Live data from Hacker News

Facebook Asking for Some New Users' Email Passwords

thedailybeast.com

281–290 of 377 posts

Re: Facebook Asking for Some New Users' Email Passwords

#281
post #171

Earlier quoted context omitted.

Ignoring their recent fail at logging passwords. It has been established as minimal practice, that NO ONE should be asking you about your password. If this would become a normal, it would also make regular people more likely to give out their passwords. And email is key to your online kingdom, so it's a big deal, if it gets compromised.

At the very least, your mail client has to ask you for your email password. Might sound like I'm splitting hairs but I don't think most users have a strong sense of why that's different from Facebook doing it. And with wizzy online features crammed into more and more desktop software (seen Photoshop lately?) you can't really fault them for it.

Your mail client isn't a company, that's not the same.

You're right that the wording is important, and we do a bad job explaining what passwords actually mean, and how to treat them. A simpler analogy: Don't give your house keys to strangers, McDonald's has no business asking you for your keys to confirm your order.

I don't think users need to understand why, they just need to understand what to do / not to do. I've taught my mother to never give anybody her passwords, not even me, and if anyone asks her for her password to call me. She's mildly annoyed when I'm helping her with something and I tell her to please input her password, but she's gotten used to it. Did it work? It did. The representatives for a car sharing company were poorly trained and asked her to write her email and her password into a form. She refused, walked out and called me because she was worried that they were trying to get into her bank account. Turns out they wanted her to choose a password for their service, and were just very bad at wording it (and had the terrible idea to have customers hand-write it into a form and let somebody transcribe it into the computer system) and the guys working in the office had only been handed a script, they didn't actually know what information they were supposed to get. I'm certain that they accidentally harvested a good number of valid email/password combinations since it's a leading company that is owned by a major car manufacturer and has a good reputation.

Re: Facebook Asking for Some New Users' Email Passwords

#282

Earlier quoted context omitted.

This. I studied Electrical Engineering and in my experience, the only thing my classmates cared about was the technical aspects of the field, and often they couldn't see the big picture. Great talents of course, but more like robots, not even capable of understanding the humanitarian aspects of life. Such a waste. Disclaimer: It's just my experience, not necessarily true for all engineers and engineering schools.

That's one part of it, I'm sure. Another part is that if you pipe up, you risk getting shunned: loss of income, loss of status, loss of being "part of the cool kids". Sure, you can get another job (that pays less) but you'll probably not work at the same cutting edge technology, and when you tell relatives or friends who you work for, their eyes don't light up. If somebody offered me five to eight times as much as I…

If somebody offered me five to eight times as much as I make today with a huge boost in status and other positive side effects, and all they ask is to quiet down those silly principles, I'm not so sure I'd say no. "You can still do good in 5 years when you've made enough money to be set for life", I'd probably tell myself.

The worst thing is, sticking to those principles just means someone else will take the job.

Coming out of university, I had one job offer (it was a bad down market at the time). My principles made me say no. I didn't want to work on guidance systems for military applications, thank you very much. That choice has cost me a great deal in earning potential. Even so, I would find it hard to blame someone for compromising their principles.

Re: Facebook Asking for Some New Users' Email Passwords

#283

Earlier quoted context omitted.

Degiro, an investment platform, do the same for your initial £100 deposit: you enter your bank's auth info and they do the wire transfer for you. It uses a 3rd party system called "SOFORT". Thereby training the public that passwords to a bank account should be given to random third parties, undoing years of pain staking training efforts. If they asked for your PIN code, people would clearly balk. But somehow, passwor…

> It uses a 3rd party system called "SOFORT" Which is Klarna. > Thereby training the public that passwords to a bank account should be given to random third parties, undoing years of pain staking training efforts. Accounts details are relatively fine to enter on other sites, just entering 2FA tokens should be limited for transactions that you really want to confirm.

There are three reasons I disagree:

1. You train end users that entering banking credentials on 3rd party sites is Okay. This makes educating against phishing an impossible task.

2. Many banks require (a form of) 2FA to log in. Perhaps it’s a “2 letters from a secret code” system (see sibling post). You’re now educating users that entering 2FA on 3rd party sites is ok. This is the end of educating users about any security at all, really.

3. This 3rd party gets access to my full transaction history, everything I ever spent on anything, using this account. That is an unconscionable overreach in personal data access. “But we don’t use it / read it / store it / we only send it to trusted partners / .....” I’ve heard that song too many times.

If someone asked for email account passwords and 2FA login, people would scream bloody murder. What makes this different?

Note that none of this is about money. If someone defrauds me, the bank will refund me. It’s the least of my worries, really. Sure, rather not. But the bank can’t refund my privacy if someone exfiltrates purchase history. Based on any data leak ever, I think we all know what’s the most valuable thing in my bank account .. it’s not the money. It’s the data.

Re: Facebook Asking for Some New Users' Email Passwords

#284

All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...

