Facebook Asking for Some New Users' Email Passwords
thedailybeast.com
thedailybeast.com
Facebook told Axios that "a very small group of people have the option of entering their email password to verify their account when they sign up for Facebook," but noted that people could choose instead to confirm their account with a code or link sent to their phone or email.
"That said, we understand the password verification option isn't the best way to go about this, so we are going to stop offering it,” the company said in a statement.
Those being asked for their e-mail passwords were users who listed an e-mail address that doesn't use the secure OAuth protocol, which allows users to verify their identity to a third party without sharing their passwords.
Facebook always leaves that part out of its responses to these problems.
I do not give Facebook the benefit of the doubt here, but coincidence is technically possible.
Who didn't know any better, nor why it is bad in general and how it can harm them specifically.
So yes, FB was caught; exposed, if you wish. Especially given that they didn't roll out this feature to everyone, including you and me, which would result in immediate disaster.
A side problem with this is that if it's truly easier for the user than clicking on an emailed link, then users are going to expect that from all of us. So you have to do the sleazy shit or from the users' point of view you are "behind" and less good.
I wish there was some good way to educate the user to privacy dangers. I mean, we could make an online workshop but would have to support it by advertising because we would have to reach the people who don't realize there even could be a problem. And the people willing to drop $5 on it are the ones who don't need to (classic problem in education).
It was years ago, but it sounds a bit like a swan song pattern to my ears despite the lack of any rational connection...
...they should find a new WhatsApp or a Snapchat to buy ASAP because sooner or later they'll be too uncool for people to share the interesting content in their garden, so their humongous user base's value will start asymptoting to $0.
That Facebook will cease to be. That it will expire and go to meet its maker (as its last user). That it's about to be stiff, bereft of life, resting in peace. That if it hadn't been propped up by the network effect, it'd be pushing up the daisies. That Facebook is about to kick the bucket, to shuffle off its mortal coil, run down the curtain and join the bleedin' choir invisible.
That Facebook will soon be an ex-social network.
I would guess it's some combination of the complainers being ignored, and people at a higher level thinking "well we're doing this in a secure way, as long as the user trusts us, and why wouldn't they trust us, we're Facebook!".
The engineers who built it care mostly about their total compensation and getting promoted. They therefore gleefully implement the product requirements.
The PMs behind the idea also care about the above, except they are held to account by business objectives. By narrowly optimizing for a particular objective (reducing account fraud) in an unprincipled manner, they come up with an insane feature idea like this.
The lowly L3 engineer fresh out of college understands how crazy this is and speaks up, but is hammered down by the culture. The decision is quite literally above their pay grade. They begrudgingly fall in line as they have the most to lose in this situation.
Finally a story like this breaks and upper management realizes the contradiction with the narrative that they're trying to create - that Facebook really does care about your privacy. The whole project gets scrapped, and by the time it's all said and done, over $1M is wasted.
Welcome to life at a big tech company.
Before these companies where FAANG most of them were small, crazy startups that were able to easily acquire talent because tech was pretty boring at the time. You could pay market rates, but give someone an exciting project and they'd join you. That allowed all of these companies to completely disrupt the market. Having disrupted the market they are no longer interested in this happening again.
The current hiring practices are to basically drain talent from the startup pool. Paying an engineer 500k is much cheaper than acquiring the new darling startup they ended up creating (DeepMind), which is much cheaper than acquiring the now large company that is threatening you (instagram), which is still much cheaper than allowing existential threats to you to eventually IPO.
There's the added benefit that you now have a bunch of great engineers on your team, but this isn't the real purpose. The tech giants of the past, IBM, Oracle etc all failed to realize how important it was not only to have good engineers, but to also remove great engineers from the market.
It is part of the norm but the norm is horrifying and stupid yet you are the crazy one for suggesting something different like actually listening to the people you pay to think.
Do you have a citation for this claim?
Doesn't make it right at all. But if you were that engineer, it's easier to say to yourself that you'll work your way up and change things the day you are in charge.
To clarify: nothing good for you. Ignoring ethical issues, Facebook certainly benefits.
> Many professionals set out to make a contribution to society and add meaning to their lives. Yet our system of professional education and employment abusively inculcates an acceptance of politically subordinate roles in which professionals typically do not make a significant difference.
Still less than what they spend on management.
Is it a worst practice in our industry right now? Yep. Is it nefariously evil, probably not.
