Live data from Hacker News

Facebook Asking for Some New Users' Email Passwords

thedailybeast.com

81–90 of 377 posts

Re: Facebook Asking for Some New Users' Email Passwords

#81

I noticed that when I was dating around it was extremely important that they could find my Facebook profile if I said I don't use Facebook much they would immediately respond with scepticism. For that purpose alone I kept it. And they have a point, it's easy to find out if someone is single or not via Facebook, and you are bound by your friends to be truthful. I'm not single anymore, but I'm still curious, in those c…

> countries where everyone is sleeping around with everyone I want to know where these are

Re: Facebook Asking for Some New Users' Email Passwords

#82
post #67

I just don't understand how this gets implemented without someone speaking up and saying "hey, wait, isn't this an insane thing to do?". I would guess it's some combination of the complainers being ignored, and people at a higher level thinking "well we're doing this in a secure way, as long as the user trusts us, and why wouldn't they trust us, we're Facebook!".

Easy.

The engineers who built it care mostly about their total compensation and getting promoted. They therefore gleefully implement the product requirements.

The PMs behind the idea also care about the above, except they are held to account by business objectives. By narrowly optimizing for a particular objective (reducing account fraud) in an unprincipled manner, they come up with an insane feature idea like this.

The lowly L3 engineer fresh out of college understands how crazy this is and speaks up, but is hammered down by the culture. The decision is quite literally above their pay grade. They begrudgingly fall in line as they have the most to lose in this situation.

Finally a story like this breaks and upper management realizes the contradiction with the narrative that they're trying to create - that Facebook really does care about your privacy. The whole project gets scrapped, and by the time it's all said and done, over $1M is wasted.

Welcome to life at a big tech company.

Re: Facebook Asking for Some New Users' Email Passwords

#83
post #65

All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...

Swedish payment processor Klarna does something similar to this as well. If bying something through the platform by direct bank transfer you are asked to sign to your bank to accept the payment using BankID [0], which is normal. What is not normal is that they grab your personal identification number and send a login request using BankID before you open your app. When authenticating the login you authorize one of Kla…

POLi in Australia also asks for your bank username and password, logs into your bank's online portal, and performs a bank transfer on your behalf; which is of course in violation of the bank's policies.

It's truly insane, if I see any company accepting payment via POLi it's instant verification the company in question is clueless and that I should avoid using their services whenever possible, because they have zero idea about security.

According to POLi[1][2], the list includes:

Qantas, Jetstar, Virgin Australia, Microsoft (?), Sportsbet, Emirates, BetEasy, CoinSpot, Australia Post, TigerAir, Facebook (?)

The list goes on. It's pure madness.

I really wish there was more awareness of this, I can't believe these massive companies can't comprehend how they're being implicated when they encourage users to hand over their banking password to a third party.

[1] https://www.polipayments.com/ [2] https://www.polipayments.com/Buy#matrix

Re: Facebook Asking for Some New Users' Email Passwords

#84
post #67

I just don't understand how this gets implemented without someone speaking up and saying "hey, wait, isn't this an insane thing to do?". I would guess it's some combination of the complainers being ignored, and people at a higher level thinking "well we're doing this in a secure way, as long as the user trusts us, and why wouldn't they trust us, we're Facebook!".

Easy. The engineers who built it care mostly about their total compensation and getting promoted. They therefore gleefully implement the product requirements. The PMs behind the idea also care about the above, except they are held to account by business objectives. By narrowly optimizing for a particular objective (reducing account fraud) in an unprincipled manner, they come up with an insane feature idea like this.…

Your summary hits the nail on the head.

But you forgot the most important thing: What happens once upper management reads an article like this and realizes they f*cked up badly again?

Yes, more of the same hierarchy, compensation, promotions, and "culture".

Welcome to "efficient" big corporate hierarchies.

Re: Facebook Asking for Some New Users' Email Passwords

#85

Earlier quoted context omitted.

I remember Quicken doing it back in the early 2000s.

That is a program though, not a website.

That's the problem now though. We've made it so apps have to be approved by gatekeepers, and are highly discouraged by the gatekeepers from sharing state with other apps on the same device.

Then the recommendation if that's a problem for you is to use the web. But sometimes the web doesn't work, as is the case here, because it requires the user to trust third party code in real time and give sensitive data to third party servers they don't control.

So we have everything pushing the user to put their most sensitive information into some third party service that should be an app, but isn't, because cloud.

Re: Facebook Asking for Some New Users' Email Passwords

#86
post #65

Earlier quoted context omitted.

Swedish payment processor Klarna does something similar to this as well. If bying something through the platform by direct bank transfer you are asked to sign to your bank to accept the payment using BankID [0], which is normal. What is not normal is that they grab your personal identification number and send a login request using BankID before you open your app. When authenticating the login you authorize one of Kla…

POLi in Australia also asks for your bank username and password, logs into your bank's online portal, and performs a bank transfer on your behalf; which is of course in violation of the bank's policies. It's truly insane, if I see any company accepting payment via POLi it's instant verification the company in question is clueless and that I should avoid using their services whenever possible, because they have zero i…

The problem with Klarna in Sweden is that virtually every single online shop use them now.

Re: Facebook Asking for Some New Users' Email Passwords

#87

Earlier quoted context omitted.

Plaid might be my least favorite company ever. It's such a privacy nightmare and they do not even tell you basic information about what you are sharing (or how to revoke sharing rights) going through their typical flow on some random fintech app. If you look at their website, you could be giving away just the bank and routing number, or potentially your entire bank transaction history, balance, identity information,…

I alluded to this in my other comment, but I don't blame Plaid. Blame the banks - Plaid isn't doing this behind their banks, but with their blessings. Again, Mint was doing this for years. When it comes to Credit Card Fraud, the banks are buying all sorts of AI based solutions - after all it's their money. When it comes to customer cash, then its the wild west. I recently found out that my Wells Fargo password isn't…

Not case sensitive, huh? How about not even distinguishing between letters and numbers?

When I called a prominent bank* recently, I was asked to enter my password via the phone. As in, the digit-equivalent of my password. At least I finally figured out why their password length is capped so low - user experience!

*I began this post with the bank name, and then wondered if given their approach to security, even that might be a bad idea.

Re: Facebook Asking for Some New Users' Email Passwords

#89
post #67

I just don't understand how this gets implemented without someone speaking up and saying "hey, wait, isn't this an insane thing to do?". I would guess it's some combination of the complainers being ignored, and people at a higher level thinking "well we're doing this in a secure way, as long as the user trusts us, and why wouldn't they trust us, we're Facebook!".

Why is this insane? It's just asking. If you don't want to, don't give your pw to facebook.

You make a proposition to an entity, they evaluate the risk-benefit and respond.

Unless of course, you think adults are actually childiren and should be protected from themselves by the technocrats.

Re: Facebook Asking for Some New Users' Email Passwords

#90

I noticed that when I was dating around it was extremely important that they could find my Facebook profile if I said I don't use Facebook much they would immediately respond with scepticism. For that purpose alone I kept it. And they have a point, it's easy to find out if someone is single or not via Facebook, and you are bound by your friends to be truthful. I'm not single anymore, but I'm still curious, in those c…

So I kept it, why would you? go against the stream.
Post reply on HN