Earlier quoted context omitted.
I'm a little confused. Does the code get generated on any attempt to log in, or only those that have the password and MFA is activated? Or when someone attempts password recovery? Because I'm a bit concerned if Microsoft passwords are leaking.
When attempting to login to your Microsoft account, instead of typing your password you can do an optional "one time password" generation thing from Microsoft. So instead of typing your password +2FA - they email you a 6 digit "one time password" that you can use instead. You cant disable this. So all Microsoft accounts could have a daily 1 in 1 million chance of been overtaken. Odds are low - but if you then spam th…
Someone keeps trying to reset my Facebook password
151–160 of 246 posts
Re: Someone keeps trying to reset my Facebook password
#152I used to use an e-mail address a terrific domain name that I own. Without publicly disclosing specifics, it was like this: @ .com Thousands of people with this name, who didn't want to give out their real e-mail address, used this e-mail address when signing up for things online. They probably never thought it would be someone's actual address. I finally had to quit using it because of the tremendous amount of e-mai…
Mine is temporal at gmail. "Temporal" was my teenage gamer tag which I mostly stopped using decades ago, but it's been my gmail address for almost 20 years and changing it is not easy. The problem is, "temporal" happens to mean "temporary" in Spanish. As soon as Gmail became popular in the Spanish-speaking world, people started using it as a placeholder address. * Lots of people use it when creating throw-away accoun…
Re: Someone keeps trying to reset my Facebook password
#153I was a PM at instagram in 2016 when we got a lot of these complaints from celebrities and short usernames. Some users were getting hundreds of reset emails/day triggered by random people in the world trying to reset their password. It's a really hard problem to solve because if these users actually forgot their password someday, they would really want those emails. We ended up creating a snooze for 30 days button at…
Human brains are not designed to remember:
* Passwords that aren't reused across the many dozens/hundreds of logins a person typically has * Passwords that aren't easily guessed phrases including substrings of personal information (birthdays, children's names, etc) * Long and strongly random
Yet good passwords need to be all of those. Christ, if websites just included a little "have you considered using a password manager?" link on the registration page. Tragedy of the commons I guess... everyone wants other companies to do the hard work of convincing a few percent per year to use them. We'll still be dicking around with this bullshit 30 years from now though.
The problem is easy. The work of implementing it is difficult and slow. Let someone else do it.
Re: Someone keeps trying to reset my Facebook password
#154I was a PM at instagram in 2016 when we got a lot of these complaints from celebrities and short usernames. Some users were getting hundreds of reset emails/day triggered by random people in the world trying to reset their password. It's a really hard problem to solve because if these users actually forgot their password someday, they would really want those emails. We ended up creating a snooze for 30 days button at…
If websites made a concerted effort to train their users to not "remember passwords", this could eventually be solved. Human brains are not designed to remember: * Passwords that aren't reused across the many dozens/hundreds of logins a person typically has * Passwords that aren't easily guessed phrases including substrings of personal information (birthdays, children's names, etc) * Long and strongly random Yet good…
Re: Someone keeps trying to reset my Facebook password
#155Our company owns a one letter domain (e.g. "x.tld"), that follows a quite common sequence. A few months ago we've enabled receiving e-mails for all local parts on that domain. We've received hundreds of notification mails, newsletter subscriptions, alerts (from internal systems disclosing details about infrastructure of giant corporations), etc. It was quite fun, but became annoying quickly. We've then reduced recept…
> We've then reduced reception to the common hostmaster@, ... mailboxes Just FYI: For a more-or-less authoritative list of what aliases you ought to consider having, see RFC 2142: https://www.rfc-editor.org/rfc/rfc2142 >
Re: Someone keeps trying to reset my Facebook password
#156Earlier quoted context omitted.
If websites made a concerted effort to train their users to not "remember passwords", this could eventually be solved. Human brains are not designed to remember: * Passwords that aren't reused across the many dozens/hundreds of logins a person typically has * Passwords that aren't easily guessed phrases including substrings of personal information (birthdays, children's names, etc) * Long and strongly random Yet good…
I personally feel password managers are convenience that bundles separate risks into a single point of failure.
Re: Someone keeps trying to reset my Facebook password
#157I own the domain of my last name. Several family members use (firstname@lastname.com). I once went to get a new phone at Best Buy, and the employee needed my email address. I gave it to here (firstname@lastname.com) and she insisted that it was NOT my email address. She insisted that it MUST end in @gmail.com or @yahoo.com, something like that. We frequently sign up for stuff online, and when we enter our email addre…
I have the same, firstname@lastname.com/uk/.co.uk/etc; my family name alone is an absolute pain in the arse for most British English speakers to spell when given it verbally; to make matters worse, when I give people my email, over the phone for example, I get the combination of "what's it @?" and then when they finally get there, that my last name is after the @, another 5 minutes to get them to spell it correctly;…
You could have solved the problem at the root by taking her name
Re: Someone keeps trying to reset my Facebook password
#158I was a PM at instagram in 2016 when we got a lot of these complaints from celebrities and short usernames. Some users were getting hundreds of reset emails/day triggered by random people in the world trying to reset their password. It's a really hard problem to solve because if these users actually forgot their password someday, they would really want those emails. We ended up creating a snooze for 30 days button at…
If websites made a concerted effort to train their users to not "remember passwords", this could eventually be solved. Human brains are not designed to remember: * Passwords that aren't reused across the many dozens/hundreds of logins a person typically has * Passwords that aren't easily guessed phrases including substrings of personal information (birthdays, children's names, etc) * Long and strongly random Yet good…
Public key crypto never took off for account management and neither did Persona, but the current iteration with passkeys/Webauthn should hopefully be a fresh step in the right direction there.
Re: Someone keeps trying to reset my Facebook password
#159I used to use an e-mail address a terrific domain name that I own. Without publicly disclosing specifics, it was like this: @ .com Thousands of people with this name, who didn't want to give out their real e-mail address, used this e-mail address when signing up for things online. They probably never thought it would be someone's actual address. I finally had to quit using it because of the tremendous amount of e-mai…
Re: Someone keeps trying to reset my Facebook password
#160Earlier quoted context omitted.
Mine is temporal at gmail. "Temporal" was my teenage gamer tag which I mostly stopped using decades ago, but it's been my gmail address for almost 20 years and changing it is not easy. The problem is, "temporal" happens to mean "temporary" in Spanish. As soon as Gmail became popular in the Spanish-speaking world, people started using it as a placeholder address. * Lots of people use it when creating throw-away accoun…
I'm sure having it spelled out verbatim in an article online helped cut the emails per second down ;)