Live data from Hacker News

Facebook spamming users via their 2FA phone numbers

mashable.com

301–310 of 380 posts

Re: Facebook spamming users via their 2FA phone numbers

#301

Finally, somewhere I can appropriately vent about this. About TWO years ago I was constantly annoyed by the 'secure your account: add your phone number here' banner frequently displayed at the top of the page upon loading FB, so I input my number to make it disappear for good. (Also, they kept hiding the 'x' (close) icon in different spots, making the banner difficult to dismiss.) A few days later I got a text messag…

>I've had my account since 2006 and despite the company's terrible practices, I'm really not interested in disconnecting for good at this time Having a Facebook account is like being in an abusive relationship. You've been together for a long time, and you keep hoping they'll change, but they never do, and it just gets worse and worse. The sooner you realize this this and get out, the less additional time and energy…

To add to this... I also made my account sometime in 2006, right after you didn't need an .edu anymore. It was a great platform, because it combined my friends, photos, and events.

So I could find out about an event, go and meet people, and then find them later in the photos and friend them. It snowballed very quickly, and it helped that I was really into photography at the time. It really was the perfect social platform for me at the time. It contributed greatly to my life.

For me, the main motivation to stop using it and eventually leave was all the frontend changes that made the website clunky and tedious to use. It used to be a joy, and now it's just... Well, IYCSSN... Even m.facebook.com, and many of the features are broken on it.

I deleted my account a year or two ago, after a couple of failed attempts, since there was a 14-day cool-off period before they would actually "delete" your account.

I recently made a new one just for keeping up with a couple of event spaces, but that's basically all I do on it. That, and I friend all the spammer accounts that send me requests, because, why not? The more the merrier. I'm pretty sure that's where most of the growth is coming from at this point.

Re: Facebook spamming users via their 2FA phone numbers

#302

Finally, somewhere I can appropriately vent about this. About TWO years ago I was constantly annoyed by the 'secure your account: add your phone number here' banner frequently displayed at the top of the page upon loading FB, so I input my number to make it disappear for good. (Also, they kept hiding the 'x' (close) icon in different spots, making the banner difficult to dismiss.) A few days later I got a text messag…

It might sound harsh, but from your comment you know exactly what you were doing and the probable consequences.

At this point I'm not quite sure simply terminating is the best way forward, sanitizing a profile with disinformation ( or straight filling with garbage up to the brim) might work better?

Re: Facebook spamming users via their 2FA phone numbers

#303

Earlier quoted context omitted.

I have blocked all of FB's allocated networks worldwide on my machine (via a look up of allocated IP space and fed into iptables / ipset).[0] So FB doesn't even get "phantom" traffic from me (indirect traffic from FB logos / js on random websites). I only log into FB a few times a year and only via a temporary VPS in another country and using an incognito browser tab. So now FB has taken to emailing me complaining th…

I know a few people that completely block every IP range owned by Google, Amazon, or Facebook. Most of that works fine, sometimes some shitty websites are on AWS or GCP or load JS frameworks from their CDNs, but the worst is: You can't connect from Android to their WiFi anymore. Android pings a Google server, if it can't open a connection, it immediately disconnects. In Android 8.1, there's no way around that anymore…

Can the response be faked?

Re: Facebook spamming users via their 2FA phone numbers

#304

Earlier quoted context omitted.

I know a few people that completely block every IP range owned by Google, Amazon, or Facebook. Most of that works fine, sometimes some shitty websites are on AWS or GCP or load JS frameworks from their CDNs, but the worst is: You can't connect from Android to their WiFi anymore. Android pings a Google server, if it can't open a connection, it immediately disconnects. In Android 8.1, there's no way around that anymore…

Can the response be faked?

Probably, considering that domain is HTTP only, but why is this even necessary?

Sometimes I do want to connect to a local network without internet.

Re: Facebook spamming users via their 2FA phone numbers

#305
post #157

Earlier quoted context omitted.

That thing facebook does with demanding your phone number, that's my favorite dark pattern. Apple does the same thing with iOS upgrades. First you pose a seemingly innocent question, like 'would you like to give us your phone number so we can keep your account secure?' or 'would you like to upgrade to new iOS?'. Then you take away the NO option. You replace it with 'i'll decide later'. And by doing so, you make it no…

It is a nasty dark pattern but I think in the case of iOS upgrades you can somewhat justify it - it’s important that users upgrade to avoid security issues etc. Of course really, iOS upgrades should be so pain-free that no one would ever want to say no, but that’s a different story!

I suspect that their motivation to push users to upgrade has far more to do with their planned obsolescence than anything to do with keeping users secure.

Re: Facebook spamming users via their 2FA phone numbers

#306
post #239

I don't understand why they require your phone number to do 2FA, and prefer it over any OTP app like Google Authenticator. It's 2018 Facebook.

Maybe they like phone numbers. Nevertheless Google Authenticator's permissions are in another league completely and one should probably be as suspicious of Google as Facebook.

Version 5.00 can access: Camera

    take pictures and videos
Other

    create accounts and set passwords
    full network access
    control Near Field Communication
    use accounts on the device
    control vibration

Re: Facebook spamming users via their 2FA phone numbers

#307
post #188

Earlier quoted context omitted.

As an ethical UX designer, unethical UX designers/PMs/ need to be shamed for creating/allowing dark pattern in their work. This goes against the fundamental tenets of empathetic UX design and in downright manipulative and bordering evil.

From the UX I've studied it seems that ethics is unrelated. Typically in consumer apps the goal is to increase MAU and engagement and UX is dictated by whatever moves the needle on those areas. It's hard to separate whether people are using the app more because of it's better design through UX design feedback loop iterations or if it is a dark pattern. For example it is entirely plausible that the sms notification be…

[deleted]

Re: Facebook spamming users via their 2FA phone numbers

#309
post #105

Earlier quoted context omitted.

If you message them you can know

If you’re relying on active messaging, why bother with FB?

Because that's the only reliable way I can message my friends. I'm not sure what else would work, people change/lose numbers all the time. Email is the worst. Not really much solutions out there if you want to keep in touch with your friends.

I personally mostly use messenger.com, rarely use the news feed anymore.

Re: Facebook spamming users via their 2FA phone numbers

#310
post #157

Earlier quoted context omitted.

That thing facebook does with demanding your phone number, that's my favorite dark pattern. Apple does the same thing with iOS upgrades. First you pose a seemingly innocent question, like 'would you like to give us your phone number so we can keep your account secure?' or 'would you like to upgrade to new iOS?'. Then you take away the NO option. You replace it with 'i'll decide later'. And by doing so, you make it no…

When I first opened up the Netflix mobile app and it asked me if I wanted it to show me notifications I thought "hey, that's nice, most apps just start spamming me without asking". I clicked "No thanks" and went on my way. It turns out, though, that it asks that _every_ single time I open the app. It's really annoying and I'm about to allow them only to block them at the OS level.

I'm guessing this is a bug. It asked me once (per device), and never asked again. Or I'm too trusting, and this is indeed a change in behavior for new customers.
Post reply on HN