Live data from Hacker News

Someone keeps trying to reset my Facebook password

reddit.com

81–90 of 246 posts

Re: Someone keeps trying to reset my Facebook password

#81
My sister had her Facebook account taken over by a bot of some sort some years ago. It was odd – they changed her profile photo over time, so at first it was just the regular profile photo, then it was the regular profile photo with a little bit of a different profile photo sort of creeping in on top of it, like if they had pasted the new one into a photoshop layer. Over a few weeks the new profile photo crept up until it was the only one, and then it became a sort of "call me for hot fun" spam account.

I assume they were sidestepping some sort of detection algorithm, but it happened during a time when she was losing her mind in real life so it was a strange kind of metaphor.

Re: Someone keeps trying to reset my Facebook password

#82

I’ve accumulated, what, 3 Facebook accounts over the years? Many mornings I wake up to see that recovery codes have been requested for all of them, at a similar time. Surely this is enough of a signal to act on!? It really speaks to the fact that Meta really just doesn’t give a rats.

I mean a single attempt is always possible, even a number of attempts. But consistent attempts affecting what is probably millions of users over the span of years is a Facebook problem, clearly any measures they have to avoid repeated login attempts aren't working.

Re: Someone keeps trying to reset my Facebook password

#83

Earlier quoted context omitted.

The email allows you to enter a new password, it doesn't validate some other access to your account by clicking yes.

They will just wait for you to get used to this, then stop triggering Facebook to send you legitimate emails and start sending you similarly-looking phishing emails similarly often. It may happen to be enough to view a phishing email, let alone click anything in it to get pwned.

What if they send you dozens of these, then one that actually looks legitimate, saying something like "We have detected 24 login attempts to your account in the past 30 days coming from this location, click here to see additional details and / or improve your account security", containing a phisher's login form.

Re: Someone keeps trying to reset my Facebook password

#84

Earlier quoted context omitted.

? the comment you're replying to is talking about resetting by *account name*, not email address.

Ah, sorry, I see now, but the underlying point is the same. You should not reveal any information. A "We have sent an email to the address associated with the account" would be sufficient.

It is not sufficient.

The amount of disclosed information, and it's utility, is non-zero, but simply weighs less than the amount of damage from not hinting which account to check.

Accounts can grow to be 20 years old and even a "normal" person who is not actively using lots of addresses for security, will still end up having used several in the fullness of time and completely forgotten about some, yet, may still have or can regain access to them if only they knew to go look.

You don't see how that can happen or really be a problem? Oh well, consider yourself informed that it does happen and is a problem.

Re: Someone keeps trying to reset my Facebook password

#85
post #79

Earlier quoted context omitted.

Okay. Why not add a configuration option for this then so people who know what they are doing would be able to opt in for the more secure way?

I used to think info about whether an account exists should not be leaked in the password reset flow, and I designed sites this way, but then someone pointed out that in practice a hacker would then just move to the account sign up flow to check for the existence of an account. (If account exists, you cannot make another with that email on most sites.) I never had a good response for that. I now lean toward the idea…

> If account exists, you cannot make another with that email on most sites.

Many sites require you to verify your email before you can use your account. If you wanted to avoid leaking whether an account existed, you could show them a message like "if this account doesn't already exist, a message has been sent to your email asking you to verify it". If the account did exist, you might send an email like "someone tried to create an account with your email".

Re: Someone keeps trying to reset my Facebook password

#86
fairly simply fixed by making publicly available information (email address) not part of the process:

- create an email address alias (random, unguessable)

- change your login to use that email address

- remove your phone number from Facebook

There are many ways to do this (plus addressing, apple hide my email, account aliases, etc.) Pick your own approach.

Re: Someone keeps trying to reset my Facebook password

#87
post #49

Earlier quoted context omitted.

The GP is talking about a situation where you are not asked for an email address. You ask for a password reset for the username @coolanonguy. The website tells you that the reset email was sent to an obscured email address. The obscured email allows you to confirm (with high likelihood) or deny (with certainty) that @coolanonguy is your friend whose email address you know.

on the systems where i had to do this for my account i usually get a message like: "an email has been sent to the address registered with this account" there is no benefit to reveal any details.

The benefit is that people often don't remember which email they used for a service. They check their "main" email inbox but don't remember that they used their student email address 8 years ago when they signed up. By providing a hint they know which inbox to check and don't get frustrated because the email isn't coming.

So it is a privacy tradeoff for better UX. If it is a good tradeoff will depend on how much you value each.

Re: Someone keeps trying to reset my Facebook password

#88
post #64

This is very common with short or otherwise valuable usernames on social media platforms. Initials and so on. That's what 2FA is there for, but you still get the annoying e-mail notifications for attempted sign-ins. Make sure to weigh the pros and cons when you pick your username on the internet. A dedicated e-mail filter to limit the mental attrition might not be the worst idea.

I was early enough to get my first name on Twitter and didn't, but did get it on Instagram.

The @tommy on Twitter was a dev at Gameloft who gets constantly harassed in his mentions to give it up. I had a similar problem on Instagram. I've mostly stopped using it, but when I did post and had an open profile I constantly got comments offering money for my username.

Eventually someone set up a follower bot on my account and I was getting hundreds of new followers a day. I made my profile private and don't post anymore, but it's still hundreds of new follower requests per day.

Re: Someone keeps trying to reset my Facebook password

#89
post #76

Earlier quoted context omitted.

This is how I'm going to describe that attack where you get a zillion authenticator push notifications because Microsoft has designed the damn thing to authenticate you to them but not them to you. Like, how freaking difficult would it be to put a transaction code in there like Apple so that you can match the notification on your phone with the session you're starting on some other device or service?!

I just wish Microsoft would let me use any other authenticator app instead of their garbage one. So now I've got one from Google with 99% of my accounts on it, one for Microsoft for one of 4 MS accounts, and one for the USG for IRS/etc. Waste of space and poorly-duplicated functionality.

Microsoft does let you use other authenticators. My non-MS authenticator app has 3 MS accounts on it.

Re: Someone keeps trying to reset my Facebook password

#90

Funny I keep getting login codes for my Microsoft account. Also there is seemingly no way to figure out who is doing it or how to stop it. I wish I could just disable that form of login, I have a very safe password so the login via email isn't necessary.

It's like the google 2FA where you can accept the login on ANY android device where you are logged in. and you can't disable the feature and the only way to remove the option from a device is to logout your account on the device... I have an tabled and an phone which is used by other people in my family and I definitely don't want the 2FA requests on these devices...
Post reply on HN