Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

371–380 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#371
post #316

Earlier quoted context omitted.

This isn't correct, it's not the only way. A Facebook vulnerability is less valuable than a browser 0-day and could similarly leak credentials. In fact, Facebook has had numerous authentication blunders in the past. [1] One of them was a zero-click mechanism very recently. [2] Facebook's security team is a joke, or worse -- they're muzzled by product teams and forced to do their bidding. [3] [1] https://threatpost.co…

You're right. But when there's an exploited vulnerability Facebook logs everyone out and then posts a blog post about it, as show by the 2018 hack you linked to. That hasn't happened here. I don't really consider 3 years ago to be very recent. I think that 3rd link is arguably not a vulnerability. If you intentionally want people to be able to look up future friends by email address, then that's basically the desired…

Leaking PII in the name of "features" is a security disaster.

Ask yourself why Facebook doesn't just make available a spreadsheet of all names associated with which emails on the platform. It's because it's private information.

Why doesn't Facebook's security team do anything? Either they're incompetent, or they're being muzzled by product.

Additionally, Facebook's privacy policy explicitly says that they don't share your private information that you have chosen to set private. That's an egregious lie.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#372

Earlier quoted context omitted.

It was a secure account as far as the password goes, no 2FA. Like I said it was a bit of a throwaway account. Password 15 chars long, random chars. No phishing. I concluded that there's perhaps a cross-origin issue on Facebook's side that allowed cookie hijacking. The clickbaity link was almost tailor made for our group "[something ominous happened] in [your part of town]". Looks like it was auto-shared by someone wh…

>The only other plausible thing wrt my account's case was that it was almost empty (i.e. no photo, no friends, not much to go by) and was somehow flagged but was given a misleading reason why it was. That sounds much more likely to me. When facebook has a website vulnerability that is exploited, they log everyone out, post a blog post, and makes big news: https://www.wired.co.uk/article/facebook-hack-beach-single-s..…

The thing is it wasn't an ad, it was a post a regular user posted into a group.

And that being the plausible answer doens't explain why me as a Northern European post-ban-resurrection ended up getting all my friends suggestions from Africans. It was never the case before that and all my activity simply involved campaigning against losing a local park and looking at local news.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#373

Earlier quoted context omitted.

This is another good part of steam - even if your account is banned from the entire community for site-wide spam, you don’t lose access to your game library.

Edit: looks like, of course, they can ban you and lose access to your games, however it requires threatening legal action against Valve. https://www.oneangrygamer.net/2020/06/steam-user-loses-game-... Looks like this user received this message[0] after being banned from the community and only because he mentioned russian law did Steam suspend his account. > Going to support and blalblab again my rights and the russia…

Generally speaking, you don't lose access to your Steam library unless you defraud them, e.g. by charging back purchases. I don't buy that the Russian guy got banned for spamming. The only evidence that that was the ban reason is his own words. Considering that this story seems to have only been picked up by sites like "oneangrygamer", "riseupgamer", and the Daily Stormer, I'd lay money he's not being honest.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#374
post #287

Earlier quoted context omitted.

Most games I’ve played on my Oculus have been paid, the same as Stream.

i belive (s)he’s talking about facebook, who’s system has been built for its free users. oculus is just something that they have added later on, without taking time and money to adapt it for the (small number of) paying users.

yup

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#375
post #354

Earlier quoted context omitted.

I can't make sense of your explanation. In 1) I don't think my YubiKey knows anything about the sites I use it for? It just creates keys, so a phishing site could presumably still steal the key created by YubiKey and pass it on to the real site. 2) My fingerprints definitely don't know anything about web sites. So WebAuthn being unphishable has nothing to do with fingerprints. It is only incidental that some devices…

At high level imagine it like this: The browser will only give access to the Yubikey token for a specific domain name - so if the attacker phishes for examle.org, rather then example.org, then there is just no tokens (signing keys) available the Yubikey could use and give to the browser. In the early days WebUSB in Chrome had bugs that allowed to bypass that same origin check but that has been fixed 3 years ago.

I've been using the browser's password manager as protection against phishing, as the password manager won't fill in passwords on the wrong site. So I guess it works in a similar way with the Yubikey? OK.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#376
post #354

Earlier quoted context omitted.

At high level imagine it like this: The browser will only give access to the Yubikey token for a specific domain name - so if the attacker phishes for examle.org, rather then example.org, then there is just no tokens (signing keys) available the Yubikey could use and give to the browser. In the early days WebUSB in Chrome had bugs that allowed to bypass that same origin check but that has been fixed 3 years ago.

I've been using the browser's password manager as protection against phishing, as the password manager won't fill in passwords on the wrong site. So I guess it works in a similar way with the Yubikey? OK.

