Live data from Hacker News

Facebook Asking for Some New Users' Email Passwords

thedailybeast.com

331–340 of 377 posts

Re: Facebook Asking for Some New Users' Email Passwords

#331
post #102

All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...

Monzo in the UK recently added a beta ("labs") feature in their app to check your Barclaycard balance from within the app. Sounded ideal as the Monzo app is the best banking app I've ever used. I figured they'd be using Open Banking (the new OAuth style authentication system rolling out across banks here). I went to turn it on only to find that they use a third party who ask for all of your Barclaycard credentials (i…

The third party Monzo uses is called TrueLayer. It's being discussed on the Monzo forums at https://community.monzo.com/t/monzo-labs-connected-credit-ca...

A couple of people have raised concerns about security and privacy.

Re: Facebook Asking for Some New Users' Email Passwords

#332
post #232

Earlier quoted context omitted.

If the on-line component goes anywhere beyond the ability to sync an opaque binary blob that only your local machines can decrypt and reencrypt, there's a problem there.

How does my secret key get from my phone to my tablet?

The devices could exchange their keys through a secure connection - be it direct (Bluetooth, LAN) or routed by a third-party service. It could also be transferred physically (through removable storage, or through retyping a bunch of numbers shown on one device into another device).

Re: Facebook Asking for Some New Users' Email Passwords

#333
post #65

All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...

Swedish payment processor Klarna does something similar to this as well. If bying something through the platform by direct bank transfer you are asked to sign to your bank to accept the payment using BankID [0], which is normal. What is not normal is that they grab your personal identification number and send a login request using BankID before you open your app. When authenticating the login you authorize one of Kla…

BankID generally have quite strict rules about how you use their authentication, or so I've hear from their customers. If it is as deceptive as you say, I really don't understand how/why BankID is allowing it.

Re: Facebook Asking for Some New Users' Email Passwords

#335
post #67

I just don't understand how this gets implemented without someone speaking up and saying "hey, wait, isn't this an insane thing to do?". I would guess it's some combination of the complainers being ignored, and people at a higher level thinking "well we're doing this in a secure way, as long as the user trusts us, and why wouldn't they trust us, we're Facebook!".

It was probably A/B tested and yielded the highest conversion rate.

Re: Facebook Asking for Some New Users' Email Passwords

#336
post #65

Earlier quoted context omitted.

Swedish payment processor Klarna does something similar to this as well. If bying something through the platform by direct bank transfer you are asked to sign to your bank to accept the payment using BankID [0], which is normal. What is not normal is that they grab your personal identification number and send a login request using BankID before you open your app. When authenticating the login you authorize one of Kla…

BankID generally have quite strict rules about how you use their authentication, or so I've hear from their customers. If it is as deceptive as you say, I really don't understand how/why BankID is allowing it.

It's not really BankIDs fault. It was discussed when it was discovered that Allra had misused BankID in this way. The BankID will say who/where is trying to log on, and the hijackers trust that users don't read the BankID login screen.

It's a great service and I can't believe shady things like this is allowed.

Re: Facebook Asking for Some New Users' Email Passwords

#337
post #228

https://www.axios.com/facebook-will-stop-asking-new-users-fo... Facebook told Axios that "a very small group of people have the option of entering their email password to verify their account when they sign up for Facebook," but noted that people could choose instead to confirm their account with a code or link sent to their phone or email. "That said, we understand the password verification option isn't the best way…

They shouldn't need to log in to the user's password account at all through OAuth or any other way! A side problem with this is that if it's truly easier for the user than clicking on an emailed link, then users are going to expect that from all of us. So you have to do the sleazy shit or from the users' point of view you are "behind" and less good. I wish there was some good way to educate the user to privacy danger…

Sounds like the perfect job for Public Service Announcements. I remember when those were a regular thing on TV.

Re: Facebook Asking for Some New Users' Email Passwords

#338

Earlier quoted context omitted.

There's a book about the process by which this happens: https://www.goodreads.com/book/show/558867.Disciplined_Minds > Many professionals set out to make a contribution to society and add meaning to their lives. Yet our system of professional education and employment abusively inculcates an acceptance of politically subordinate roles in which professionals typically do not make a significant difference.

Companies are not democracies. Is it a contradiction that we both praise democracy and spend our working time in dictatorships? Probably but we usually don't even notice it.

This is such an astute observation, yet remarkably simple.

I'd never stopped to think about it, but I think the world would be a much better place if more people did.

Re: Facebook Asking for Some New Users' Email Passwords

#339

Earlier quoted context omitted.

I agree partially. First of, I don't think the finance industry gets vilified for having flexible morals, they attract hate for having no morals at all. Certainly, you're right that we depend on each one to say "no, I won't do that", but I feel like there's a difference in quality: evil intent vs willful ignorance/negligence. There might be borderline illegal tax-dodging with large tech companies, there might be irre…

> Certainly, you're right that we depend on each one to say "no, I won't do that", but I feel like there's a difference in quality: evil intent vs willful ignorance/negligence. Oh so you are saying that the willful and deliberate exploitation of people's private data, the willful and deliberate ignorance of laws by companies like Uber, the willful and deliberate "research" done by tech companies to determine the most…

No, I'm not saying that at all. There are _some_ companies that run targeted campaigns to influence elections, sure, but they are a tiny minority in the world of tech. I don't like Uber's business tactics either, but I don't see them as the face of the tech industry - in fact, I don't really see them as a tech company. Count everybody who's main source of income is driving for Uber as an employee and the percentage of employees working tech roles is pretty small. Many large companies (including banks) have more and more complicated tech than Uber.

Again, let me make that clear: I'm not arguing that every company in the tech industry is staffed by angels, but that intentional bad actors in tech are the exception, not the norm.

> Borderline illegal tax-dodging by large tech companies is business as usual

And I haven't said it wasn't, I've merely compared it with what the largest banks have been involved recently. I don't know if it got worldwide coverage - this is what I was referencing: https://en.wikipedia.org/wiki/CumEx-Files

> I don't see them warning their users that right now they are (maybe) not being profiled by governments for thought crimes, but the data is all there, so if in 10, 20 or 50 years time the government changes, this is a definite and very real risk.

And I'd love for them to be legally required to explain privacy considerations to their users in such a way that informed consent can be given. Again: I'm not "pro big tech", I'm saying that big tech still has some room if they want to rub shoulders with big finance when it comes to amoral business practices. Big tech operates in a grey area, big finance hasn't seen anything but #000 in decades.

Re: Facebook Asking for Some New Users' Email Passwords

#340
post #308

I recently learned that when you connect your Paypal account to your checking account, there's two verification methods you can choose between: 1) the good old fashioned, we'll make two small deposits into your account, tell us what they are; and 2) just give us the login info for your bank's web site. But Mint works the same way, doesn't it?

I believe most if not all legitimate companies that ask for your banking credentials (besides your bank, obviously) are just passing them straight to https://plaid.com/ . It's still questionable whether you should trust Plaid with your banking credentials, but at least you probably don't need to trust that Paypal and Mint are both going to store your credentials securely.

Why don't banks provide a read only api and login/password if this type of thing is becoming more common.

Providing any company my banking or email account login password sounds like a really bad idea. And something I'm not willing to provide.

Post reply on HN