Tech talent of all sorts generally don't know how the business manages money and what rules might apply to that management however.
on edit: added even, removed extra letter at end.
I studied Electrical Engineering and in my experience, the only thing my classmates cared about was the technical aspects of the field, and often they couldn't see the big picture. Great talents of course, but more like robots, not even capable of understanding the humanitarian aspects of life. Such a waste.
Disclaimer: It's just my experience, not necessarily true for all engineers and engineering schools.
If somebody offered me five to eight times as much as I make today with a huge boost in status and other positive side effects, and all they ask is to quiet down those silly principles, I'm not so sure I'd say no. "You can still do good in 5 years when you've made enough money to be set for life", I'd probably tell myself.
Disclaimers: I'm not an engineer, but my CS degree is ABET accredited. I also took a few more Archaeology, Cog Sci, and Philosophy classes than strictly necessary.
But you forgot the most important thing: What happens once upper management reads an article like this and realizes they f*cked up badly again?
Yes, more of the same hierarchy, compensation, promotions, and "culture".
Welcome to "efficient" big corporate hierarchies.
I’ve worked in these megacorps and I understand how easy is to believe everything they do is awesome.
“We’re just doing it to make it easier for our users” or “we’re Facebook, we know how to securely handle their passwords”
It’s very easy to _believe_ these things when you’re in the inside being showered with money and being told how amazing you are all the time.
Now, I can understands that someone working for SpaceX can think they're all amazing, but if you work for FB? It's like working for MS in late 90s - maybe good for you cash-wise, and that's pretty much it.
It was clean and light and fast, unlike MySpace which was often described as a messy, bloated pig.
It's not that I am programmed to keep my head down and focus on technical stuff only and that I don't see the big picture and externalities of our actions.
Having a technical degree instead of humanity or philosophy doesn't make you less ethical. I'd bet a broke and uneducated person can be more ethical than me despite not having the technical education I possess.
I can see the ethical problems but when I raised them to the management.
Management acted like my friend and told me, look pal, there are many people in the world and we can't just think for everyone. You need to care about yourself and your family and we care about you. This is our group and we only care how much our group prospers (read: makes money) and we don't care about outsiders.
It's ingroup and outgroup politics here and it's much easier to sympathize with the people who are in front of you acting desperate to make money than those who you'll never see.
Then they bring their legal team, who assure me that this plan is completely legal, so we will not run into any problems!
Have you ever seen Wolf of Wall Street? It's much similar to that, we live in bubble where it's okay to do those things and no one around us judges us for that, so we feel safe and secure.
There is no one telling me that I am doing something unethical.
If you want to study this problem then go back to history and see how much unfair the world was and people who had it easy were pretty okay with all that.
I can choose to leave this job but it basically means being stripped of your status, income and group (which took years of hard work) and even then someone else will right? And I can move up the chain, some day I might do ethical work, system can only be changed from the top, right? It's easy to justify your actions to yourself this way and stay at the place.
You can't? We'll help you!
You don't know how to? We'll teach you!
You don't want to? We'll force you!
I guess these companies work pretty much like totalitarian regimes but at least you can quit without being shot.
We routinely have clients ask for more tracking data on users and we explain/teach why it is a bad idea. In some way these FB stories help me, because I can point to these articles and ask 'do you want to end up associated with this?'
It's also why manufactured scarcity (especially in housing) enables people who wish to apply engineering effort in unethical ways.
If 10 engineers are bidding on 5 houses, the 5 highest-paid ones will get it. Any pay raise they get will get dumped in to their house - give them all 100k raises and the house will go up by whatever another 100k a year in mortgage payments gets you (I simplify, but not that much)
Not only that, those 5 highly-paid engineers who got the houses have every incentive to make it illegal to build more.
It's hard to stick to your principles when it means getting kicked out of your home, pulling your kids out of school, your spouse having to move away from their job, etc.
It's not just housing, of course, it's a huge part of it. The engineer with a $750 a month mortgage will have a MUCH easier time saying "fuck off this is evil" than one with a $7500 a month mortgage.
Most of this is, as you've correctly spelled out, just due to perverse incentives, and there's not really any intentional malfeasance. The REAL problems start when you get a neurotic psychopath with a modicum of power, and an agenda to climb the ladder, who pushes through ideas they KNOW are bad for the company, as a whole, in the long run, but do so anyway because they know it will help their career in the short run. I've been powerless to try to stop this from happening at two Fortune 250's.