At a very very high level yes - but the reason you want to use tokens is that you get a second factor and you have better entropy and created tokens are time based (password is valid forever).

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#377
post #371

Earlier quoted context omitted.

You're right. But when there's an exploited vulnerability Facebook logs everyone out and then posts a blog post about it, as show by the 2018 hack you linked to. That hasn't happened here. I don't really consider 3 years ago to be very recent. I think that 3rd link is arguably not a vulnerability. If you intentionally want people to be able to look up future friends by email address, then that's basically the desired…

Leaking PII in the name of "features" is a security disaster. Ask yourself why Facebook doesn't just make available a spreadsheet of all names associated with which emails on the platform. It's because it's private information. Why doesn't Facebook's security team do anything? Either they're incompetent, or they're being muzzled by product. Additionally, Facebook's privacy policy explicitly says that they don't share…

There's been a bit of miscommunication here, and I think it's partially my fault. It looks like there was a vulnerability in the rate limiter, and Facebook has admitted that and says they're trying to fix it (I don't know whether they have fixed it):

>In a statement, Facebook said: "It appears that we erroneously closed out this bug bounty report before routing to the appropriate team. We appreciate the researcher sharing the information and are taking initial actions to mitigate this issue while we follow up to better understand their findings."

https://arstechnica.com/gadgets/2021/04/tool-links-email-add...

I'm not sure whether you're just concerned with this apparent rate limit bypass vuln or with the entire concept of lookup by email.

>Ask yourself why Facebook doesn't just make available a spreadsheet of all names associated with which emails on the platform. It's because it's private information.

That would be Facebook telling you the email of every account. The behavior we're discussing is not doing that. Facebook allows you to find a person's profile given a person's email (assuming the person didn't disable that lookup it in privacy settings, and also considering rate limits which might be bypassable by a vulnerability). Facebook doesn't allow you do to the reverse unless the person sets email visibility to public.

>Why doesn't Facebook's security team do anything? Either they're incompetent, or they're being muzzled by product.

What do you think they should do?

Just because someone disagrees with you doesn't make them incompetent.

>Additionally, Facebook's privacy policy explicitly says that they don't share your private information that you have chosen to set private. That's an egregious lie.

What private information is being shared? Your profile URL? Your first and last name?

Facebook has an option to disable this lookup. Are you saying people are disabling the lookup and Facebook is disobeying that?

>Who can look you up using the email address you provided?

https://i.imgur.com/D8qQjq0.png

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#378

Earlier quoted context omitted.

>The only other plausible thing wrt my account's case was that it was almost empty (i.e. no photo, no friends, not much to go by) and was somehow flagged but was given a misleading reason why it was. That sounds much more likely to me. When facebook has a website vulnerability that is exploited, they log everyone out, post a blog post, and makes big news: https://www.wired.co.uk/article/facebook-hack-beach-single-s..…

The thing is it wasn't an ad, it was a post a regular user posted into a group. And that being the plausible answer doens't explain why me as a Northern European post-ban-resurrection ended up getting all my friends suggestions from Africans. It was never the case before that and all my activity simply involved campaigning against losing a local park and looking at local news.

Was the user a spam bot? Maybe the bot saw a city mentioned in the group and generated a spam comment using that city.

It's possible some people (or bots) from Africa viewed your page and no one else did in the recent past, and thus Facebook thought there was some connection between you and Africa.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#379

Earlier quoted context omitted.

> And Facebook refuses so much as to pick up the phone to discuss it. It's part of the business model - each FB user generates so little revenue for the company that you can't afford to offer anything resembling "real" support channels. The company is massively profitable by sheer scale - by making a small amount of money per year off of a vast number of users. This applies to Google as well - or really any ad-based…

> One of many reasons I pay Google to host my email rather than use a free Gmail - when you are generating a non-negligible revenue stream suddenly companies' willingness to answer emails and pick up phones increases. If you think that does any difference, I hope you good luck. Google is unreachable for support, even if you are a paying user.

I don't think that's true - Google One (which I subscribe to basically just to have a support fallback) offers this: https://one.google.com/about/support?hl=en_GB

"Live chat, email or call us".

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#380

Earlier quoted context omitted.

I managed to get in touch with a Google engineer once for help with some Adwords API stuff (our company is a large adwords agency). ...They accidentally CC'd in a public mailing list into our discussion and leaked enough information that someone would be able to use the automated support system to change the company AdWords password. There was basically no way of contacting anyone further, the engineer couldn't conta…

I might as well been the engineer that reached out toward you. But in the end, I was let go as support is not earned any metric into performance.

I did run into that engineer in-person at a Google event and grabbed a coffee with them. I think they're still at Google. No hard feelings but yeah getting any real support at Google is impossible and obviously not prioritized by the organization.
Post reply on HN