Live data from Hacker News

Someone keeps trying to reset my Facebook password

reddit.com

71–80 of 246 posts

Re: Someone keeps trying to reset my Facebook password

#72
post #3

At this point, I would not be at all surprised if this is a guerrilla tactic for accounts that have not logged in in a while to create engagement/MAU.

I would believe it. I recently logged out of facebook on each device and took a month long timeout. After a couple of weeks, I started getting facebook email notifications of things they figured I'd want to see. With the impossible to remove/hide facebook reels nonsense they force on users, I'm about to take a much longer facebook timeout.

Re: Someone keeps trying to reset my Facebook password

#73

Earlier quoted context omitted.

The GP is talking about a situation where you are not asked for an email address. You ask for a password reset for the username @coolanonguy. The website tells you that the reset email was sent to an obscured email address. The obscured email allows you to confirm (with high likelihood) or deny (with certainty) that @coolanonguy is your friend whose email address you know.

Isn't a step in password reset a prompt asking you to enter the email address the account is tied to?

Sometimes, not always.

Re: Someone keeps trying to reset my Facebook password

#74
I'm close with someone whose FB account was compromised due to a shared password, and then didn't see the 'an email has been added/removed from your account' emails until after the revert link expired a few weeks later.

The recovery process is totally broken for them now. We eventually managed to revert back to the original email address by visiting facebook.com/hacked (not without the help of a weird youtube video to make sure we were selecting the right options, though), and we lost a ton of time on a weird issue where emails or recovery options were deeplinking to the app, which was opening but didn't know what to show us. After deleting the app, we managed to start generating 2-factor email codes, but the same prompts that generate them don't accept them. And the 'send in an ID to verify your identity' feature just doesn't load at all. I'm chipping away at it when I see them, but I give recovery a low probability of success.

Understandable that this is probably not very fair to those who can't afford it, but I wish there was a 'pay $100 to speak with a rep who can fix this now' feature.

Re: Someone keeps trying to reset my Facebook password

#75

Earlier quoted context omitted.

? the comment you're replying to is talking about resetting by *account name*, not email address.

Ah, sorry, I see now, but the underlying point is the same. You should not reveal any information. A "We have sent an email to the address associated with the account" would be sufficient.

Not if you have multiple email accounts. Many times these codes reset in just a few minutes, you should try to avoid forcing users to spend time logging into every single email they can remember just to wait for an email to pop into one of them. You can show a few characters of an email or the first character of the domain to give a lot of info out in relative safety.

Everything is about tradeoffs, and the only objectively wrong answer is this dogmatic "never do $X" nonsense.

Re: Someone keeps trying to reset my Facebook password

#76

It’s a satiation attack (my term). The hope is you’ll get so frustrated at the frequency of the emails that you’ll eventually just press yes or ok or whatever it is that allows the reset.

This is how I'm going to describe that attack where you get a zillion authenticator push notifications because Microsoft has designed the damn thing to authenticate you to them but not them to you. Like, how freaking difficult would it be to put a transaction code in there like Apple so that you can match the notification on your phone with the session you're starting on some other device or service?!

I just wish Microsoft would let me use any other authenticator app instead of their garbage one. So now I've got one from Google with 99% of my accounts on it, one for Microsoft for one of 4 MS accounts, and one for the USG for IRS/etc. Waste of space and poorly-duplicated functionality.

Re: Someone keeps trying to reset my Facebook password

#77

Earlier quoted context omitted.

They will just wait for you to get used to this, then stop triggering Facebook to send you legitimate emails and start sending you similarly-looking phishing emails similarly often. It may happen to be enough to view a phishing email, let alone click anything in it to get pwned.

surely the more of these they send, the less likely you are to click on them

Maybe they would at some point send an email offering to turn off these annoying notifications with a malicious URL?

Re: Someone keeps trying to reset my Facebook password

#78
post #67
post #64

This is very common with short or otherwise valuable usernames on social media platforms. Initials and so on. That's what 2FA is there for, but you still get the annoying e-mail notifications for attempted sign-ins. Make sure to weigh the pros and cons when you pick your username on the internet. A dedicated e-mail filter to limit the mental attrition might not be the worst idea.

Several years ago I was getting multiple password reset attempts per day from my bank because I picked an easy username to remember 20 years ago. Luckily my bank allowed me to change my user name so I used my password manager to generate a password and used that as my username.

One trick I've applied with a wordpress environment is to change the default 'admin' password to something longer / more complicated, change the default location of the admin panel to something else (only works if the admin environment is set up for that), and change the default SSH port. This already defeats 99% of 'low hanging fruit' attempted login attempts.

Re: Someone keeps trying to reset my Facebook password

#79
post #52

Earlier quoted context omitted.

That is the security researcher perspective, but it’s a UX nightmare resulting in a lot of confusion for normal users, because they don’t get any info if they even have an account or are trying to use the correct email address.

Okay. Why not add a configuration option for this then so people who know what they are doing would be able to opt in for the more secure way?

I used to think info about whether an account exists should not be leaked in the password reset flow, and I designed sites this way, but then someone pointed out that in practice a hacker would then just move to the account sign up flow to check for the existence of an account. (If account exists, you cannot make another with that email on most sites.) I never had a good response for that. I now lean toward the idea that not providing info is just not worth the bad UX.

Re: Someone keeps trying to reset my Facebook password

#80

Maybe unrelated, but I think some people do this to check (at least partially) what email is tied to an account. E.g. if you suspect an anonymous instagram user to be your friend Bob, you can invoke the reset email procedure to see We sent an email to bo****@gm***.com Which gives you a hint

A variant I've seen was "We've sent you a recovery code to your email at gmail.com". I think it's useful for login name based authentication, since people will have multiple email addresses and may forget which one they used for that account.

(we have a 15 year old who's made at least four, probably more different gmail addresses for different purposes. Ironically, the one he used to sign up for porn includes his real first/lastname)

Post reply on HN