Live data from Hacker News

Facebook spamming users via their 2FA phone numbers

mashable.com

61–70 of 380 posts

Re: Facebook spamming users via their 2FA phone numbers

#61

I really hope this is a sign of the end times for Facebook. I genuinely believe that the world will be better off without it, and its effect on culture, mental health, work habits, and socialisation. _Especially_ for young people.

We might be seeing the (slow) decline of Facebook, but in no way will we see the decline of social media that causes those bad effects.

Re: Facebook spamming users via their 2FA phone numbers

#62

Facebook has been asking me to add my mobile number to secure my account. It even prepopulated the input field with my mobile number that I never shared with them! My best guess is that their app farmed it out of the phone adress book of one of my friends. Either way, they definitely overstepped the mark here, in my opinion.

Do you use Whatsapp? Unless you opted out during the short window they offered during the summer, Facebook got all your Whatsapp contacts and data, and that of course includes your phone number: https://www.cnet.com/how-to/how-to-stop-whatsapp-from-sharin...

I do not but a number of my friends are using the Facebook Messenger, Facebook App and Whatsapp.

Re: Facebook spamming users via their 2FA phone numbers

#63
Reposting my comment from the other thread:

I’ve always been suspicious of services that use SMS as the primary 2FA mechanism. TOTP is more secure and convenient, but it doesn’t allow the service to collect and extra datapoint. Using a communication channel intended for security as a method to boost falling engagement is as shady as it gets.

Matthew Green’s twitter thread[0] on this is an interesting read.

0: https://twitter.com/matthew_d_green/status/96376666146678784...

Re: Facebook spamming users via their 2FA phone numbers

#64
post #34

FB (among other web sites) continually asks for my phone number. I continually ignore their entreaties. I always suspected they could not resist the temptation to use it like this. I really expected them to sell it to telemarketers.

> I really expected them to sell it to telemarketers. reply

I doubt they'd sell it to telemarketers, but they'll use it for every dark pattern under the sun to increase your engagement. Frankly, your engagement is much more profitable to them than a one-time sale of an email list.

Re: Facebook spamming users via their 2FA phone numbers

#65
post #15

It's pretty clear from some simple googling that he ended up somehow activating a feature called "Facebook Texts" (the key giveaway -- that replying to the texts posted to his wall): https://www.facebook.com/help/130694300342171?helpref=faq_co... I believe that he didn't set this up intentionally and it may very well be a bug that caused him to be signed up, but as bad as Facebook is I'll eat my shoe if they signed u…

[deleted]

Re: Facebook spamming users via their 2FA phone numbers

#66
post #12

If they're not processing STOP as an opt-out, they're in major violation of the CTIA's rules on short codes.

If you send a STOP, though, won't that cause you to stop getting 2FA codes as well?

I'm not sure if the rules carve out an exemption for that.

If they don't, polluting the 2FA short code with other types of messages is doubly bad.

Re: Facebook spamming users via their 2FA phone numbers

#67
post #21

Earlier quoted context omitted.

Well as far as legal protections go, nothing definitive, and they can always argue their statements about enhancing user experience would cover this. Check westlaw on it https://content.next.westlaw.com/6-502-0467?transitionType=D... I think the real issue, is people think they are doing one thing, but doing another. depending on the age of your account, you'll notice that the notifications for SMS maybe defaulted on…

> It's another case of people screaming to the heavens about evil megacorp. when in reality they can't be bothered to check their own settings. Facebook's settings are often opaque and unintuitive, and some of the stuff around notifications qualifies as dark patterns. Also, as you mentioned, Facebook has a history of using selfishly-chosen defaults which are often not what a user would likely want or expect. I'm not…

I won't defend their practices in most cases, changing the news feed to recent for example is far more work than it should be, and reverts randomly.

but this setting is Settings>Notifications it's not really buried.

I suppose I'm not upset at people who discovered the issue, but I am annoyed at mashable.com for making it a specifical when it shouldn't be, quoting a "a self-described technosociologist, professor at UNC" and their uninformed statements.

Re: Facebook spamming users via their 2FA phone numbers

#69
post #55
post #45

Earlier quoted context omitted.

To have your account erased as opposed to "deactivated" (which doesn't really do anything) the surefire method is to spam gore images on popular groups.

I'm pretty sure even then they don't actually delete your data. They just make it impossibly for you to reactivate your account.

Interestingly I've read an anecdote that in the EU you can write them and say "Either delete my account or return my access to it.", and because they don't/can't delete accounts...

Re: Facebook spamming users via their 2FA phone numbers

#70
post #15

It's pretty clear from some simple googling that he ended up somehow activating a feature called "Facebook Texts" (the key giveaway -- that replying to the texts posted to his wall): https://www.facebook.com/help/130694300342171?helpref=faq_co... I believe that he didn't set this up intentionally and it may very well be a bug that caused him to be signed up, but as bad as Facebook is I'll eat my shoe if they signed u…

> I'll eat my shoe if they signed up every single person who gave a 2FA phone number to this service.

Facebook doesn't have to sign up every 2FA person. It can pick a few hundred or thousand and see what happens. If engagement increases, then more 2FA people are brought on board.

If this isn't widespread, it may not be the user's fault. It may just be the camel's nose under the tent.

Post reply on HN