Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

291–300 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#291

Fascinating blog post. However I don’t know why it took him so long to reach out to Facebook support, everyone knows that to get your account unlocked you just need to write a viral blog post about your experience and use your existing popularity to ensure someone at Facebook reads it, realises you’re not one of their typical peasant end users and unlocks your account for you.

Can confirm, wife had a similar issue and tried to buy an oculus to get in touch with a human - said person could not help at all. Ended up having to use her network to get in touch with a Facebook employee who got it handled immediately.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#293

Earlier quoted context omitted.

> One of many reasons I pay Google to host my email rather than use a free Gmail - when you are generating a non-negligible revenue stream suddenly companies' willingness to answer emails and pick up phones increases. If you think that does any difference, I hope you good luck. Google is unreachable for support, even if you are a paying user.

I managed to get in touch with a Google engineer once for help with some Adwords API stuff (our company is a large adwords agency). ...They accidentally CC'd in a public mailing list into our discussion and leaked enough information that someone would be able to use the automated support system to change the company AdWords password. There was basically no way of contacting anyone further, the engineer couldn't conta…

I might as well been the engineer that reached out toward you. But in the end, I was let go as support is not earned any metric into performance.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#294

Earlier quoted context omitted.

> PCs/ laptops/ etc. can use little USB hardware devices, from outfits like Yubico This is actually built into most computers now -- Windows Hello, and Apple has something similar. Websites can check the attestation response to specifically block those, however. (Seems like Github allows it, and I've written code that allows it.) > I think some iPhones do facial recognition instead? Yup, they use whatever you use to…

> Websites can check the attestation response to specifically block those, however. (Seems like Github allows it, and I've written code that allows it.) For the client side of things WebAuthn contains a standard option to block/allow "platform" authenticators, which I empirically know includes Windows Hello, and I'm not sure about Apple's or other equivalents. Of course you'd still want to verify the attestation on t…

> Of course you'd still want to verify the attestation on the server side.

You almost certainly do not want to do this for a public web site. If you insist on attestation right thinking people will hit "No" and block the site.

Think about it, what is attestation doing for you in this scenario? You're saying that you don't trust your users/ customers to pick the authentication methods that work for them, and instead you're going to insist on methods you prefer. Do you also choose each user's passwords? "No, sorry, that resembles an English word, we have selected the password 48'J3X$q)M3NBfr_2 for you instead" ?

In a corporate environment this could make sense. If you issue every employee a $100 FooCorp Security Key with their photo engraved on it, maybe you decide to require attestation that the keys used are FooCorp brand keys to prevent employees adding some off-brand Yubico product. I don't know whether that's a good idea, but it's no crazier than lots of corporate policies, however doing this for a public site makes no sense, please just skip attestation.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#295

Earlier quoted context omitted.

> if you lose them your account is gone IMO, this is way too extreme for almost everybody. There needs to be some sort of happy medium so that a person who's lost everything they own (e.g., house fire) can get their account back somehow still. Two ideas I had: 1. When you set up your account, provide your legal name, date of birth, and a photo. If you need to reset 2FA, go somewhere in person with a government-issued…

Advanced Protection does have the account recovery. https://landing.google.com/advancedprotection/faq/ It is just very slow as it's a human process. There's very little reason you shouldn't use Advanced Protection, if your account is important enough.

Big caveat being you can no longer use the account to develop things with the Google API or use some third party clients (e.g. rclone).

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#296
post #275

Earlier quoted context omitted.

The UX for client certificates is horrific , especially if you choose the more secure approach of storing them on a smart card.

It certainly would make sense to improve the UX as opposed to coming up with different implementations. webauthn basically forces use of HTTP as the application level protocol, whereas a client side TLS certificate will work regardless of which application protocol is in use.

Client certificates, as the name might hint, certify your identity. But a big thrust of technologies like U2F and WebAuthn was not to do that, for privacy reasons.

My FIDO authenticator has no idea who I am, no opinion who I am, so you can't use it to do identity correlation. It's only useful for the very specific problem we wanted to solve "Are you still you?" "Yes".

In contrast a client certificate for u801e is enduring proof you're u801e and signatures the client cert makes during login will be durable proof that u801e logged in. PornHub can show Facebook and GitHub that the same user is using their site. So that's a privacy hole you can drive a truck through.

There are numerous practical problems with trying to leverage TLS client certificates for this work, but that's a big privacy problem.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#297
post #48

Earlier quoted context omitted.

Could you describe the types that are non-phishable?

WebAuthn (or its predecessor U2F but that's obsolete, so in green field deployments do WebAuthn) is the only practical non-phishable second factor for ordinary users on the web. You can do this two ways, one of which will make more sense for your web site: 1. PCs/ laptops/ etc. can use little USB hardware devices, from outfits like Yubico, the word to Google or type into your preferred hardware source is "FIDO" altho…

I can't make sense of your explanation.

In 1) I don't think my YubiKey knows anything about the sites I use it for? It just creates keys, so a phishing site could presumably still steal the key created by YubiKey and pass it on to the real site.

2) My fingerprints definitely don't know anything about web sites. So WebAuthn being unphishable has nothing to do with fingerprints. It is only incidental that some devices decide to unlock the functionality with fingerprints.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#298

I had someone contact me on Facebook marketplace, we agreed upon a time/price and then they asked for my phone number (which I sadly gave them). Then they said "I'm going to text you a code, so I can verify you are legit". The text I got was from Google Voice's 2FA.....

I get these texts periodically. I feed them fake codes and waste as much of their time as possible.

When they figure it out, I receive threats ranging from reporting me to the authorities all the way up to killing me and raping my family.

I then point out exactly how their scam works, and that they are either criminals directly or working for them as patsies. At this point, they usually stop responding.

If they don’t, then I take the chance to vent some of my own vitriol at them. It’s usually therapeutic, but it’s always fun.

I have accumulated a lot of hobbies over the years, and I count this among them.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#299
I honestly have never seen my login to Facebook expire. Even without enabling the remember me checkbox after logging in on iOS safari the login is valid forever unless I clear the cookies. I have never seen that level of brazen disregard for security with any other modern site.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#300

Earlier quoted context omitted.

WebAuthn (or its predecessor U2F but that's obsolete, so in green field deployments do WebAuthn) is the only practical non-phishable second factor for ordinary users on the web. You can do this two ways, one of which will make more sense for your web site: 1. PCs/ laptops/ etc. can use little USB hardware devices, from outfits like Yubico, the word to Google or type into your preferred hardware source is "FIDO" altho…

I can't make sense of your explanation. In 1) I don't think my YubiKey knows anything about the sites I use it for? It just creates keys, so a phishing site could presumably still steal the key created by YubiKey and pass it on to the real site. 2) My fingerprints definitely don't know anything about web sites. So WebAuthn being unphishable has nothing to do with fingerprints. It is only incidental that some devices…

1) The browser tells the Yubikey: "sign this: 'logging in to site.com at 12:34PM'". The yubikey signs it and gives the signature to the browser. The browser gets the signature and passes it on to the site. attacker.com will get a signature over 'logging in to attacker.com at 12:34PM'. That signature will not allow the attacker to log in to facebook.com .

2) Correct. In fact you don't even need a hardware token. You can do the whole thing in software. It could even theoretically be built right into your browser (but you would have the problem of logging in to the account on a different device or different browser). The fingerprint protects against physically stolen devices, and slightly against malware on your computer.

Post reply on HN