Live data from Hacker News

Someone keeps trying to reset my Facebook password

reddit.com

41–50 of 246 posts

Re: Someone keeps trying to reset my Facebook password

#41

Maybe unrelated, but I think some people do this to check (at least partially) what email is tied to an account. E.g. if you suspect an anonymous instagram user to be your friend Bob, you can invoke the reset email procedure to see We sent an email to bo****@gm***.com Which gives you a hint

Best practice would be to display this message no matter whether the email address is correct or not, to avoid leaking information. Many sites do this.

? the comment you're replying to is talking about resetting by *account name*, not email address.

Re: Someone keeps trying to reset my Facebook password

#42
I have an alias that is a vaguely common name, which is firstname.lastname@gmail.com

Once a year or so somebody tries to get into that gmail or associated social media account with a bunch of password-reset emails. I'm pretty sure it's someone with a similar name who is slightly misspelling their email, messing up the dot (gmail ignores dots but other systems don't), etc.

Re: Someone keeps trying to reset my Facebook password

#43

Maybe unrelated, but I think some people do this to check (at least partially) what email is tied to an account. E.g. if you suspect an anonymous instagram user to be your friend Bob, you can invoke the reset email procedure to see We sent an email to bo****@gm***.com Which gives you a hint

Best practice would be to display this message no matter whether the email address is correct or not, to avoid leaking information. Many sites do this.

The GP is talking about a situation where you are not asked for an email address. You ask for a password reset for the username @coolanonguy. The website tells you that the reset email was sent to an obscured email address. The obscured email allows you to confirm (with high likelihood) or deny (with certainty) that @coolanonguy is your friend whose email address you know.

Re: Someone keeps trying to reset my Facebook password

#44

I think the better question is why facebook sends mails from facebookmail.com and metamail.com? Any sensible person would expect those to be scams, but they are real. https://www.facebook.com/help/1634546593478660

Why does any company needs more than one 2nd level domain? Microsoft, I'm looking at you ( https://learn.microsoft.com/en-us/microsoft-365/enterprise/u... ). It nerve-wrecking trying to figure out if some login box or link is legit. They claim to be transitioning to cloud.microsoft, but if you go there, you are redirected to yet another new domain (microsoft365.com) which looks like a scam site, which doesn't render…

> Why does any company needs more than one 2nd level domain?

Re: the first part of your comment, the most common reason I've seen is companies using 2nd domains to send emails that are at higher risk of bouncing or being marked spam (newsletters, cold outreach, etc). And using your primary domain to send "more important" emails from.

Re: Someone keeps trying to reset my Facebook password

#45

It’s a satiation attack (my term). The hope is you’ll get so frustrated at the frequency of the emails that you’ll eventually just press yes or ok or whatever it is that allows the reset.

The email allows you to enter a new password, it doesn't validate some other access to your account by clicking yes.

Re: Someone keeps trying to reset my Facebook password

#46

I think the better question is why facebook sends mails from facebookmail.com and metamail.com? Any sensible person would expect those to be scams, but they are real. https://www.facebook.com/help/1634546593478660

Common tactic to make sure that delivery of notifications is isolated in reputation from the main domains. That way, if notifications are be reported as spam and thus land in a number of distributed blacklists, at least corporate communication still works.

Why don't they use a more obscure domain for internal corporate communication and keep the widely recognized one for messages to end users? Is it just the vanity that people who work there like to be mark.zuckerberg@facebook.com?

Re: Someone keeps trying to reset my Facebook password

#47

Earlier quoted context omitted.

Best practice would be to display this message no matter whether the email address is correct or not, to avoid leaking information. Many sites do this.

? the comment you're replying to is talking about resetting by *account name*, not email address.

Ah, sorry, I see now, but the underlying point is the same. You should not reveal any information. A "We have sent an email to the address associated with the account" would be sufficient.

Re: Someone keeps trying to reset my Facebook password

#48
post #5

I just assumed someone was going through a database of known FB accounts and triggering the reset looking for people who accept. It is strange that they appear to be able to avoid being blocked for bulk/frequent requests though. Seems like a big flaw.

My assumption is that it is engagement juicing. These seem to go out to seldom/casual users a lot of the time, and people respond by logging in and checking things out. Easy way to pump the MAUs

I got these reset emails, for email addresses on an account that I use multiple times per day. Same for friends of mine.

Re: Someone keeps trying to reset my Facebook password

#49

Earlier quoted context omitted.

Best practice would be to display this message no matter whether the email address is correct or not, to avoid leaking information. Many sites do this.

The GP is talking about a situation where you are not asked for an email address. You ask for a password reset for the username @coolanonguy. The website tells you that the reset email was sent to an obscured email address. The obscured email allows you to confirm (with high likelihood) or deny (with certainty) that @coolanonguy is your friend whose email address you know.

on the systems where i had to do this for my account i usually get a message like: "an email has been sent to the address registered with this account"

there is no benefit to reveal any details.

Re: Someone keeps trying to reset my Facebook password

#50

Because of the username. Many people forget their own username, for example: my username is pineapple and someone else's is pineapple2. And they end up using their username to recover their password. If your username is a common namesake, word or homonym, this makes the situation worse.

I have a friend with a firstname.lastname@gmail.com account. Someone out there apparently doesn’t realize that address doesn’t belong to them, because for 10 years he has been getting signup confirmations, appointment reminders, and very personal correspondence meant for the confused individual.

Over the years I have and continue to receive emails destined for other people. After years of trying to help people realize the errors of their ways (sometimes you just can't find the destined people).

Some of my favourites are the tax information (and other common business related correspondence) on their Disney songwriting royalties (I make more before my first coffee break than they do all year on streaming revenue, but they've got a fair number of songs), there is also a bank account tied it in Peru (CFO doesn't care but I'm not locking her out - I do have some compassion.. not much but it's there), but OTOH I've permanently locked people out of their brand new iPhones because they all choose to use my email address, or the person on the other end types it in wrong for them. I also think people don't read what their browser saves and later populates for them.

People will also just randomly give out fake addresses (that are real) when signing up to just to get a discount.

It's a single word that was popularized through pop culture years after I created it, and one letter away from being a traditional western name (and also one character toggled from a popular Hispanic one).

Also a very wealthy PTA mom in Mountain View uses my email address all the time. Our children are doing very well.

Sites should always confirm an address by having you authenticate a link before permanently using it in perpetuity. It would stop a lot of bad actions.

Post reply on HN