Live data from Hacker News

Someone keeps trying to reset my Facebook password

reddit.com

201–210 of 246 posts

Re: Someone keeps trying to reset my Facebook password

#201

Earlier quoted context omitted.

> Set a limit, you get one password reset email per day/successful password reset. I routinely see password reset emails get caught by greylisting. Most are released by the 2nd email but sometimes it takes more.

Greylisting is really a rare configuration choice in modern times and has always been a "results may vary" sort of deal. Personally I wouldn't factor those users into my considerations.

I do password resets for clients fairly routinely. I run into greylisting behavior about 2 doz times a year. Often happens in spurts.

Just last week I ran into greylisting a bunch of times, while testing a new mail server against gmail accounts. Same thing two weeks prior for a diff server. This is with SPF, DKIM and DMARC setup. Corp and personal gmail accounts - no rhyme or reason to when it happens.

Re: Someone keeps trying to reset my Facebook password

#202
post #156
post #154

Earlier quoted context omitted.

I personally feel password managers are convenience that bundles separate risks into a single point of failure.

I also feel like this about them, but I don't really have much knowledge on the subject. Do you have any experience or references that this might be the case?

For passwords nothing personal, only the eggs 1 basket heuristic. But stories like this don't inspire my confidence: https://news.ycombinator.com/item?id=34516275

Re: Someone keeps trying to reset my Facebook password

#204
post #154

Earlier quoted context omitted.

I personally feel password managers are convenience that bundles separate risks into a single point of failure.

It might have been a convenience thing back when there were only a few sites on the Internet but it's unreasonable, and just not practical to expect users to memorize several hundred, good, unique passwords for all the websites and apps they'll use in their modern digital life. Login with Google/Facebook/Apple/auth0 help mitigate the number of passwords to remember, but then you are beholden to that company. Not all…

For silly websites I agree, a password manager makes sense. For banking, identity, and work, I prefer to keep those keys on my person, in my head.

Re: Someone keeps trying to reset my Facebook password

#205

Earlier quoted context omitted.

There's an idiot sharing my first & last name who never remembers to put his middle initial in his email address, and as a result I see he's an alcoholic, has financial trouble, keeps applying for artist grants, has a social sciences degree of some sort, is involved in local politics, and so on. I could also choose to pwn his online betting, games, dating, and porn accounts any moment I want. I may or may not have ch…

How? If his email is something like johnWsmith@gmail.com and he's accidentally entering johnsmith@gmail.com (you), how is he ever able to register? If he's sending password reset requests to the wrong address (yours) - wouldn't every site in existence realize that's not the registered account and the email would never end up in your inbox?

A surprisingly large number of sites will let you register without requiring an email verification.

I continually get a lot of emails, sometimes with private information to first name.lastname@gmail.com where people with my same name just use that without caring that it is not their email address. You probably aren't getting that job offer and you probably aren't getting that bank load approved without being able to see the emails.

For a while I tried to notify the senders but they rarely reacted or even provided a way to contact them. Now I worry about it becoming a scam vector so I just delete them.

Re: Someone keeps trying to reset my Facebook password

#206

Earlier quoted context omitted.

Greylisting is really a rare configuration choice in modern times and has always been a "results may vary" sort of deal. Personally I wouldn't factor those users into my considerations.

I do password resets for clients fairly routinely. I run into greylisting behavior about 2 doz times a year. Often happens in spurts. Just last week I ran into greylisting a bunch of times, while testing a new mail server against gmail accounts. Same thing two weeks prior for a diff server. This is with SPF, DKIM and DMARC setup. Corp and personal gmail accounts - no rhyme or reason to when it happens.

That might not be greylisting like I'm thinking of, Gmail has its own secret process but in my experience they accept the message and decide if they want to deliver it or not later.

If you don't have a ton of users you don't have the "celebrities getting hit thousands of times with password reset requests" problem and if you do have tons of users, your higher volume of transitional emails makes Gmail trust you more so your issue is much less likely to happen.

Re: Someone keeps trying to reset my Facebook password

#207
post #194

Earlier quoted context omitted.

