemes doesn't meet Facebook's definition of "spam", apparently. https://imgur.com/a/xihRPwE W…
> You anonymously reported ...
> You *anonymously* reported ...
> *You* *anonymously* reported...
"Greetings, human. We have masked your identity from... o̧u͢rs̢e͘lv́e҉s."
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#278Earlier quoted context omitted.
My smartphone cannot be remotely turned into an overpriced wheel chock by someone in a call center.
Apple at least can absolutely do this, that's what the purpose of reporting a device stolen is.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#279Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#280I don't think Facebook 2FA is terribly secure. They definitely err on the side of usability. I was using TOTP on Instagram and I forgot to backup my Google Authenticator before wiping my iPhone. But I was then able to just go the the settings on a logged-in device and disable 2FA without 2FA. And it wasn't like I had logged into that device recently, either. I only had to 2FA Instagram once, years ago.
I wonder if having 2FA made it worse ... I can see the review process taking the enablement of 2FA as proof he really did the abuse and discounting the possibility that his account was hacked.
I was going to make the following point to the parent comment then read this reply and realized the situation is even worse:
1. (According to parent comment) 2FA can be disabled without 2FA
2. Having 2FA makes you look studious/thorough/decisive
Presumably the tech support is indeed told to pay attention to 2FA.
Presumably the entire management/instruction chain there isn't aware of the fact it can be turned off without 2FA confirmation, which effectively neuters it.
So you have the worst of all the worlds. Niiice.