More Ways to Stay Secure (Facebook introduces one-time passwords, global logout)
blog.facebook.com
blog.facebook.com
My teenage friends trade phones all the time and they constantly nab them out of pockets, backs, purses, etc. for a few seconds. This change makes it trivially easy to steal someone's credentials.
Within the next 2 years, most everyone's phone will already be logged in to Facebook, as smartphones become as cheap as iPods, mooting the latter concern. Regardless, if you can't safely use the feature, you'd be well advised not to use it.
My phone dies in 3 days if I have bluetooth on, and it cost $60 for the one-step-above-dirt phone after a 2 year contract got me a discount.
Also, how many people do you think are "well advised" of safely using security features? Even simple ones? Who don't see Facebook as one gigantic privacy / security geyser? ie, non-security-aware-geek-types? This is a minor, arguable security improvement and a major feel-good for people who don't know any better, and not much else.
Now if I ever use it... It is hard to get to. I find that I peek at my Gmail activity more with the link on the bottom.
on an unrelated note, is anyone tackling comment spam by ignorant humans that's not relevant to the article? just look at the comments on the blog post to see what i mean.
To everyone in what countries? I guess US users only?
If anything though, it makes it easier for your friends to log into your account and prank you: "Do you mind if I borrow your phone for a minute?" And then log in on their laptop.
When someone steals your phone, you can suspend your mobile service. You can also disassociate the number from Facebook.
The perpetrator 'borrows' your phone .. sends a one shot password request .. logs in to your account and deletes the message. You find your phone where you left it and are non-the-wiser.
If you want confidentiality, you have to be certain to share only that which you are comfortable being made totally public. This goes for information written or spoken pretty much anywhere. Long gone are the days of ephemeral communication.
For what it's worth, Facebook's Availability (uptime) is pretty good, and these measures have the potential to improve Integrity, but only if implemented and used properly both by Facebook and the end users.
A few times, I was warned that someone tried to accessed my account from a different computer, and went through a multi-step process to prove that I was indeed me. And, though it was multiple steps, it wasn't too much of a hassle actually.
Another time, one of my friends' account was compromised by a scammer and I got the account shut down in a couple of hours.
Recent activity and global logout is pretty useful. I imagine Facebook will offer a two-factor authentication at some point down the road.
Notice that throughout the entirety of this, I've stated my opinion. No more, no less. I even lauded this move as a way to potentially increase Integrity assuming proper implementation and use, yet I get buried.