I would argue that the people at the top making these decisions are not ignorant about what is going on.
As technologists we like to think that we are above this behavior, but we are not. All it takes is someone to wave enough dollar bills in front of our eyes and we'll mostly justify our actions with a mixture of whataboutism and by saying "I'm just a lowly cog in the machine".
I'm seeing a great many parallels in the short term predatory and risky behavior in the financial machinations of the past and the behavior of tech firms including FAANG today. Even with the best intentions, the system eventually evolves to a point where the show is being run by fundamentally the same sort of people in both industries. Perhaps it is because it is these sort of people who strive in a cut-throat corporate environment that is itself in a cut-throat capitalist environment.
I'm not saying this as some sort of hard line leftist either - hell, I work in systematic trading so I'm as much part of the system as one can be. Yeah sure, I should hold true to my morals, but what about all the others who are willing to replace me at a moments notice? I'm just a cog in the machine, my action will not make an ounce of difference and only cause hardship for myself.
Oh the irony!
Certainly, you're right that we depend on each one to say "no, I won't do that", but I feel like there's a difference in quality: evil intent vs willful ignorance/negligence. There might be borderline illegal tax-dodging with large tech companies, there might be irresponsible data security, but there's not a lot that is comparable to the cum-ex-trades that large banks engaged in: no active defrauding of the government and/or citizens. Granted, it may happen once tech corporations have as strong a grip on governments as banks do, and feel secure enough that they won't have to face repercussions if it blows up.
Plenty of banks, and not just the large, global ones have actively engaged in tricking their customers by selling them junk and hiding and/or downplaying important details to get their sales provision, and it wasn't something that was "only known at the top". I've yet to hear of scandals of a similar magnitude in tech. Chrome doesn't contain any hidden crypto-miner, and if it ever will, I doubt that an investigation would reveal everybody on the team knew about it - it would likely just reveal a security breach or a small amount of people subverting the processes.
I do completely agree that tech isn't all sunshine, however. Behind pretty much every large scale data leak is an engineer that said "well okay if you want me to put this database server on the public internet and remove the password, I'm happy to do it" instead of refusing, and behind every horrible overreach in surveillance is an engineer that just blocks out the impact his work has on real people. There are people working on killer drones after all, and I don't think any of them are naive enough to believe that "they only target the bad guys".
Oh so you are saying that the willful and deliberate exploitation of people's private data, the willful and deliberate ignorance of laws by companies like Uber, the willful and deliberate "research" done by tech companies to determine the most addictive products to entice people to buy in and stay on particular platforms, the willful and deliberate exploitation of minors by tech companies to get them to spend their parent's money on whatever stupid game or product is the fad of the week, or the fact that there are tech companies running targeted campaigns to influence voter opinion based on stolen private data is all just ignorance/negligence?
I strongly disagree. There is just as much rotten in tech as is in finance, the only difference is that many of the shenanigans enabled by tech have not been outlawed yet. Borderline illegal tax-dodging by large tech companies is business as usual compared to the other crap that they do, but being disruptive and breaking things is hip and cool, and it's Us doing it, and not Them, so we let it slide.
You say that banks are willfully selling junk to customers, and this is true. But this is exactly the whataboutism I was talking about. Tech companies mining people's most private data to get them to buy stuff they don't need is just as insidious, if not more in my book.
I don't see Facebook openly admitting to their users that every single bit of their and their loved one's lives will be exploited to the max to allow thirds parties to influence their opinions based on the wishes of the highest bidder.
I don't see them warning their users that right now they are (maybe) not being profiled by governments for thought crimes, but the data is all there, so if in 10, 20 or 50 years time the government changes, this is a definite and very real risk.
Again, let me make that clear: I'm not arguing that every company in the tech industry is staffed by angels, but that intentional bad actors in tech are the exception, not the norm.
> Borderline illegal tax-dodging by large tech companies is business as usual
And I haven't said it wasn't, I've merely compared it with what the largest banks have been involved recently. I don't know if it got worldwide coverage - this is what I was referencing: https://en.wikipedia.org/wiki/CumEx-Files
> I don't see them warning their users that right now they are (maybe) not being profiled by governments for thought crimes, but the data is all there, so if in 10, 20 or 50 years time the government changes, this is a definite and very real risk.
