Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

311–320 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#311

This is what I'm worried about, to be honest. Not necessarily getting hacked but just getting flagged, banned and burned with no recourse. This is why I commented on an article here some weeks ago that if they ever offered any paid user experience they'd be in trouble because they'd actually have to help their users with their issues. These tech companies should offer actual support the moment you spend money with th…

I guess this is the model when the user is the product and not the customer. Flipping this, if this were a paying advertiser (customer) that got locked out, there probably is a valid path to contact someone. Looks like it is time to remove all my Single Sign On from Google, Facebook, GitHub etc. And have individual user/pass for all of them. I have the same fear as you and way more so after reading this article, just…

GitHub seems competent and not that banhammery. I wonder if you get better account recovery support there, especially as a paying customer?

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#312
post #310

Earlier quoted context omitted.

Big caveat being you can no longer use the account to develop things with the Google API or use some third party clients (e.g. rclone).

Which Google API do you mean? I use advanced protection and have developed various things with various Google APIs, I just use a service account with minimal privileges for each thing I'm developing, which is probably best practice anyway. Not sure about rclone but probably it would work fine with a service account too?

It blocks any unverified OAuth app, including the ones you create yourself.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#313

Earlier quoted context omitted.

>cookie theft I think that's quite likely. I have a (somewhat throwaway) FB account, not much of a profile and mainly used for a local cause. Co-admining a page I'd clicked on a clickbaity headline posted to the page and several days later my account was disabled. The account recovery process was completely broken/circular but somehow the account revived itself after a week. The fact that my 'friend suggestions' were…

There's no way clicking on a headline would lead to your account being hijacked... Unless there's a browser 0-day which are extremely valuable and no one would waste that on your FB account. Or if clicking the link downloaded malware and you ran the malware. Did you ever use the password of the FB account anywhere else? You getting phished is also much more likely than a browser 0-day. Did you have a security key on…

It was a secure account as far as the password goes, no 2FA. Like I said it was a bit of a throwaway account. Password 15 chars long, random chars.

No phishing.

I concluded that there's perhaps a cross-origin issue on Facebook's side that allowed cookie hijacking. The clickbaity link was almost tailor made for our group "[something ominous happened] in [your part of town]". Looks like it was auto-shared by someone whose account had been compromised as they were local. Reasonably confident it was a session hijack, my password remained the same while account locked.

The only other plausible thing wrt my account's case was that it was almost empty (i.e. no photo, no friends, not much to go by) and was somehow flagged but was given a misleading reason why it was.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#314

Earlier quoted context omitted.

I can't make sense of your explanation. In 1) I don't think my YubiKey knows anything about the sites I use it for? It just creates keys, so a phishing site could presumably still steal the key created by YubiKey and pass it on to the real site. 2) My fingerprints definitely don't know anything about web sites. So WebAuthn being unphishable has nothing to do with fingerprints. It is only incidental that some devices…

1) The browser tells the Yubikey: "sign this: 'logging in to site.com at 12:34PM'". The yubikey signs it and gives the signature to the browser. The browser gets the signature and passes it on to the site. attacker.com will get a signature over 'logging in to attacker.com at 12:34PM'. That signature will not allow the attacker to log in to facebook.com . 2) Correct. In fact you don't even need a hardware token. You c…

I'm still waiting for password managers to add soft-WebAuthn support, so I can log in using my password manager (and no physical keys or passwords). That would make password managers ten times better.

Then again, it doesn't have to be the password manager that does this, but it'd be nice if it were integrated.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#315

Earlier quoted context omitted.

WebAuthn (or its predecessor U2F but that's obsolete, so in green field deployments do WebAuthn) is the only practical non-phishable second factor for ordinary users on the web. You can do this two ways, one of which will make more sense for your web site: 1. PCs/ laptops/ etc. can use little USB hardware devices, from outfits like Yubico, the word to Google or type into your preferred hardware source is "FIDO" altho…

> if you have spare cash and like cool toys FIDO2 is a more capable second generation of the technology. Why would you want passwordless authentication? Isn't the whole point of 2FA that you have to have something and you have to know something?

The FIDO2 key is usually protected by a PIN that wipes the key after a few wrong attempts, so it combines the two itself.

Besides, there's nothing that dictates how secure the key should be. You could use your hardware cryptocurrency wallet for this, which is probably much more secure and convenient than the average Yubikey (you can duplicate it with the seed phrase).

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#316

Earlier quoted context omitted.

>cookie theft I think that's quite likely. I have a (somewhat throwaway) FB account, not much of a profile and mainly used for a local cause. Co-admining a page I'd clicked on a clickbaity headline posted to the page and several days later my account was disabled. The account recovery process was completely broken/circular but somehow the account revived itself after a week. The fact that my 'friend suggestions' were…

There's no way clicking on a headline would lead to your account being hijacked... Unless there's a browser 0-day which are extremely valuable and no one would waste that on your FB account. Or if clicking the link downloaded malware and you ran the malware. Did you ever use the password of the FB account anywhere else? You getting phished is also much more likely than a browser 0-day. Did you have a security key on…

This isn't correct, it's not the only way. A Facebook vulnerability is less valuable than a browser 0-day and could similarly leak credentials.

In fact, Facebook has had numerous authentication blunders in the past. [1] One of them was a zero-click mechanism very recently. [2]

Facebook's security team is a joke, or worse -- they're muzzled by product teams and forced to do their bidding. [3]

[1] https://threatpost.com/facebook-patches-oauth-authentication...

[2] https://about.fb.com/news/2018/09/security-update/

[3] https://appleinsider.com/articles/21/04/22/facebook-dangerou...

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#317
post #251

Earlier quoted context omitted.

10 billions profit a year, seems like enough money for user support

Short answer: they lose less money from people getting frustrated than the massive cost of real support

Maybe they would have more users with real support.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#318

Earlier quoted context omitted.

Advanced Protection does have the account recovery. https://landing.google.com/advancedprotection/faq/ It is just very slow as it's a human process. There's very little reason you shouldn't use Advanced Protection, if your account is important enough.

Big caveat being you can no longer use the account to develop things with the Google API or use some third party clients (e.g. rclone).

I'd just use a dummy account for developing.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#319
post #226

Earlier quoted context omitted.

If you would like to take advantage of such an option, you are also opting in to taking on an operational burden. That burden is exactly maintaining a set of backup keys and testing them on a regular basis.

And that's why "everyone should just use yubikeys" is never going to happen.

Everyone already pays the same operational burden with their house keys, which are far more difficult to manage for the average person (as they leave the house constantly). It's worked fine for hundreds of years.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#320
post #94

Earlier quoted context omitted.

Old school phishing is the most common MFA bypass. Here is a description how it works: https://github.com/wunderwuzzi23/KoiPhish Unless you use Yubikeys (webauthn) etc these phishing attacks just continue to work. I do consultancy in this space at times and about 95+% of folks who enter their password will also enter their MFA token.

I might be tempted to enter the TOTP, but my browser is unlikely to enter the password, and I definitely won't.

I think the fact that password managers can spot incorrect urls better than users is useful. However I've become numbed to this warning flag by those services that seem to have endless different urls that are all legitimate. (Microsoft being a particular offender here).

I can imaging some variant of outlook.microsoft.developer.really.yes.com catching me unawares one day.

Post reply on HN