Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

361–370 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#361

Earlier quoted context omitted.

My smartphone cannot be remotely turned into an overpriced wheel chock by someone in a call center.

Apple at least can absolutely do this, that's what the purpose of reporting a device stolen is.

OK but that's a very different story, one is stolen and at the request of the owner, the other is for some ethereal vague hard to pin down rule that was broken with no way to resolve it. My use of my property that I own should not be contingent on some behavioral rule on some website that could change at any time. Don't give money to companies that can remotely brick your property without your explicit request.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#362

This is what I'm worried about, to be honest. Not necessarily getting hacked but just getting flagged, banned and burned with no recourse. This is why I commented on an article here some weeks ago that if they ever offered any paid user experience they'd be in trouble because they'd actually have to help their users with their issues. These tech companies should offer actual support the moment you spend money with th…

>This is why I commented on an article here some weeks ago that if they ever offered any paid user experience they'd be in trouble because they'd actually have to help their users with their issues.

Facebook has offered a paid user experience to Oculus users for several years now, and so far no one has forced them to actually help users with these issues. Not the market, not regulators, and certainly not users. They will keep getting away with it simply because they can. What are you going to do about it?

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#363
post #101

Earlier quoted context omitted.

So the email address is not 2FA secured?

It's my own mail server. I just tail the mail spool ...

Is your account with the DNS registrar who controls your MX record 2FA-secured?

>[...] via encrypted SMTP

In addition to establishing a secure socket, does the mule validate the mail server's TLS certificate name?

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#364

I don’t understand how the hacker bypassed 2FA? Did OP accidentally entered his keys somewhere? Or did the hacker convince FB support to disable 2FA? How can we all avoid OP’s fate. Lot of comments go in-depth on yubi keys and whatnot. But if FB support disabled 2FA what good is a U2F, fido2 and whatnot?

If it's malware that steals cookies, no 2fa is necessary, just set up your cookies and log in like it's a live session

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#365

Earlier quoted context omitted.

There's no way clicking on a headline would lead to your account being hijacked... Unless there's a browser 0-day which are extremely valuable and no one would waste that on your FB account. Or if clicking the link downloaded malware and you ran the malware. Did you ever use the password of the FB account anywhere else? You getting phished is also much more likely than a browser 0-day. Did you have a security key on…

It was a secure account as far as the password goes, no 2FA. Like I said it was a bit of a throwaway account. Password 15 chars long, random chars. No phishing. I concluded that there's perhaps a cross-origin issue on Facebook's side that allowed cookie hijacking. The clickbaity link was almost tailor made for our group "[something ominous happened] in [your part of town]". Looks like it was auto-shared by someone wh…

>The only other plausible thing wrt my account's case was that it was almost empty (i.e. no photo, no friends, not much to go by) and was somehow flagged but was given a misleading reason why it was.

That sounds much more likely to me.

When facebook has a website vulnerability that is exploited, they log everyone out, post a blog post, and makes big news:

https://www.wired.co.uk/article/facebook-hack-beach-single-s...

https://krebsonsecurity.com/2018/09/facebook-security-bug-af...

https://about.fb.com/news/2018/09/security-update/

>"[something ominous happened] in [your part of town]"

Those ads are all over. They determine [your part of town] through geoip or FB tells the advertiser your city. It's like the "singles in [your city]" ads.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#366
post #316

Earlier quoted context omitted.

There's no way clicking on a headline would lead to your account being hijacked... Unless there's a browser 0-day which are extremely valuable and no one would waste that on your FB account. Or if clicking the link downloaded malware and you ran the malware. Did you ever use the password of the FB account anywhere else? You getting phished is also much more likely than a browser 0-day. Did you have a security key on…

This isn't correct, it's not the only way. A Facebook vulnerability is less valuable than a browser 0-day and could similarly leak credentials. In fact, Facebook has had numerous authentication blunders in the past. [1] One of them was a zero-click mechanism very recently. [2] Facebook's security team is a joke, or worse -- they're muzzled by product teams and forced to do their bidding. [3] [1] https://threatpost.co…

You're right. But when there's an exploited vulnerability Facebook logs everyone out and then posts a blog post about it, as show by the 2018 hack you linked to.

That hasn't happened here.

I don't really consider 3 years ago to be very recent.

I think that 3rd link is arguably not a vulnerability. If you intentionally want people to be able to look up future friends by email address, then that's basically the desired behavior. Now arguably allowing people to look up future friends by email is a privacy problem. Some users probably want that feature though. Yes a lack of rate limiting is a problem, but rate limiting won't stop attackers from doing it, it just slows them down.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#367

Earlier quoted context omitted.

> if you have spare cash and like cool toys FIDO2 is a more capable second generation of the technology. Why would you want passwordless authentication? Isn't the whole point of 2FA that you have to have something and you have to know something?

The FIDO2 key is usually protected by a PIN that wipes the key after a few wrong attempts, so it combines the two itself. Besides, there's nothing that dictates how secure the key should be. You could use your hardware cryptocurrency wallet for this, which is probably much more secure and convenient than the average Yubikey (you can duplicate it with the seed phrase).

You can duplicate the Yubikey or the hardware cryptocurrency wallet?

Wouldn't the ability to duplicate it make it weaker?

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#368

Earlier quoted context omitted.

The FIDO2 key is usually protected by a PIN that wipes the key after a few wrong attempts, so it combines the two itself. Besides, there's nothing that dictates how secure the key should be. You could use your hardware cryptocurrency wallet for this, which is probably much more secure and convenient than the average Yubikey (you can duplicate it with the seed phrase).

You can duplicate the Yubikey or the hardware cryptocurrency wallet? Wouldn't the ability to duplicate it make it weaker?

You can duplicate the wallet. It would make it weaker, but it's more secure in that they usually have hardware keypads for you to enter your PIN on.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#369

Earlier quoted context omitted.

Just think of it as like paying to see a movie. I bought a $10 app once, used it for what it was for, and now several phones later, I don't know or care what's happened to it. I got my value out of it and don't need to hoard every possession I "buy". Remember people who used to have a huge collection of video tapes or CDs? They hardly used them for anything except decoration of their living room. Hoarding old crap th…

> The world's richest man had half his wealth taken like that. If you're talking about Bezos, all of their wealth was made after they got married. The news can say it's "his wealth" but it always belonged to both of them. It's not "taking half his wealth," it's splitting their co-owned assets.

Well, yes, exactly. It's legal. An online service denying access to a movie you bought is just them acting on their right to do so because you never had a non-revocable license to use it. It was always their property. In both cases, people don't appreciate that what they feel is theirs isn't really theirs until it gets taken away. That's the whole problem.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#370
post #341

Earlier quoted context omitted.

Just think of it as like paying to see a movie. I bought a $10 app once, used it for what it was for, and now several phones later, I don't know or care what's happened to it. I got my value out of it and don't need to hoard every possession I "buy". Remember people who used to have a huge collection of video tapes or CDs? They hardly used them for anything except decoration of their living room. Hoarding old crap th…

So much wrong here lets start with this >The world's richest man had half his wealth taken like that I assume you are talking Bezo's divorce, you might want to actually look into that if you believe that. he did not have half his wealth taken, far far far from it. >Physical things can readily be taken away in divorces and debt recovery That is not being "taken away" in the sense you are talking about in context, for…

> Sad you just used them for decoration.

Who?

Post reply on HN