And I'd love for them to be legally required to explain privacy considerations to their users in such a way that informed consent can be given. Again: I'm not "pro big tech", I'm saying that big tech still has some room if they want to rub shoulders with big finance when it comes to amoral business practices. Big tech operates in a grey area, big finance hasn't seen anything but #000 in decades.
Facebook's would most probably not call it off. Or just resurface the same thing at another time with another name or excuse.
Probably all approaches are needed.
I'm simply stating, that if no one is on the inside, then we're missing out on a possible interaction channel that could help changing FB.
Simply trying to get in to be on the inside - without lying, is better than not even trying.
Of course, trying to advocate for better political control (privacy, transparency, lower barriers to enter the market) is important, and can and should be done while trying to engage with FB, trying to get close to their internal decision making process.
And, naturally, not everyone has the affinity to work at FB, but since it's a spectrum, likely there are a lot of software engineers that do have some ethical concern with regards to what and how FB does, and they shouldn't be discouraged from working at FB, but they should be very much empowered to be able to stand up and leave when their moral compass signals.
With all the shit being fired at Facebook from all directions these days, I just want to see the faces and reactions of those who thought "Yep, that's a good idea!" when this concept was originally brought up. It's really stretching my curiosity and imagination to the point where I start wondering what type of people they are hiring at Facebook these days.
Is there a name for this phenomenal in psychology where one would insist on doing the exact same things other people are criticizing them, but with an increasingly higher intensity the more they get criticized for it? This is exactly what it is.
LI are awful for many reasons, but they do honour these things.
Pretty quickly, people learn to keep their mouth shut.
Also, many, many FB engineers are early-career folk who are fresh out of school. More senior folk are few and far between and are even more strongly incentivized to keep their mouth shut, because their bonuses are bigger.
I guess this is what happens when a startup gets big. They keep all the toxic baggage of startup culture (edit: "move fast and break things") while gaining the impact on people's lives that big companies have.
I think Apple is the only one of the FAANG that's jettisoned startup culture, and I think that's why they're doing so incredibly well.
https://www.irishnews.com/magazine/technology/2017/11/08/new...
Let's not underestimate the power of precedents: someone else said it was crazy at ANOTHER COMPANY, didn't get their idea through, and now other companies are copying it.
Additionally, a lot of people in the comments mentioned how engineers are ignored. Being able to convince your peers (like a product manager) of something is a skill, one that is fairly uncommon among "top tech talent", but happens to be a minimum requirement for roles like PMs. Saying "We can't do that, it's crazy!" and expecting everyone to just agree with you because you're awesome at coding just isn't going to cut it. Yeah, maybe the PM should have realized it was insane on their own. But let's consider that given hundreds or thousands of people in a company, crazy ideas might get deflected thousands of times, but it only take one "failure" for it to slip in.
I have never had a higher level person worrying at all about security except as a nuisance when prodded.
Maybe they hired someone who worked at border controls?
You see, Facebook has Facebook.com, Instagram and Whatsapp.
Facebook.com has already reached it's peak and is not going to grow.
Instagram is likely to have the same trajectory as Facebook.com and Whatsapp is not making them money anyways.
They failed to get into any new market or come up with any decent product.
And they are supposed to compete with Google, which is competing on all fronts with extremely competitive offerings.
* Google Search
* Gmail
* Android
* Youtube
* Chrome
* Chrome OS
* Google Drive
* Google Analytics
* Google Docs
* Google Cloud
* Google Apps
* Google Maps
And they seem to be constantly trying new things (Stadia seems to have a really good chance to compete with PS and Xbox and get them a holding in gaming)
And Facebook keeps pushing out pathetic moves like this and all their acquisitions that were supposed to help them get into new markets and sectors (Oculus, Parse, etc) seem like failures.
Acquisition of Instagram bought them another 10-15 years and they should be just very lucky to keep making the right call and buy the next Instagram)
Google continues to make the majority of their money from advertising. And since those early days they have not released a single product which has helped to diversify their revenue stream. But they've had plenty of failures along the way.
Facebook is far more interesting in terms of diversification. Payments via Messenger/WhatsApp is going to be great for them and is already doing well. Spilling over into web services e.g. Dating is equally looking promising. And they've done okay in the enterprise space with Workspace.
Fact is that it's far harder to switch social graphs than it is to switch search engines.
