I assume they were sidestepping some sort of detection algorithm, but it happened during a time when she was losing her mind in real life so it was a strange kind of metaphor.
Someone keeps trying to reset my Facebook password
81–90 of 246 posts
Re: Someone keeps trying to reset my Facebook password
#82I’ve accumulated, what, 3 Facebook accounts over the years? Many mornings I wake up to see that recovery codes have been requested for all of them, at a similar time. Surely this is enough of a signal to act on!? It really speaks to the fact that Meta really just doesn’t give a rats.
Re: Someone keeps trying to reset my Facebook password
#83Earlier quoted context omitted.
The email allows you to enter a new password, it doesn't validate some other access to your account by clicking yes.
They will just wait for you to get used to this, then stop triggering Facebook to send you legitimate emails and start sending you similarly-looking phishing emails similarly often. It may happen to be enough to view a phishing email, let alone click anything in it to get pwned.
Re: Someone keeps trying to reset my Facebook password
#84Earlier quoted context omitted.
? the comment you're replying to is talking about resetting by *account name*, not email address.
Ah, sorry, I see now, but the underlying point is the same. You should not reveal any information. A "We have sent an email to the address associated with the account" would be sufficient.
The amount of disclosed information, and it's utility, is non-zero, but simply weighs less than the amount of damage from not hinting which account to check.
Accounts can grow to be 20 years old and even a "normal" person who is not actively using lots of addresses for security, will still end up having used several in the fullness of time and completely forgotten about some, yet, may still have or can regain access to them if only they knew to go look.
You don't see how that can happen or really be a problem? Oh well, consider yourself informed that it does happen and is a problem.
Re: Someone keeps trying to reset my Facebook password
#85Earlier quoted context omitted.
Okay. Why not add a configuration option for this then so people who know what they are doing would be able to opt in for the more secure way?
I used to think info about whether an account exists should not be leaked in the password reset flow, and I designed sites this way, but then someone pointed out that in practice a hacker would then just move to the account sign up flow to check for the existence of an account. (If account exists, you cannot make another with that email on most sites.) I never had a good response for that. I now lean toward the idea…
Many sites require you to verify your email before you can use your account. If you wanted to avoid leaking whether an account existed, you could show them a message like "if this account doesn't already exist, a message has been sent to your email asking you to verify it". If the account did exist, you might send an email like "someone tried to create an account with your email".
Re: Someone keeps trying to reset my Facebook password
#86- create an email address alias (random, unguessable)
- change your login to use that email address
- remove your phone number from Facebook
There are many ways to do this (plus addressing, apple hide my email, account aliases, etc.) Pick your own approach.
Re: Someone keeps trying to reset my Facebook password
#87Earlier quoted context omitted.
The GP is talking about a situation where you are not asked for an email address. You ask for a password reset for the username @coolanonguy. The website tells you that the reset email was sent to an obscured email address. The obscured email allows you to confirm (with high likelihood) or deny (with certainty) that @coolanonguy is your friend whose email address you know.
on the systems where i had to do this for my account i usually get a message like: "an email has been sent to the address registered with this account" there is no benefit to reveal any details.
So it is a privacy tradeoff for better UX. If it is a good tradeoff will depend on how much you value each.
Re: Someone keeps trying to reset my Facebook password
#88This is very common with short or otherwise valuable usernames on social media platforms. Initials and so on. That's what 2FA is there for, but you still get the annoying e-mail notifications for attempted sign-ins. Make sure to weigh the pros and cons when you pick your username on the internet. A dedicated e-mail filter to limit the mental attrition might not be the worst idea.
The @tommy on Twitter was a dev at Gameloft who gets constantly harassed in his mentions to give it up. I had a similar problem on Instagram. I've mostly stopped using it, but when I did post and had an open profile I constantly got comments offering money for my username.
Eventually someone set up a follower bot on my account and I was getting hundreds of new followers a day. I made my profile private and don't post anymore, but it's still hundreds of new follower requests per day.
Re: Someone keeps trying to reset my Facebook password
#89Earlier quoted context omitted.
This is how I'm going to describe that attack where you get a zillion authenticator push notifications because Microsoft has designed the damn thing to authenticate you to them but not them to you. Like, how freaking difficult would it be to put a transaction code in there like Apple so that you can match the notification on your phone with the session you're starting on some other device or service?!
I just wish Microsoft would let me use any other authenticator app instead of their garbage one. So now I've got one from Google with 99% of my accounts on it, one for Microsoft for one of 4 MS accounts, and one for the USG for IRS/etc. Waste of space and poorly-duplicated functionality.
Re: Someone keeps trying to reset my Facebook password
#90Funny I keep getting login codes for my Microsoft account. Also there is seemingly no way to figure out who is doing it or how to stop it. I wish I could just disable that form of login, I have a very safe password so the login via email isn't necessary.