Live data from Hacker News

Facebook spamming users via their 2FA phone numbers

mashable.com

171–180 of 380 posts

Re: Facebook spamming users via their 2FA phone numbers

#171
post #157

Finally, somewhere I can appropriately vent about this. About TWO years ago I was constantly annoyed by the 'secure your account: add your phone number here' banner frequently displayed at the top of the page upon loading FB, so I input my number to make it disappear for good. (Also, they kept hiding the 'x' (close) icon in different spots, making the banner difficult to dismiss.) A few days later I got a text messag…

That thing facebook does with demanding your phone number, that's my favorite dark pattern. Apple does the same thing with iOS upgrades. First you pose a seemingly innocent question, like 'would you like to give us your phone number so we can keep your account secure?' or 'would you like to upgrade to new iOS?'. Then you take away the NO option. You replace it with 'i'll decide later'. And by doing so, you make it no…

See also: https://darkpatterns.org/types-of-dark-pattern

Re: Facebook spamming users via their 2FA phone numbers

#172
Tangentially related, make sure to remove any phone numbers you no longer use. I started receiving sms FB notifications for another person's account (I'm guessing they switched numbers). The link in the message logged me directly into their account. I reported it, but they said this was expected behavior.

Re: Facebook spamming users via their 2FA phone numbers

#174
post #15

It's pretty clear from some simple googling that he ended up somehow activating a feature called "Facebook Texts" (the key giveaway -- that replying to the texts posted to his wall): https://www.facebook.com/help/130694300342171?helpref=faq_co... I believe that he didn't set this up intentionally and it may very well be a bug that caused him to be signed up, but as bad as Facebook is I'll eat my shoe if they signed u…

[deleted]

Re: Facebook spamming users via their 2FA phone numbers

#175
post #15

It's pretty clear from some simple googling that he ended up somehow activating a feature called "Facebook Texts" (the key giveaway -- that replying to the texts posted to his wall): https://www.facebook.com/help/130694300342171?helpref=faq_co... I believe that he didn't set this up intentionally and it may very well be a bug that caused him to be signed up, but as bad as Facebook is I'll eat my shoe if they signed u…

No. Look at the following tweet. He explicitly says that he hasn’t enabled this and posted a screenshot of his settings:

https://mobile.twitter.com/Gabriel__Lewis/status/96312181416...

Update: Matthew Green just experienced the same thing, in the midst of tweeting about the security implications of abusing 2FA phone numbers this way:

https://mobile.twitter.com/matthew_d_green/status/9637666614...

Re: Facebook spamming users via their 2FA phone numbers

#176

Just get multiple phone numbers. It's easy these days and totally worth it. They're only $1 / month and being able to keep your real number separate from all these BS sites is great. Plus, for 2FA social engineers aren't going to get you just by working your network.

Google voice is a free phone number ;) I have a couple for 2fa if i ever truly want it. The danger of 2FA is that you are trusting your phone service provider. A semi-common hack is to socially engineer a phone provider into transferring the target's phone number from their service to your service provider under a false or stolen identity. Now you can control the phone number, tie it to your own device, and recieve the 2fa sms at your own device.

Re: Facebook spamming users via their 2FA phone numbers

#177
post #15

It's pretty clear from some simple googling that he ended up somehow activating a feature called "Facebook Texts" (the key giveaway -- that replying to the texts posted to his wall): https://www.facebook.com/help/130694300342171?helpref=faq_co... I believe that he didn't set this up intentionally and it may very well be a bug that caused him to be signed up, but as bad as Facebook is I'll eat my shoe if they signed u…

It's a default that's checked when you add your phone number.

I'm not happy that it's a default, but when I added my phone number I had no trouble noticing it and disabling it.

Re: Facebook spamming users via their 2FA phone numbers

#178
post #31

Earlier quoted context omitted.

That's not true, you have the ability in settings to see all old sessions and revoke device approvals. It's pretty easy to clear out your old machines.

If you remember and know where to look. Google eventually asked if I wanted to remove a phone I'd stopped using 2 years ago the other day.

Google's is pretty easy:

https://myaccount.google.com/

Under Device activity

Re: Facebook spamming users via their 2FA phone numbers

#179

Earlier quoted context omitted.

> I'll eat my shoe if they signed up every single person who gave a 2FA phone number to this service. Facebook doesn't have to sign up every 2FA person. It can pick a few hundred or thousand and see what happens. If engagement increases, then more 2FA people are brought on board. If this isn't widespread, it may not be the user's fault. It may just be the camel's nose under the tent.

The evil of unrestrained A/B testing.

I've heard engagement increases if you give the impression a family member is going through a personal crisis, perhaps facebook ought to look into the technique, seems excellent for the metrics.

Re: Facebook spamming users via their 2FA phone numbers

#180

I experienced this a few months ago and it was the last straw for me - it really feels like they're willing to do anything to drive engagement and ramp up addiction. This was after I'd removed messenger and facebook from my phone (having them really push hard for me to use messenger creeped me out; it's obviously in order for them to track my location). I've crippled facebook via chrome extensions to the point that i…

Consider trying https://mbasic.facebook.com/

It's a JavaScript-free version :)

Also works with the Tor hidden service https://mbasic.facebookcorewwwi.onion/

Post reply on HN