Live data from Hacker News

Someone keeps trying to reset my Facebook password

reddit.com

221–230 of 246 posts

Re: Someone keeps trying to reset my Facebook password

#221
post #194

Earlier quoted context omitted.

There's an idiot sharing my first & last name who never remembers to put his middle initial in his email address, and as a result I see he's an alcoholic, has financial trouble, keeps applying for artist grants, has a social sciences degree of some sort, is involved in local politics, and so on. I could also choose to pwn his online betting, games, dating, and porn accounts any moment I want. I may or may not have ch…

I've got one who keeps forgetting he's got numbers on the end of his email address. He's a sheriff in a southern state. Also an idiot. What's doubly annoying is the US gov is pretty lax at things like unsubscribe links, so I keep getting notifications about his Medicare account that I can't unsubscribe from.

My wife has one of those, a rather stupid American who keeps using her gmail for things (and regularly tries to reset her password).

Re: Someone keeps trying to reset my Facebook password

#222

Earlier quoted context omitted.

> Long and strongly random You can choose to substitute length for randomness. A long enough random sentence works quite well. The hard bit is generating random sentences. I suppose you could use GPT to generate a sensible but random sentence, or just go old school and pick words from a large list and make a sentence with them.

Just battery horse staple it. https://xkcd.com/936/

Dictionary attacks? I know any two words isn't strong enough. Four seems little better.

Besides, this only gives you one good password anyway. You won't remember five unique password constructed that way, and if you have fewer than 80 passwords that you need to all be unique, I'd be shocked. Even AOL grandmas have several dozen accounts somewhere.

It's just bad advice, no matter how much of an xkcd fetish you have.

Re: Someone keeps trying to reset my Facebook password

#223
post #191

Earlier quoted context omitted.

I use bob@smith.com for any service that insists on an email address when they have no business doing so (eg public WiFi portals). I used to use bob@example.com to avoid spamming poor Bob but many services now disallow example.com as a domain. Sorry Bob!

I usually use marketin@domain-of-the-website.tld when a website insists on an email address to let me download something. I also curse at the marketing team, just in case.

I guess I’m more evil, I use abuse@ whatever site because I know that’s guaranteed to be monitored.

Re: Someone keeps trying to reset my Facebook password

#224

I own the domain of my last name. Several family members use (firstname@lastname.com). I once went to get a new phone at Best Buy, and the employee needed my email address. I gave it to here (firstname@lastname.com) and she insisted that it was NOT my email address. She insisted that it MUST end in @gmail.com or @yahoo.com, something like that. We frequently sign up for stuff online, and when we enter our email addre…

I tried using the clever email equivalent to me@firstna.me only using a more obscure TLD. Most people got very confused by this.

Re: Someone keeps trying to reset my Facebook password

#225
post #158

Earlier quoted context omitted.

The concept of requiring a special string to gain access to an account is massively dated, whether that string is something a human has memorised or random output from a password manager. Either the database of special strings lives in your brain, a notebook, a bit of paper, or encrypted on disk somewhere, but it's still a database of special strings. Public key crypto never took off for account management and neithe…

> The concept of requiring a special string to gain access to an account is massively dated, whether that string is something a human has memorised or random output from a password manager. I disagree. Any system, whether computerised or not, needs to pieces of information to authenticate a person - something the person has (identification), and something the person knows (authentication). You cannot simply rely on s…

I don't think they actually have to come up with a replacement for "something the person knows," they just need to prove it's already not there to be replaced. With password managers, the password becomes more like something the person has anyway.

Re: Someone keeps trying to reset my Facebook password

#226
a while ago I was messaged on Facebook by a nice Russian fellow who wanted me to _give_ him my Facebook username and domain name because he owns a dog wash in Moscow called dogself.

He seemed to imply that if I was located in Russia I would not refuse him "for reasons". He didn't really strike me as being connected, but maybe he washes Putin's dog..

Anyway I got a lot of password reset emails too until I set up 2fa with a yubikey.

I really need to remember to put something on dogself.com that will piss off the .ru but I haven't thought of anything good and legal (or at least ethical).

Re: Someone keeps trying to reset my Facebook password

#227

Earlier quoted context omitted.

How? If his email is something like johnWsmith@gmail.com and he's accidentally entering johnsmith@gmail.com (you), how is he ever able to register? If he's sending password reset requests to the wrong address (yours) - wouldn't every site in existence realize that's not the registered account and the email would never end up in your inbox?

He has john.w.smith and is repeatedly typing in john.smith, and also hands it out to humans who then want to contact me about his things. Apparently for many sites, user retention & money are more important than verifying an email address up front. He visits the scummiest betting and dating sites, so I'm not very surprised.

I'm getting similar behavior from another user with the same pattern.

I also get their college results, government assistance, a payday loan company, pinterest and subscriptions to newsletters sent to me for them.

Ive mailed them directly, multiple times but they dont seem to care. I'm now returning the favor, signing them up for all the crappy sites when i need a throwaway.

Re: Someone keeps trying to reset my Facebook password

#228
post #194

Earlier quoted context omitted.

I've got one who keeps forgetting he's got numbers on the end of his email address. He's a sheriff in a southern state. Also an idiot. What's doubly annoying is the US gov is pretty lax at things like unsubscribe links, so I keep getting notifications about his Medicare account that I can't unsubscribe from.

My wife has one of those, a rather stupid American who keeps using her gmail for things (and regularly tries to reset her password).

My friend gets one every month from a really ugly guy. Super illiterate, brings bendy-straws-to-bathrooms type, probably has grandkids.

(That's what we're doing here right? Bashing on the old and the tech-illiterate?)

Re: Someone keeps trying to reset my Facebook password

#229

Earlier quoted context omitted.

> The concept of requiring a special string to gain access to an account is massively dated, whether that string is something a human has memorised or random output from a password manager. I disagree. Any system, whether computerised or not, needs to pieces of information to authenticate a person - something the person has (identification), and something the person knows (authentication). You cannot simply rely on s…

I don't think they actually have to come up with a replacement for "something the person knows," they just need to prove it's already not there to be replaced. With password managers, the password becomes more like something the person has anyway.

> I don't think they actually have to come up with a replacement for "something the person knows," they just need to prove it's already not there to be replaced.

I don't know what this means.

Once you've identified a person, you still have to authenticate that they aren't masquerading as someone else. The replacement I asked for is not "how do I identify who I am talking to", it's for "Right, now that I've identified them, how do I verify that it really is* them."*

If you want to do away with passwords, tokens are no replacement.

> With password managers, the password becomes more like something the person has anyway.

Maybe. The user still has to both identify and authenticate themselves to the password manager anyway, so you can give access to the password manager as a "something they know" anyway.

Re: Someone keeps trying to reset my Facebook password

#230

I used to use an e-mail address a terrific domain name that I own. Without publicly disclosing specifics, it was like this: @ .com Thousands of people with this name, who didn't want to give out their real e-mail address, used this e-mail address when signing up for things online. They probably never thought it would be someone's actual address. I finally had to quit using it because of the tremendous amount of e-mai…

If you are bob@gmail.com or bob@yahoo.com, I am sorry about the decades worth of product offers, porn subscription offers, forum or blog reply notifications, etc.

Gmail launched with a minimum username length of 6 characters, so no one has ever had bob@gmail.com.
Post reply on HN