I don't think Facebook 2FA is terribly secure. They definitely err on the side of usability. I was using TOTP on Instagram and I forgot to backup my Google Authenticator before wiping my iPhone. But I was then able to just go the the settings on a logged-in device and disable 2FA without 2FA. And it wasn't like I had logged into that device recently, either. I only had to 2FA Instagram once, years ago.
Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
281–290 of 388 posts
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#282Earlier quoted context omitted.
> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…
Ok, so the scenario is I buy a headset, create a fake account, load up on games, then abuse the account to get all of it refunded so as to effectively have free use of the games for the period of time. But I still had to buy a headset, put in a real credit card, pass Facebooks initial "real identity" checks etc. With real human review and some basic policies to prevent repeat abuse this doesn't seem like something th…
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#283Earlier quoted context omitted.
It doesn't have to be planned abuse. Another possibility is "I don't use this much anymore and there's no second hand market for my game purchases so I think I'll just get my library refunded." You were going to lose value anyway on not using it, now you get something back.
"there's no second hand market for my game purchases" is an integral part of that reasoning. Why don't we just fix that too.
It's that brand new price Facebook would be refunding after a ban.
So the same perverse incentive exists even with a 2nd hand market.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#284Earlier quoted context omitted.
> refunding a significant portion of the cost of the user's Oculus library when they ban the account This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.) The problem here is that Facebook…
An easy way out would be to ban the account from everything except accessing the purchases.
it’s their decision to introduce this account, when there is really no need for it, let it be their problem to fully refund everything when this affects you. the solution is simple: quit forcing people to use the account nobody asked for.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#285Earlier quoted context omitted.
What you're describing here isn't exclusive to hardware tokens and nothing preventing software from checking the domain using TOTP.
How? TOTP does not embed the domain, as it is generated on a separate device which does not communicate with your browser, and does not know the target domain. TOTP is literally HMAC(shared-secret, time-interval) mapped to a short range (e.g. mod 10^6).
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#286Earlier quoted context omitted.
3 billion active users. If 0.1% have account issues in a year, that's 8,200 support tickets per day. If each of those takes 20 minutes to resolve, then you'd need 115 support techs ... for three shifts, or about 350 total. Oh, and covering several languages. I'm guessing my 0.1% issue rate is low by a factor of 10--100. Resolution time may also be generous. Increase all other values correspondingly.
10 billions profit a year, seems like enough money for user support
An enterprise software company I was closely familiar with in the 1990s budgeted about $50/call for user support. Mind that was 20+ years ago, and it was enterprise, rather than end-user support. But odds are strong that one service call per user eats up all, or multiples of, the actual worth of that user to Facebook. Cutting the account loose may well be the rational choice for the company.
ARPU varies by region. Within the US it's closer to $110/yr, in Europe, $35/yr, Asia & Pacific, $10/yr. Expect that support offerings are going to be measured against that, though possibly with a consideration as well to future growth and economic development.
At $25/call and servicing 1% of users/year, that's $750 million in support alone. If the cost or rates are doubled ... the maths are pretty easy.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#287Earlier quoted context omitted.
They don't have fine grained banning because the abuse system was made for a user base that pays them no money, so it's a blunt instrument optimized towards cost savings. Steam I've heard is more fine grained, and might just do online gaming bans or communication bans.
Most games I’ve played on my Oculus have been paid, the same as Stream.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#288Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#289IDEA: Build a service that identifies all the Single Sign On accounts tied to your Facebook/Google/GitHub/Twitter accounts for you and gives you a nice list and instructions on how to separate out the accounts with links if possible.
Thinking about it for a bit, I'm sadly hesitant that it might need to be built as a browser extension or mobile app, rather than a website, because none of these services provide programmatically-accessible (even read-only) feeds of what you're looking for, so you'd need to scrape everything. This brings up two issues: 1) the headache of IP ratelimiting (and/or flat-out IP bans from trigger-happy systems optimized for fighting fraud/bots hosted on cloud infrastructure). IIUC there are proxy services that you can outsource the workaround problem to, but this is awkward to get behind in the face of 2), which is that users would need to input their actual usernames and passwords so that the service could request the account page with the details on it in order to scrape the data.
Given that these are broadly web services poked at via HTTPS, you could potentially get everything you needed from a browser extension (as long as the service doesn't require you to set any HTTP headers that extensions aren't allowed to touch).
The second possibility is using an app. Writing a thin layer that lets you craft custom HTTPS/whatever requests from a WebView would probably be the most straightforward approach.
The main issue with both the extension and app approaches is that they code-dump both the idea and methodology of "here is how to do X" into the hands of the IQ-99 skiddie group (especially with an extension). So now you have more people running around scraping pages and whatnot and trying to figure out how to weaponize everything. Probably won't go anywhere (in terms of producing actual attacks), but the noise may potentially make your life harder.
The least-complex solution seems to just be a giant boring list of links, for example:
- https://myaccount.google.com/permissions
- https://twitter.com/settings/connected_apps, https://twitter.com/settings/connected_accounts
- https://github.com/settings/apps/authorizations, https://github.com/settings/applications, https://github.com/settings/installations, https://github.com/settings/apps, https://github.com/settings/developers, https://github.com/settings/tokens
Hmm, that's kind of all over the place for some things. A single aggregate view that combines everything could definitely be very interesting...
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#290I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account. This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the co…
Why are we buying this account-linked physical shit. Just pretend the headsets are not a viable product to purchase if they can be remotely bricked by a company you have no leverage over. Get a competitor product or go without.