Live data from Hacker News

Someone keeps trying to reset my Facebook password

reddit.com

151–160 of 246 posts

Re: Someone keeps trying to reset my Facebook password

#151

Earlier quoted context omitted.

I'm a little confused. Does the code get generated on any attempt to log in, or only those that have the password and MFA is activated? Or when someone attempts password recovery? Because I'm a bit concerned if Microsoft passwords are leaking.

When attempting to login to your Microsoft account, instead of typing your password you can do an optional "one time password" generation thing from Microsoft. So instead of typing your password +2FA - they email you a 6 digit "one time password" that you can use instead. You cant disable this. So all Microsoft accounts could have a daily 1 in 1 million chance of been overtaken. Odds are low - but if you then spam th…

That makes much more sense, thanks. I'm guilty of using this from time to time as well.

Re: Someone keeps trying to reset my Facebook password

#152

I used to use an e-mail address a terrific domain name that I own. Without publicly disclosing specifics, it was like this: @ .com Thousands of people with this name, who didn't want to give out their real e-mail address, used this e-mail address when signing up for things online. They probably never thought it would be someone's actual address. I finally had to quit using it because of the tremendous amount of e-mai…

Mine is temporal at gmail. "Temporal" was my teenage gamer tag which I mostly stopped using decades ago, but it's been my gmail address for almost 20 years and changing it is not easy. The problem is, "temporal" happens to mean "temporary" in Spanish. As soon as Gmail became popular in the Spanish-speaking world, people started using it as a placeholder address. * Lots of people use it when creating throw-away accoun…

I'm sure having it spelled out verbatim in an article online helped cut the emails per second down ;)

Re: Someone keeps trying to reset my Facebook password

#153

I was a PM at instagram in 2016 when we got a lot of these complaints from celebrities and short usernames. Some users were getting hundreds of reset emails/day triggered by random people in the world trying to reset their password. It's a really hard problem to solve because if these users actually forgot their password someday, they would really want those emails. We ended up creating a snooze for 30 days button at…

If websites made a concerted effort to train their users to not "remember passwords", this could eventually be solved.

Human brains are not designed to remember:

* Passwords that aren't reused across the many dozens/hundreds of logins a person typically has * Passwords that aren't easily guessed phrases including substrings of personal information (birthdays, children's names, etc) * Long and strongly random

Yet good passwords need to be all of those. Christ, if websites just included a little "have you considered using a password manager?" link on the registration page. Tragedy of the commons I guess... everyone wants other companies to do the hard work of convincing a few percent per year to use them. We'll still be dicking around with this bullshit 30 years from now though.

The problem is easy. The work of implementing it is difficult and slow. Let someone else do it.

Re: Someone keeps trying to reset my Facebook password

#154

I was a PM at instagram in 2016 when we got a lot of these complaints from celebrities and short usernames. Some users were getting hundreds of reset emails/day triggered by random people in the world trying to reset their password. It's a really hard problem to solve because if these users actually forgot their password someday, they would really want those emails. We ended up creating a snooze for 30 days button at…

If websites made a concerted effort to train their users to not "remember passwords", this could eventually be solved. Human brains are not designed to remember: * Passwords that aren't reused across the many dozens/hundreds of logins a person typically has * Passwords that aren't easily guessed phrases including substrings of personal information (birthdays, children's names, etc) * Long and strongly random Yet good…

I personally feel password managers are convenience that bundles separate risks into a single point of failure.

Re: Someone keeps trying to reset my Facebook password

#155
post #123

Our company owns a one letter domain (e.g. "x.tld"), that follows a quite common sequence. A few months ago we've enabled receiving e-mails for all local parts on that domain. We've received hundreds of notification mails, newsletter subscriptions, alerts (from internal systems disclosing details about infrastructure of giant corporations), etc. It was quite fun, but became annoying quickly. We've then reduced recept…

> We've then reduced reception to the common hostmaster@, ... mailboxes Just FYI: For a more-or-less authoritative list of what aliases you ought to consider having, see RFC 2142: https://www.rfc-editor.org/rfc/rfc2142 >

That's exactly the one we picked. I've even commented it in our Sieve script. Funnily enough some spammers have picked up on this and send their spam even to those mailboxes.