There's an idiot sharing my first & last name who never remembers to put his middle initial in his email address, and as a result I see he's an alcoholic, has financial trouble, keeps applying for artist grants, has a social sciences degree of some sort, is involved in local politics, and so on. I could also choose to pwn his online betting, games, dating, and porn accounts any moment I want. I may or may not have ch…

I've got one who keeps forgetting he's got numbers on the end of his email address. He's a sheriff in a southern state. Also an idiot. What's doubly annoying is the US gov is pretty lax at things like unsubscribe links, so I keep getting notifications about his Medicare account that I can't unsubscribe from.

They exempted themselves from the spam rules.

Re: Someone keeps trying to reset my Facebook password

#208

Earlier quoted context omitted.

There's an idiot sharing my first & last name who never remembers to put his middle initial in his email address, and as a result I see he's an alcoholic, has financial trouble, keeps applying for artist grants, has a social sciences degree of some sort, is involved in local politics, and so on. I could also choose to pwn his online betting, games, dating, and porn accounts any moment I want. I may or may not have ch…

How? If his email is something like johnWsmith@gmail.com and he's accidentally entering johnsmith@gmail.com (you), how is he ever able to register? If he's sending password reset requests to the wrong address (yours) - wouldn't every site in existence realize that's not the registered account and the email would never end up in your inbox?

Once you leave sites actually created by tech companies many sites don't actually verify that you own an address you just input anything you please that looks like a valid email. The extra step as it were isn't included in all online tutorials on "how to manage implement login".

To deepen the problem gmail actually ignores periods in email so even if johnsmith@gmail.com already exists its possible create accounts for both john.smith@gmail.com and j.o.h.n.s.m.i.t.h@gmail.com because although google will absolutely treat those 3 as the same thing and route all messages to any of the above to our first fellow randombob.com treats those as 3 unique email addresses.

This was actually exploited by the fellows that robbed Washington states unemployment system during the pandemic applying for unemployment for folks that didn't need it including humiliatingly enough actual workers who worked for the washington state employment security division. To make their robbery more ergonomic multiple fraudulent accounts were set up with email addresses that differed only by periods. In this instance it only worked of course because they were indeed able to verify their email accounts.

In other instances for example myFico has weak protections on signing up. You can use ANYONE's email address to sign up but strong protections on actually accessing information. This means in effect if someone signs up as you as actually happened to my wife you will never be able to get them to stop spamming you with that persons personal information nor make the person stop giving out your email.

I wasted 15 minutes of my life trying to explain that the address given actually was my wife's email address. Bitched to their credit union/other institutions about the persons financial data being leaked, created a complaint with the FCC. YADA YADA nobody cares about properly implementing email verification or leaking people's financial information.

Re: Someone keeps trying to reset my Facebook password

#209

Funny I keep getting login codes for my Microsoft account. Also there is seemingly no way to figure out who is doing it or how to stop it. I wish I could just disable that form of login, I have a very safe password so the login via email isn't necessary.

I thought this was the Passwordless account they implemented (EDIT: didn't realize you weren't talking about the Authenticator app), but I had it turned off. I somehow managed to make it stop by re-enabling/re-disabling both Passwordless and 2FA. So now they always ask me for a password and then I get the challenge.

To this day, I can't comprehend how this is supposed to be safe. So someone can just type in my username and wait until i eventually misclick in the Authenticator app? If it was from a browser I have used before at least, but I was getting these challenges from around the globe.

Re: Someone keeps trying to reset my Facebook password

#210

Funny I keep getting login codes for my Microsoft account. Also there is seemingly no way to figure out who is doing it or how to stop it. I wish I could just disable that form of login, I have a very safe password so the login via email isn't necessary.

Yeah - and what is crazy is when you think about it - Microsoft generates a 6 digit code. So it is a "one in a million" to randomly guess what the code is on any given login. But it is "one in a million" for each Microsoft account you know about - and if they have millions of email addresses, and automate it each day (I also get attempts 1-2 times per day). Yes - the odds are small - but there is a greater than 0% ch…

If you have 500 million accounts you know of, you'd be breaking into around 500-1000 a day.

I suppose that's a decent rate, but it feels like most Microsoft accounts will just have something like Office or Minecraft set up.

Post reply on HN