Transfund does this now. I tried complaining to their support and they just don't get it. Account/routing number should be enough, they don't need access to my transactions, etc.

Add that on top of increasing fees and I'm seeking alternatives.

Re: Facebook Asking for Some New Users' Email Passwords

#285
post #67

I just don't understand how this gets implemented without someone speaking up and saying "hey, wait, isn't this an insane thing to do?". I would guess it's some combination of the complainers being ignored, and people at a higher level thinking "well we're doing this in a secure way, as long as the user trusts us, and why wouldn't they trust us, we're Facebook!".

Facebook also asked users in Australia for their naked photos. This isn't even the weirdest privacy invading request that they've had recently. This is business as usual.

https://www.irishnews.com/magazine/technology/2017/11/08/new...

Re: Facebook Asking for Some New Users' Email Passwords

#286
post #65

Earlier quoted context omitted.

Swedish payment processor Klarna does something similar to this as well. If bying something through the platform by direct bank transfer you are asked to sign to your bank to accept the payment using BankID [0], which is normal. What is not normal is that they grab your personal identification number and send a login request using BankID before you open your app. When authenticating the login you authorize one of Kla…

>they are relying on recent court cases where scammers would call old people asking them to log on to check their retirement accounts How would this work? As far as I know Swedish courts don't follow stare decisis.

This is going to contain errors, one would have to be a professional to get this right, but the gist is that formally, no, but in practice it kind of does.

If the decision was made by one of the higher courts, a precedent will be created, which while not formally binding is essentially treated as such. In general the precedents can't create new law, only interpret. However this turns out to sometimes be a difference without significance, as effectively new law is created due to how heavy lower courts are leaning on some such cases.

One I have some knowledge of regards agency of company representatives where the interpretation made it essentially legal for a company to use third party sellers to act as representatives for the company write and sign contracts, which then the original party could renege on at any time, with no penalties by simply stating that their agent had overstepped their bounds. This was a case of a house builder backing out because the agent had given a price that the house builder deemed a little too low. This is described in the relevant literature as a clear precedent for all manners of company agency, while if you read the actual judgement it was clearly marginal. But it has effectively created new law. You now have to make sure to write contracts with an employee of whomever you are dealing with if you are to be able to trust in your contract.

All courts also have a right to judicial review, thus in theory a single local court can nullify any law if it doesn't follow the constituting laws, either completely, or for a specific case. If this happens, then that case becomes a precedent. This is however somewhat rare as far as I understand it, as it's somewhat of a joke that the best way to loose a case is to refer to the constituting laws, as they are essentially completely ignored.

Yeah, I'm amazed it works at all.

At least on the surface it seems our judicial system really has some deep flaws that nobody has really dared to address.

To little real oversight, no binding checks on the constitutionality of new laws - although the advisory committee tends to be respected, and no formal way afaik to revoke precedents that turn out to have bad consequences.

It seems to work a lot based on some form of "gentlemen's agreement", and tradition. By now I guess we all know how quickly those can crumble.

Re: Facebook Asking for Some New Users' Email Passwords

#288
post #58

Earlier quoted context omitted.

The general public is extremely myopic and lazy . They will hand over anything you ask for if it means they have to do less work in the short-term. Convenience trumps all. It's how we've ended up with people voluntarily purchasing, maintaining, carrying around at all times, keeping charged and powered on, their own personal surveillance devices running heaps of software they have no control over.

Counterpoint: Many people of the "general public" are at least vaguely aware of the fact that they're making risky decisions, but proceed regardless in order to reap the short-term rewards that you mention, calculating that the benefits are worth the hypothetical costs, and many of them will live and die having been right about making that tradeoff.

Counterpoint to your counterpoint: Living in flyover country surrounded by people with at best a high school education has taught me MANY things about how the public consumes tech.

They have no idea what is possible with technology. They literally do not and cannot comprehend what can be done with their information online. To the folks I interact with, it's almost magical how it works.

They trust, as another comment points out here, that someone is taking care of whatever trail they leave (if they even understand that's a thing). They trust that tech companies are acting in their best interests.

Maybe that's just anecdotal data from my experience, but it's my experience.

Re: Facebook Asking for Some New Users' Email Passwords

#290

Earlier quoted context omitted.

This. I studied Electrical Engineering and in my experience, the only thing my classmates cared about was the technical aspects of the field, and often they couldn't see the big picture. Great talents of course, but more like robots, not even capable of understanding the humanitarian aspects of life. Such a waste. Disclaimer: It's just my experience, not necessarily true for all engineers and engineering schools.

Did they not pay any attention during the humanities portion of their education? That's part of why it's there. Disclaimers: I'm not an engineer, but my CS degree is ABET accredited. I also took a few more Archaeology, Cog Sci, and Philosophy classes than strictly necessary.

Personal data point:

Did a Bachelor's + Master's degree in CS in Europe. Only around 5% of my coursework had (and could!) be outside CS. And you could fill that with things like Game Theory 102 or Copyright Law 101 or something without issue.

Post reply on HN