Live data from Hacker News

Facebook Asking for Some New Users' Email Passwords

thedailybeast.com

351–360 of 377 posts

Re: Facebook Asking for Some New Users' Email Passwords

#351
post #321

Earlier quoted context omitted.

"That said, we understand the password verification option isn't the best way to go about this, so we are going to stop offering it, now that we've been caught ." Facebook always leaves that part out of its responses to these problems.

Caught? They offered the feature directly to users. It wasn't a secret.

>Caught? They offered the feature directly to users.

Who didn't know any better, nor why it is bad in general and how it can harm them specifically.

So yes, FB was caught; exposed, if you wish. Especially given that they didn't roll out this feature to everyone, including you and me, which would result in immediate disaster.

Re: Facebook Asking for Some New Users' Email Passwords

#352
post #243

Earlier quoted context omitted.

I don't have a citation, but I have read repeatedly that stock analysts cite "overpaying" their workers as a place where they could cut costs and boost short term profits.

Amazon is know for a large capital investment and their stock has gone up even though they could cut costs and increase their margins.

Capital investment != labor costs

Re: Facebook Asking for Some New Users' Email Passwords

#354

Earlier quoted context omitted.

I use mint even now. I'm generally technically paranoid, and have just concluded mint is not actually that risky. Here's why: 1. Most banking companies seem to have a much better security landscape than other places, including tracking where you're logging in from. Even with a password it won't be easy for a hacker to do stuff with my accounts. Almost any change or transaction triggers an email and sms alert too. 2.…

Mints privacy policy includes this language "we may prepare and share information about our customers with third parties, such as advertisers or partners, for research, academic, marketing and/or promotional purposes." - where any usage of "may" can be substituted with "will". They say they will anonymize data, but advertisers have no interest in data if they can't action on it -- i.e. use the data they buy for targe…

To some of us (me) the service Mint provides is well worth letting some marketer know I spent $50 at Walmart yesterday, that's not sensitive information to me, and if it were I'd be paying in cash.

I even gave the transaction history of all my credit cards directly to Drop (https://www.earnwithdrop.com) in exchange for a few dollars, that's how little it means to me. (So far around $30)

Re: Facebook Asking for Some New Users' Email Passwords

#355
post #308

I recently learned that when you connect your Paypal account to your checking account, there's two verification methods you can choose between: 1) the good old fashioned, we'll make two small deposits into your account, tell us what they are; and 2) just give us the login info for your bank's web site. But Mint works the same way, doesn't it?

Yep, Some banks do the same thing when you add an account for external transfer.

Re: Facebook Asking for Some New Users' Email Passwords

#356
post #268

Earlier quoted context omitted.

Where's the greater RoI in this case, what shady shit were they doing once they gained access to users email passwords??

Realistically, probably just logging into the email account once to prove ownership. Not dissimilar to how LDAP authentication works. Is it a worst practice in our industry right now? Yep. Is it nefariously evil, probably not.

The industry standard appears to be "click on a link in an email", I think that's what FB did for me. So the question still remains what the RoI is that makes getting users passwords better. The only answers I can give are very bad, I can't see a legitimate reason to change to do it that way.

Re: Facebook Asking for Some New Users' Email Passwords

#357
post #67

I just don't understand how this gets implemented without someone speaking up and saying "hey, wait, isn't this an insane thing to do?". I would guess it's some combination of the complainers being ignored, and people at a higher level thinking "well we're doing this in a secure way, as long as the user trusts us, and why wouldn't they trust us, we're Facebook!".

I was once in a conflict with a bunch of people at a larger e-commerce tech company because I railed against the practices and requirements of one of the stupidest projects that I was pushed into. The 'wisest' amongst the group, justifying his subservience, stated as an argument: 'they debate, they decide, we deliver'. I felt a visceral sense of disgust at hearing that and never spoke to this person again. He is doing quite well slithering up the corporate ladder, last I heard. The stupid project in question cost the company millions and died a well deserved whimpering death within a few months.

Re: Facebook Asking for Some New Users' Email Passwords

#358

I had someone create a Facebook account with my email once. I let it persist for a year until I got tired of the friend request notices. Did a password reset and deleted the account.

Did you verify the email for them?

No. It was never verified. Facebook didn't care.

Re: Facebook Asking for Some New Users' Email Passwords

#359

Earlier quoted context omitted.

No, I'm not saying that at all. There are _some_ companies that run targeted campaigns to influence elections, sure, but they are a tiny minority in the world of tech. I don't like Uber's business tactics either, but I don't see them as the face of the tech industry - in fact, I don't really see them as a tech company. Count everybody who's main source of income is driving for Uber as an employee and the percentage o…

> Again, let me make that clear: I'm not arguing that every company in the tech industry is staffed by angels, but that intentional bad actors in tech are the exception, not the norm. Just to be completely clear, are you arguing that the opposite is true in finance - i.e., that the norm is to be intentionally malicious?

I'm much closer to that position than the opposite.

This doesn't go for day to day interactions between you and a bank clerk, but rather for product development, sales etc. Fortunately, the industry is much more heavily regulated that the tech industry.

Re: Facebook Asking for Some New Users' Email Passwords

#360
post #321

Earlier quoted context omitted.

"That said, we understand the password verification option isn't the best way to go about this, so we are going to stop offering it, now that we've been caught ." Facebook always leaves that part out of its responses to these problems.

Caught? They offered the feature directly to users. It wasn't a secret.

It wasn’t announced on their News site, and when the press asked about it, their first on the record statement is ‘we’ve coincidentally reached the same conclusion at just this same time and will shut it down sometime’.

I do not give Facebook the benefit of the doubt here, but coincidence is technically possible.

Post reply on HN