Earlier quoted context omitted.
My smartphone cannot be remotely turned into an overpriced wheel chock by someone in a call center.
Apple at least can absolutely do this, that's what the purpose of reporting a device stolen is.
Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
361–370 of 388 posts
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#362This is what I'm worried about, to be honest. Not necessarily getting hacked but just getting flagged, banned and burned with no recourse. This is why I commented on an article here some weeks ago that if they ever offered any paid user experience they'd be in trouble because they'd actually have to help their users with their issues. These tech companies should offer actual support the moment you spend money with th…
Facebook has offered a paid user experience to Oculus users for several years now, and so far no one has forced them to actually help users with these issues. Not the market, not regulators, and certainly not users. They will keep getting away with it simply because they can. What are you going to do about it?
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#363Earlier quoted context omitted.
So the email address is not 2FA secured?
It's my own mail server. I just tail the mail spool ...
>[...] via encrypted SMTP
In addition to establishing a secure socket, does the mule validate the mail server's TLS certificate name?
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#364I don’t understand how the hacker bypassed 2FA? Did OP accidentally entered his keys somewhere? Or did the hacker convince FB support to disable 2FA? How can we all avoid OP’s fate. Lot of comments go in-depth on yubi keys and whatnot. But if FB support disabled 2FA what good is a U2F, fido2 and whatnot?
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#365Earlier quoted context omitted.
There's no way clicking on a headline would lead to your account being hijacked... Unless there's a browser 0-day which are extremely valuable and no one would waste that on your FB account. Or if clicking the link downloaded malware and you ran the malware. Did you ever use the password of the FB account anywhere else? You getting phished is also much more likely than a browser 0-day. Did you have a security key on…
It was a secure account as far as the password goes, no 2FA. Like I said it was a bit of a throwaway account. Password 15 chars long, random chars. No phishing. I concluded that there's perhaps a cross-origin issue on Facebook's side that allowed cookie hijacking. The clickbaity link was almost tailor made for our group "[something ominous happened] in [your part of town]". Looks like it was auto-shared by someone wh…
That sounds much more likely to me.
When facebook has a website vulnerability that is exploited, they log everyone out, post a blog post, and makes big news:
https://www.wired.co.uk/article/facebook-hack-beach-single-s...
https://krebsonsecurity.com/2018/09/facebook-security-bug-af...
https://about.fb.com/news/2018/09/security-update/
>"[something ominous happened] in [your part of town]"
Those ads are all over. They determine [your part of town] through geoip or FB tells the advertiser your city. It's like the "singles in [your city]" ads.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#366Earlier quoted context omitted.
There's no way clicking on a headline would lead to your account being hijacked... Unless there's a browser 0-day which are extremely valuable and no one would waste that on your FB account. Or if clicking the link downloaded malware and you ran the malware. Did you ever use the password of the FB account anywhere else? You getting phished is also much more likely than a browser 0-day. Did you have a security key on…
This isn't correct, it's not the only way. A Facebook vulnerability is less valuable than a browser 0-day and could similarly leak credentials. In fact, Facebook has had numerous authentication blunders in the past. [1] One of them was a zero-click mechanism very recently. [2] Facebook's security team is a joke, or worse -- they're muzzled by product teams and forced to do their bidding. [3] [1] https://threatpost.co…
That hasn't happened here.
I don't really consider 3 years ago to be very recent.
I think that 3rd link is arguably not a vulnerability. If you intentionally want people to be able to look up future friends by email address, then that's basically the desired behavior. Now arguably allowing people to look up future friends by email is a privacy problem. Some users probably want that feature though. Yes a lack of rate limiting is a problem, but rate limiting won't stop attackers from doing it, it just slows them down.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#367Earlier quoted context omitted.
> if you have spare cash and like cool toys FIDO2 is a more capable second generation of the technology. Why would you want passwordless authentication? Isn't the whole point of 2FA that you have to have something and you have to know something?
The FIDO2 key is usually protected by a PIN that wipes the key after a few wrong attempts, so it combines the two itself. Besides, there's nothing that dictates how secure the key should be. You could use your hardware cryptocurrency wallet for this, which is probably much more secure and convenient than the average Yubikey (you can duplicate it with the seed phrase).
Wouldn't the ability to duplicate it make it weaker?
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#368Earlier quoted context omitted.
The FIDO2 key is usually protected by a PIN that wipes the key after a few wrong attempts, so it combines the two itself. Besides, there's nothing that dictates how secure the key should be. You could use your hardware cryptocurrency wallet for this, which is probably much more secure and convenient than the average Yubikey (you can duplicate it with the seed phrase).
You can duplicate the Yubikey or the hardware cryptocurrency wallet? Wouldn't the ability to duplicate it make it weaker?
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#369Earlier quoted context omitted.
Just think of it as like paying to see a movie. I bought a $10 app once, used it for what it was for, and now several phones later, I don't know or care what's happened to it. I got my value out of it and don't need to hoard every possession I "buy". Remember people who used to have a huge collection of video tapes or CDs? They hardly used them for anything except decoration of their living room. Hoarding old crap th…
> The world's richest man had half his wealth taken like that. If you're talking about Bezos, all of their wealth was made after they got married. The news can say it's "his wealth" but it always belonged to both of them. It's not "taking half his wealth," it's splitting their co-owned assets.
Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
#370Earlier quoted context omitted.
Just think of it as like paying to see a movie. I bought a $10 app once, used it for what it was for, and now several phones later, I don't know or care what's happened to it. I got my value out of it and don't need to hoard every possession I "buy". Remember people who used to have a huge collection of video tapes or CDs? They hardly used them for anything except decoration of their living room. Hoarding old crap th…
So much wrong here lets start with this >The world's richest man had half his wealth taken like that I assume you are talking Bezo's divorce, you might want to actually look into that if you believe that. he did not have half his wealth taken, far far far from it. >Physical things can readily be taken away in divorces and debt recovery That is not being "taken away" in the sense you are talking about in context, for…
Who?