Live data from Hacker News

Facebook spamming users via their 2FA phone numbers

mashable.com

51–60 of 380 posts

Re: Facebook spamming users via their 2FA phone numbers

#51

Seriously, why do the rank-and-file of Facebook engineering allow this to happen? Does anyone stand up to their employers anymore? Or does everyone just drink the koolaid and ask no questions?

These things are never spelled out in any plans. They're done piecemeal, by separate teams, incrementally over long development cycles.

One team implements 2FA, and they add a way for users to enter their phone numbers as a second factor. The engineers are fine with this because it's for the users' benefit, so they can secure their account.

Another team implements the mobile notifications, which a user has to turn on explicitly. The engineers there do this for the users' benefit, for those users that want notifications by phone. They're opting in, after all.

Sometime in here, the fact that the phone numbers are being collected for 2FA gets forgotten. This sets the stage for a third team, who is tasked with improving engagement numbers. They see that lots of inactive users have phone numbers associated with their accounts. Maybe they might be interested in something their friends are doing? So they try an experiment where they send a notification to these users, and a large percentage of them engage with it! That must mean that the users were interested in the notification right? After all, they opened the link or replied. So they roll it out to a wider audience, and the engagement numbers go up. Awesome! Pats on the back all around.

To be clear, I have no idea about how this actually happened, or if this is the right chronology, or anything else. It really doesn't matter, my point is that this is how this sort of thing happens in large organizations. No one has the whole picture, and in their own world view everyone thinks they're doing something good for their users.

But if you put them all together, and sprinkle in a little willful ignorance, you get Facebook spamming their users on their 2FA numbers.

Re: Facebook spamming users via their 2FA phone numbers

#52

Finally, somewhere I can appropriately vent about this. About TWO years ago I was constantly annoyed by the 'secure your account: add your phone number here' banner frequently displayed at the top of the page upon loading FB, so I input my number to make it disappear for good. (Also, they kept hiding the 'x' (close) icon in different spots, making the banner difficult to dismiss.) A few days later I got a text messag…

> but I've had my account since 2006 and despite the company's terrible practices, I'm really not interested in disconnecting for good at this time

This behavior does not encourage FB to self-correct.

Re: Facebook spamming users via their 2FA phone numbers

#53
post #7

This happened to me too. The value of being on facebook is an illusion. In person relationships are vastly more rewarding, both emotionally and financially.

No, it's not an illusion and it has nothing to do with facebook only relationships (I don't even know what that is). All the people I contact on facebook I have in person relationships with. For well over the past 3 years its primary function has been as an organizational tool for my close group of friends. Few of us update our status or regularly post on there anymore. They live in different cities, states, or countries now. Groups and events make a fantastic way to plan a vacation with friends and has all the interactive features you'd want for that sort of a thing (messages, RSVP, polls, etc) that e-mail simply can't give you, and the fact that facebook is completely ubiquitous among my friends make it really the only choice for the job (although I do suspect this is due to our age range- we are all mostly in our early 30's - I think if we were older or younger this would not be as true).

Until someone makes an organizing tool that can break the network effect facebook has with my friend group, I'll have a facebook account.

Re: Facebook spamming users via their 2FA phone numbers

#54
post #22

Earlier quoted context omitted.

> I realize that the proper solution is to terminate my account and never attempt to log back in.... but I've had my account since 2006 and despite the company's terrible practices, I'm really not interested in disconnecting for good at this time Well, that's the real problem, isn't it? If users aren't punishing Facebook by leaving the platform in droves, then what incentive does Facebook have to stop its consistentl…

They definitely are. And for users like me they certainly aren't getting their money's worth... I use FB purity, ublock origin, and have spent the better part of the last year using the 'on this day' feature to scrub historical information from the platform. As a tool Facebook still has valid use cases for me. The benefits of keeping it edge out any negatives. So for now I will stay. Unless any egregious election med…

> to scrub historical information from the platform.

You know they never actually delete user data, right? They don't delete your data if you actually delete your account, much less if you just delete a post. They just stop displaying it then.

Re: Facebook spamming users via their 2FA phone numbers

#55
post #45

Earlier quoted context omitted.

> I realize that the proper solution is to terminate my account and never attempt to log back in I've had a "terminated" account that occasionally gets emails inviting me to "Log back in with one click". When I originally tried to delete the account, it told me it would be actually erased a month after. That was 6 years ago.

To have your account erased as opposed to "deactivated" (which doesn't really do anything) the surefire method is to spam gore images on popular groups.

I'm pretty sure even then they don't actually delete your data. They just make it impossibly for you to reactivate your account.

Re: Facebook spamming users via their 2FA phone numbers

#56
Just get multiple phone numbers. It's easy these days and totally worth it. They're only $1 / month and being able to keep your real number separate from all these BS sites is great. Plus, for 2FA social engineers aren't going to get you just by working your network.

Re: Facebook spamming users via their 2FA phone numbers

#57

I found a similar thing with email notifications. If you regularly login to FB and look at your feed they will leave you alone. Delete the app from your phone or neglect logging in and you’ll start to get email notifications about the silliest things. Of course they don’t contain much more than “so and so shared a link” without any description of what was shared (trying to get you to login and look.) Not quite as bad…

Back when I had the Facebook app installed on my phone, if I didn't open it for a long period the "so-and-so posted an update" push notifications would eventually slow to a trickle and ultimately peter out altogether. But if I so much as touched Facebook, the floodgates would re-open and I'd be spammed with them throughout the day, until the process repeated and they died away again.

In a weird way Facebook ended up conditioning me to avoid using it.

Re: Facebook spamming users via their 2FA phone numbers

#58
post #22

Finally, somewhere I can appropriately vent about this. About TWO years ago I was constantly annoyed by the 'secure your account: add your phone number here' banner frequently displayed at the top of the page upon loading FB, so I input my number to make it disappear for good. (Also, they kept hiding the 'x' (close) icon in different spots, making the banner difficult to dismiss.) A few days later I got a text messag…

> I realize that the proper solution is to terminate my account and never attempt to log back in.... but I've had my account since 2006 and despite the company's terrible practices, I'm really not interested in disconnecting for good at this time Well, that's the real problem, isn't it? If users aren't punishing Facebook by leaving the platform in droves, then what incentive does Facebook have to stop its consistentl…

I left Facebook. But mainly because I realised that it's a real poor way to keep in touch with anyone. Gives you the feeling that you are keeping in touch when in reality you are just sharing photos and quotes in a medium that's very noisy with adverts.

Re: Facebook spamming users via their 2FA phone numbers

#60
Things like this are the reason that when a company starts spamming me, I update my account with the company's own information.

I started when no matter how many times I tried to unsubscribe, Walgreens kept using my phone number (which is supposed to be used to verify that the right person is getting the prescription) to spam me flu shot notices, auto-refill offers, and more. So now those robocalls go to Walgreens HQ.

Most companies list an email address and phone number for their PR departments on their web sites, so these are what I use since they're not hidden and go to real people.

I know this doesn't work for 2FA, but it's certainly satisfying in other scenarios.

Post reply on HN