Re: Someone keeps trying to reset my Facebook password

#156
post #154

Earlier quoted context omitted.

If websites made a concerted effort to train their users to not "remember passwords", this could eventually be solved. Human brains are not designed to remember: * Passwords that aren't reused across the many dozens/hundreds of logins a person typically has * Passwords that aren't easily guessed phrases including substrings of personal information (birthdays, children's names, etc) * Long and strongly random Yet good…

I personally feel password managers are convenience that bundles separate risks into a single point of failure.

I also feel like this about them, but I don't really have much knowledge on the subject. Do you have any experience or references that this might be the case?

Re: Someone keeps trying to reset my Facebook password

#157

I own the domain of my last name. Several family members use (firstname@lastname.com). I once went to get a new phone at Best Buy, and the employee needed my email address. I gave it to here (firstname@lastname.com) and she insisted that it was NOT my email address. She insisted that it MUST end in @gmail.com or @yahoo.com, something like that. We frequently sign up for stuff online, and when we enter our email addre…

I have the same, firstname@lastname.com/uk/.co.uk/etc; my family name alone is an absolute pain in the arse for most British English speakers to spell when given it verbally; to make matters worse, when I give people my email, over the phone for example, I get the combination of "what's it @?" and then when they finally get there, that my last name is after the @, another 5 minutes to get them to spell it correctly;…

> her maiden name was so sophisticated and easy

You could have solved the problem at the root by taking her name

Re: Someone keeps trying to reset my Facebook password

#158

I was a PM at instagram in 2016 when we got a lot of these complaints from celebrities and short usernames. Some users were getting hundreds of reset emails/day triggered by random people in the world trying to reset their password. It's a really hard problem to solve because if these users actually forgot their password someday, they would really want those emails. We ended up creating a snooze for 30 days button at…

If websites made a concerted effort to train their users to not "remember passwords", this could eventually be solved. Human brains are not designed to remember: * Passwords that aren't reused across the many dozens/hundreds of logins a person typically has * Passwords that aren't easily guessed phrases including substrings of personal information (birthdays, children's names, etc) * Long and strongly random Yet good…

The concept of requiring a special string to gain access to an account is massively dated, whether that string is something a human has memorised or random output from a password manager. Either the database of special strings lives in your brain, a notebook, a bit of paper, or encrypted on disk somewhere, but it's still a database of special strings.

Public key crypto never took off for account management and neither did Persona, but the current iteration with passkeys/Webauthn should hopefully be a fresh step in the right direction there.

Re: Someone keeps trying to reset my Facebook password

#159

I used to use an e-mail address a terrific domain name that I own. Without publicly disclosing specifics, it was like this: @ .com Thousands of people with this name, who didn't want to give out their real e-mail address, used this e-mail address when signing up for things online. They probably never thought it would be someone's actual address. I finally had to quit using it because of the tremendous amount of e-mai…

Lol I always use cat@cat.com, so to whomever owns that: you're welcome.

Re: Someone keeps trying to reset my Facebook password

#160

Earlier quoted context omitted.

Mine is temporal at gmail. "Temporal" was my teenage gamer tag which I mostly stopped using decades ago, but it's been my gmail address for almost 20 years and changing it is not easy. The problem is, "temporal" happens to mean "temporary" in Spanish. As soon as Gmail became popular in the Spanish-speaking world, people started using it as a placeholder address. * Lots of people use it when creating throw-away accoun…

I'm sure having it spelled out verbatim in an article online helped cut the emails per second down ;)

Nah, I don't think saying my address publicly has any effect. AFAICT none of the problem comes from people who are actually aware that the address has an owner.
Post reply on HN