Earlier quoted context omitted.
I'm sure they'd prefer to receive notifications from their university on WhateverComesAfterSignalBecauseImOldAndDontKnow, but I imagine that SMS is the 2nd best thing (and probably still generates eye-rolling about the university being old fashioned).
But then you're stuck logging into the payment portal and filling out the form information with your phone, which is my own personal hell.
Facebook does not plan to notify half-billion users affected by data leak
301–310 of 315 posts
Re: Facebook does not plan to notify half-billion users affected by data leak
#302Earlier quoted context omitted.
What better options are there that have approximately the same ease of use? SMS works with every conceivable phone, even most landlines if need be, users don't have to install a separate authenticator app, which may require a Google/iCloud password (now where did I put that post-it note?), that takes up space that may be scarce on low-end phones and that may not even be compatible with very old phones, leaving affect…
> users don't have to install a separate authenticator app, which may require a Google/iCloud password If they wish to use Apple then that is their own choice, but on Android it's quite trivial to download Red Hat's open source authenticator app[1] from f-droid (the website, you don't even have to install the store if you don't want that). It's quite bare bones on graphics and features, doing only what you need it to…
That's even less intuitive than using the default app store. That's a whole new slew of concepts you need to grok (you can download an app from the web and install it without an app store; what is this fdroid thing? is this a virus? what do these dialogs mean?), plus training people to do this without also giving them the knowledge when and why this is safe isn't exactly helpful, but that's a lot to ask from a simple sign-up flow for a hypothetical niche app built by a hypothetical two-person team.
> And if people don't have a phone with support for apps, then you can still fall back to SMS.
You can, but that adds to the complexity and support burden and probably also costs you users due to sign up friction.
> Fun fact: my grandpa can't use SMS either, your solution is not as universal as you make it seem. He never has been able to due to sight issues (it's not an age thing, though it doesn't help if you're close to illiterate and now need to start to learn how to use solutions for sight-impaired people due to this information age having onset).
That's an interesting case. I'd like to think there would be a fallback for people like him, but I guess, in the vast majority of cases, he'd just be left out. The current state of inclusivity in tech is abysmal, though I've seen vision-impaired and deaf people get around their devices surprisingly well; it's still an embarrassment that this industry won't do better. It's hard to get this right when it should be hard to break this, but current frameworks and paradigms don't prioritize this. It's shameful IMO.
I do think SMS is a lot more accessible than authenticator apps and the like, even though that still will not work for everyone.
> Can't we have the better solution as well as the accessible one?
I'm not saying you can't or shouldn't offer the best solution you can. By all means give me Yubikey support and several fallbacks. But I can see quite well how not everyone might want or be able to.
> No no, you got that backwards. All Facebook needs is your phone number, or whoever it is that pinky promises to only use your phone number for security.
Facebook definitely should get rid of SMS factors. If anyone has the resources to do much better, it would be them and the other giants. Not sure how they handle that, though. They'd still collect phone numbers in any case, but they'd happily image people's internal organs if they could, so that is a separate issue.
Apart from that people seem to be quite happy to use their phone number for signup if it makes signup quicker and less annoying. Even if the primary flow is email and alternatives are hidden in another tab, phone number still tends to get used a lot, in my limited experience. Same with Facebook/Google login.
Plus, for most people ai guess it isn't as black and white; in quite a few cases I've given my phone number even if signing up via email, because it helps a lot if people can just call me in case of issues (e.g. the restaurant is out of my extra topping).
That said, I'm all for offering as much choice as possible, and I'm not happy with the inflationary use of phone numbers as the only way to sign up, and I'm all for Yubikey support in every app, and it's disappointing that OS/browser vendors don't make this easier and more convenient, and if anyone wants to let me have as many anonymous phone numbers as I need, I'm very interested.
But, still, I can totally see why a resource-strapped product/dev team might come to the conclusion that SMS second factors are sufficient for now.
Re: Facebook does not plan to notify half-billion users affected by data leak
#303Earlier quoted context omitted.
If you change your DoB every year like I do, you'll be fine...
The leak didn't include DoB.
Re: Facebook does not plan to notify half-billion users affected by data leak
#304Earlier quoted context omitted.
If you change your DoB every year like I do, you'll be fine...
Assuming not sarcasm, how does that help? Do you do this for just Facebook or for multiple websites?
I don't have an account, but I'm fairly sure Facebook doesn't let you edit it once you've given it.
Re: Facebook does not plan to notify half-billion users affected by data leak
#305Re: Facebook does not plan to notify half-billion users affected by data leak
#306Earlier quoted context omitted.
I deleted my account a few months ago and was pleasantly surprised to find that it didn't surface in the breach. It could just be hiding in a different datastore of course, but it's definitely more fucks than I thought they gave.
The leak is from 2019 though
Re: Facebook does not plan to notify half-billion users affected by data leak
#307Earlier quoted context omitted.
None of the birthdays I enter are real. :P
They have to be consistent, yes? If I enter 6/7/1989 everywhere they just have to get it once.
Re: Facebook does not plan to notify half-billion users affected by data leak
#308Earlier quoted context omitted.
I think Facebook (rightfully, IMO) would argue the existence of that data dump is no proof that data came from Facebook’s servers. They can’t assume that, or trolls or unscrupulous competitors would start creating ‘Facebook’ data dumps left and right. I do wonder what EU regulators will say about their viewpoint that they do not have to inform their users, though.
>I think Facebook (rightfully, IMO) would argue the existence of that data dump is no proof that data came from Facebook’s servers. Mark Zuckerbergs phone number was in the dataset. It came from Facebook.
Re: Facebook does not plan to notify half-billion users affected by data leak
#309I’ve said it before and I’ll say it again, unless and until, companies like Facebook are fined appropriate amounts they’ll never stop. Quite literally, every business school on the fucking planet will tell you do something if it’s cheaper. It is cheaper for them to not give a fuck, than to give one. Unless they are fined upwards of $20-50bn it’ll never stop because it’s always going to benefit their bottom line. Full…
If customers do not care enough to stop using the product then there is no harm. Put in another way: the people you are trying to protect don't want your protection, because they don't care enough about the breach to stop using the product. They shouldn't be learning about the breaches from the company that has been breached because that gives the company too much power. Instead we should empower watchdog organizatio…
Re: Facebook does not plan to notify half-billion users affected by data leak
#310I’ve said it before and I’ll say it again, unless and until, companies like Facebook are fined appropriate amounts they’ll never stop. Quite literally, every business school on the fucking planet will tell you do something if it’s cheaper. It is cheaper for them to not give a fuck, than to give one. Unless they are fined upwards of $20-50bn it’ll never stop because it’s always going to benefit their bottom line. Full…