Maybe unrelated, but I think some people do this to check (at least partially) what email is tied to an account. E.g. if you suspect an anonymous instagram user to be your friend Bob, you can invoke the reset email procedure to see We sent an email to bo****@gm***.com Which gives you a hint
Folks in the thread noted that the recovery code sent was the same each time, which leads me to think it might have been a phishing attack. Send email that looks like FB recovery, but have the links go to some domain you own and snarf up creds, including MFA etc.
Someone keeps trying to reset my Facebook password
231–240 of 246 posts
Re: Someone keeps trying to reset my Facebook password
#232Earlier quoted context omitted.
The benefit is that people often don't remember which email they used for a service. They check their "main" email inbox but don't remember that they used their student email address 8 years ago when they signed up. By providing a hint they know which inbox to check and don't get frustrated because the email isn't coming. So it is a privacy tradeoff for better UX. If it is a good tradeoff will depend on how much you…
Why not just login to all of your email accounts in your email client?
Re: Someone keeps trying to reset my Facebook password
#233I used to use an e-mail address a terrific domain name that I own. Without publicly disclosing specifics, it was like this: @ .com Thousands of people with this name, who didn't want to give out their real e-mail address, used this e-mail address when signing up for things online. They probably never thought it would be someone's actual address. I finally had to quit using it because of the tremendous amount of e-mai…
I'm not a big Twitter user, and when I went to log in Twitter for the first time in probably a year or two, I forgot that it was still using my gmail account. I couldn't remember my password, so I did a password reset, received the email, and reset my password.
After looking around a bit, I realized this was not my account. It turned out the previous owner of firstnameLastname.ca also used firstname@firstnameLastname.ca
I ended up making a twitter post basically saying "Hello, I think I accidentally stole your account. If this used to be your account, email me.". A few weeks later I got an email from a fellow with the same name as me, who used to live in Canada but had moved back to England. I was able to change the email on the account and give him back access.
Re: Someone keeps trying to reset my Facebook password
#234I used to use an e-mail address a terrific domain name that I own. Without publicly disclosing specifics, it was like this: @ .com Thousands of people with this name, who didn't want to give out their real e-mail address, used this e-mail address when signing up for things online. They probably never thought it would be someone's actual address. I finally had to quit using it because of the tremendous amount of e-mai…
Mine is temporal at gmail. "Temporal" was my teenage gamer tag which I mostly stopped using decades ago, but it's been my gmail address for almost 20 years and changing it is not easy. The problem is, "temporal" happens to mean "temporary" in Spanish. As soon as Gmail became popular in the Spanish-speaking world, people started using it as a placeholder address. * Lots of people use it when creating throw-away accoun…
I still check the gmail account ever so often and it still receives spam. My Fastmail account is perfect even after a year.
Re: Someone keeps trying to reset my Facebook password
#235Facebook is almost un-usable for me. Every week or so they lock my account due to "suspicious activity" even though I haven't used my account. I have all the security features and such turned on like MFA and a strong password (that I have to change like every week after every time my account gets locked). There is no useful info in the security logs. I have no idea what to do to stop this from happening.
:p
Re: Someone keeps trying to reset my Facebook password
#236Earlier quoted context omitted.
I don't think they actually have to come up with a replacement for "something the person knows," they just need to prove it's already not there to be replaced. With password managers, the password becomes more like something the person has anyway.
> I don't think they actually have to come up with a replacement for "something the person knows," they just need to prove it's already not there to be replaced. I don't know what this means. Once you've identified a person, you still have to authenticate that they aren't masquerading as someone else. The replacement I asked for is not "how do I identify who I am talking to" , it's for "Right, now that I've identifie…
You responded to this after your second quotation, I effectively said the same thing twice in different ways to make my point. Hopefully you understand it now. To be fair, it's a somewhat complicated sentence, took me a while to put that thought into words.
> so you can give access to the password manager as a "something they know" anyway.
Mostly true. Ignoring password manager breaches, as that hurts your argument a little. Security researchers are currently of the opinion that the last LastPass security breach leaked people's encrypted password vaults, which people have somehow managed to decrypt since then. In that case, the password was something the attacker had, not something they had to know. But I think I mostly agree that access to the password manager can at least (mostly) be seen as something they know.
Re: Someone keeps trying to reset my Facebook password
#237Earlier quoted context omitted.
I've got one who keeps forgetting he's got numbers on the end of his email address. He's a sheriff in a southern state. Also an idiot. What's doubly annoying is the US gov is pretty lax at things like unsubscribe links, so I keep getting notifications about his Medicare account that I can't unsubscribe from.
My wife has one of those, a rather stupid American who keeps using her gmail for things (and regularly tries to reset her password).
Re: Someone keeps trying to reset my Facebook password
#238Earlier quoted context omitted.
If websites made a concerted effort to train their users to not "remember passwords", this could eventually be solved. Human brains are not designed to remember: * Passwords that aren't reused across the many dozens/hundreds of logins a person typically has * Passwords that aren't easily guessed phrases including substrings of personal information (birthdays, children's names, etc) * Long and strongly random Yet good…
I personally feel password managers are convenience that bundles separate risks into a single point of failure.
Re: Someone keeps trying to reset my Facebook password
#239Earlier quoted context omitted.
I'm a little confused. Does the code get generated on any attempt to log in, or only those that have the password and MFA is activated? Or when someone attempts password recovery? Because I'm a bit concerned if Microsoft passwords are leaking.
When attempting to login to your Microsoft account, instead of typing your password you can do an optional "one time password" generation thing from Microsoft. So instead of typing your password +2FA - they email you a 6 digit "one time password" that you can use instead. You cant disable this. So all Microsoft accounts could have a daily 1 in 1 million chance of been overtaken. Odds are low - but if you then spam th…