Chrome OS
Have you followed news recently? It's dead.
IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...
What is not normal is that they grab your personal identification number and send a login request using BankID before you open your app. When authenticating the login you authorize one of Klarnas third parties to log into your bank account as you, allowing them to pull records of all your financial transactions, account statements etc. Most users just authenticate the login without reading where the request is coming from on the login prompt.
I don't understand how that can be legal, but they are relying on recent court cases where scammers would call old people asking them to log on to check their retirement accounts. The scammers would then send a login request before the user sent theirs, log on to the accounts and change what funds received the victims pension payments. The scammers were ruled in the wrong, but the logins themselves were ruled to be an ok way of doing business.
[0] https://en.wikipedia.org/wiki/Electronic_identification#Swed...
It's truly insane, if I see any company accepting payment via POLi it's instant verification the company in question is clueless and that I should avoid using their services whenever possible, because they have zero idea about security.
According to POLi[1][2], the list includes:
Qantas, Jetstar, Virgin Australia, Microsoft (?), Sportsbet, Emirates, BetEasy, CoinSpot, Australia Post, TigerAir, Facebook (?)
The list goes on. It's pure madness.
I really wish there was more awareness of this, I can't believe these massive companies can't comprehend how they're being implicated when they encourage users to hand over their banking password to a third party.
[1] https://www.polipayments.com/ [2] https://www.polipayments.com/Buy#matrix
They just don't care; if something happens, people (including the press) won't really blame Microsoft or Qantas, so they don't have an incentive to vet those payment systems.
I will certainly steer clear of this process in the future.
This seems like something that the Riksdagen should step-in on. BankId was meant as validating a legal entity (I am who I say I am) and a third-party presenting that they are they are that legal entity (in this case, the person in question) would certainly seem to circumvent the intention behind that.
"When authenticating the login you authorize one of Klarnas third parties to log into your bank account as you, allowing them to pull records of all your financial transactions, account statements etc.“
Do you have any source to verify this claim? That they can and do pull down this information. I would like to know if they really have all that information or not, if so it's a surprise to me, did not know that.
You have to confirm once more for the payment to be sent.
I just paid using their direct payment method two times the last week or so. Will be more on the lookout in the future and try to keep an eye on these things.
Where it says you can email this address "dataskydd@klarna.se" if you either want them to delete your data (except data they are required to store as a bank) or if you want a print out of your personal information they store.
The matching UK site (in English) is here: https://www.klarna.com/uk/privacy-policy/ and has this email for the same purpose: "privacy@klarna.co.uk"
It's a great service and I can't believe shady things like this is allowed.
But I'm not sure that's the way Klama does
How would this work? As far as I know Swedish courts don't follow stare decisis.
If the decision was made by one of the higher courts, a precedent will be created, which while not formally binding is essentially treated as such. In general the precedents can't create new law, only interpret. However this turns out to sometimes be a difference without significance, as effectively new law is created due to how heavy lower courts are leaning on some such cases.
One I have some knowledge of regards agency of company representatives where the interpretation made it essentially legal for a company to use third party sellers to act as representatives for the company write and sign contracts, which then the original party could renege on at any time, with no penalties by simply stating that their agent had overstepped their bounds. This was a case of a house builder backing out because the agent had given a price that the house builder deemed a little too low. This is described in the relevant literature as a clear precedent for all manners of company agency, while if you read the actual judgement it was clearly marginal. But it has effectively created new law. You now have to make sure to write contracts with an employee of whomever you are dealing with if you are to be able to trust in your contract.
All courts also have a right to judicial review, thus in theory a single local court can nullify any law if it doesn't follow the constituting laws, either completely, or for a specific case. If this happens, then that case becomes a precedent. This is however somewhat rare as far as I understand it, as it's somewhat of a joke that the best way to loose a case is to refer to the constituting laws, as they are essentially completely ignored.
Yeah, I'm amazed it works at all.
At least on the surface it seems our judicial system really has some deep flaws that nobody has really dared to address.
To little real oversight, no binding checks on the constitutionality of new laws - although the advisory committee tends to be respected, and no formal way afaik to revoke precedents that turn out to have bad consequences.
It seems to work a lot based on some form of "gentlemen's agreement", and tradition. By now I guess we all know how quickly those can crumble.
