Huh. Well, I guess this does shift the individual from product to customer, although it seems like quite a drastic measure to take. The real moral I guess is, set up 2FA and maybe that trusted recovery person feature, whatever they call it.
The real moral is to not build your company without any modicum of user support.
The users who have any clue what 2FA is are not the ones getting their account hacked. They are the 60+ year olds who use Facebook as their only contact with friend and family, unfortunately.
I think we can appreciate how this is a difficult problem though. Google support would get a torrent of actual hackers contacting them to gain access to someones account. Not restoring access to a few real cases is probably better than giving access over to a hacker. GitLab recently said that customer support will not help restore access to your account if you lock yourself out unless you have an active subscription…
Disagree. A company as big as google should have the decency to at least have a human reach out to paying developers before they permanently ban apps which developers use to make a living: https://news.ycombinator.com/item?id=26956077
I wonder why Google doesn’t just offer a premium support tier.
FB had an internal help system called "Oops". It was meant for employees to get help for friends they knew in real life. It was discontinued not long ago (EDIT: maybe not according to a child comment). There were just too many requests for help. Facebook has a corporate structure that simply will not prioritize any effort longer than 6 months unless a senior company executive (Mark, Sheryl) supports it. Even if it af…
> Facebook has a corporate structure that simply will not prioritize any effort longer than 6 months unless a senior company executive
To be fair, many companies have some degree of this. They don't want to commit significant resources to something the people in charge don't understand.
No info on how this Facebook account takeover is happening? I wish they would provide details...
They didn’t have 2FA, so it’s probably as basic as a password reuse attack.
The really shocking thing is the lack of any delay with email changes. I've known several people whose accounts were hacked and properly flagged by Facebook within hours but the hacker was able to change the email address immediately with no waiting period and remove the other addresses so access was impossible.
I tried this on my own account shortly after and, sure enough, there's no waiting period where previous emails remain allowed to reset passwords.
Nobody is buying an Oculus headset right now because they've been recalled and won't be available until August 24th. https://www.oculus.com/quest-2/removable-facial-interface-al...
This recall is only for the foam face insert. It's removable and probably very inexpensive to make / replace. Oculus is sending free replacements to folks. I am an avid Quest 2 user since ~October. I play Population:one and _love_ it. It's a team-based Battle Royale. I am just blown away by how much fun and social it is. It's been a godsend during the pandemic. The Quest 2 is only $300 - I strongly recommend it!
If anyone else is on the fence about the Quest 2, I received on as a gift, and it has totally blown me away. I was previously somewhat skeptical of VR, but it's so fun. FWIW, it also feels a bit _different_ than normal video games, because you're on your feet, moving your body, etc.
Disagree. A company as big as google should have the decency to at least have a human reach out to paying developers before they permanently ban apps which developers use to make a living: https://news.ycombinator.com/item?id=26956077
I wonder why Google doesn’t just offer a premium support tier.
> "The only way you can get any customer service is if you prove that you've actually purchased something from them," he said.
Seriously, this sounds super-entitled to me.
Why is this unfair?
Also, the advertising supported-model has so many negative consequences. Pragmatically, FB isn't just going to fade away, so wouldn't it be better if they evolved towards a paid model? (Or at least the option to pay.)
I'm sure detractors would find plenty to criticise about a system to prioritise friends and family, but it's smart from a QA perspective. They get a corpus of issues that are falling through the cracks, coming from real people without an agenda.
While that’s useful, I suspect the real reason it exists is to discourage fix-it-yourself options, where an engineer may access sensitive user info to help a friend.
Or just keep employees on track. Imagine a company the size of FB having a barrage of Slack messages over family and friends with suspended accounts, trying to find who manages which DB.
They didn’t have 2FA, so it’s probably as basic as a password reuse attack.
The really shocking thing is the lack of any delay with email changes. I've known several people whose accounts were hacked and properly flagged by Facebook within hours but the hacker was able to change the email address immediately with no waiting period and remove the other addresses so access was impossible. I tried this on my own account shortly after and, sure enough, there's no waiting period where previous em…