Paytm (India's largest e-Wallet), asked customers to enter their credit card details on their app on merchant's smartphone. I reported the security risk to them with a POC to their bounty hunting[1], they asked me to wait, removed the feature & the CEO told media that I was lying, there was never a security risk.
Mobiwik, read customer's SMS of bank transactions to inform its users which ATMs had cash.
[1]:https://abishekmuthian.com/paytm-says-to-me-that-its-pos-fea...
Here's why: 1. Most banking companies seem to have a much better security landscape than other places, including tracking where you're logging in from. Even with a password it won't be easy for a hacker to do stuff with my accounts. Almost any change or transaction triggers an email and sms alert too.
2. The main bank I have my money in, doesn't let you do transactions larger than 2000 in a day online, and even that is insured against fraud.
3. For credit card accounts, I have noticed that you actually can't do much with just an online account, except to pay the bill.
4. Mint is owned by Intuit and they know my tax details, most of which are far more important and guard-worthy anyways.
5. Also till now I've been a fairly poor guy with not much in my bank accounts. So I didn't worry too much about losing my cash since I didn't have much. If you have a lot of it, perhaps you need to be careful with such services.
They say they will anonymize data, but advertisers have no interest in data if they can't action on it -- i.e. use the data they buy for targeted advertising.
Its all boil down to risk vs benefit.
I went to turn it on only to find that they use a third party who ask for all of your Barclaycard credentials (including your full "secret word", which you normally only enter a few characters from at login time). I've no idea why they'd go this route, but exactly as you say - it just trains users to get phished.
It also wasn't clear what this third party would do with the transaction information they scrape from your account. Overall a terrible idea.
If they asked for your PIN code, people would clearly balk. But somehow, passwords to a bank account are fair game. It's exasperating.
Which is Klarna.
> Thereby training the public that passwords to a bank account should be given to random third parties, undoing years of pain staking training efforts.
Accounts details are relatively fine to enter on other sites, just entering 2FA tokens should be limited for transactions that you really want to confirm.
1. You train end users that entering banking credentials on 3rd party sites is Okay. This makes educating against phishing an impossible task.
2. Many banks require (a form of) 2FA to log in. Perhaps it’s a “2 letters from a secret code” system (see sibling post). You’re now educating users that entering 2FA on 3rd party sites is ok. This is the end of educating users about any security at all, really.
3. This 3rd party gets access to my full transaction history, everything I ever spent on anything, using this account. That is an unconscionable overreach in personal data access. “But we don’t use it / read it / store it / we only send it to trusted partners / .....” I’ve heard that song too many times.
If someone asked for email account passwords and 2FA login, people would scream bloody murder. What makes this different?
Note that none of this is about money. If someone defrauds me, the bank will refund me. It’s the least of my worries, really. Sure, rather not. But the bank can’t refund my privacy if someone exfiltrates purchase history. Based on any data leak ever, I think we all know what’s the most valuable thing in my bank account .. it’s not the money. It’s the data.
A couple of people have raised concerns about security and privacy.
They need to be exposed. Or sued.
Except that like all no-longer-a-startup companies who can make your life a living nightmare if they are not spot-on perfect with their security, Plaid have slapped a mandatory, binding arbitration clause in their user agreement.
Thus, if they do drop the ball in some catastrophic way, your ability to recover anything beyond a firm handshake and maybe an "oops, our bad" on the way to an "Our Incredible Journey" blog post is on the same level of probability as my winning a gold medal in curling at the Olympics: it statistically could happen, but very likely won't.
When it comes to Credit Card Fraud, the banks are buying all sorts of AI based solutions - after all it's their money. When it comes to customer cash, then its the wild west. I recently found out that my Wells Fargo password isn't even case sensitive.
There is clearly a market need for easier information exchange. Authorizing ACH withdrawals shouldn't require me depositing 2 random values in your account. The Banks could have done the work here, but they didn't and then Plaid came along and did the work for them. I hope they take data security more seriously than Wells Fargo.
Plaid's value is providing the SDK that developers can plug into their app to connect user bank accounts with their app. They have purposefully decided not to show a very common step in the user-facing bank link/onboarding flow of displaying exactly what information you are providing the developer with (e.g. think about FB Connect, Twitter, and Google and how each requires developers to show exactly what permission is being asked of the user).
Plaid has several endpoints you can hit. It could be as little as the bank number/routing number (to pull/push funds), but it can be years of bank transaction history and/or all identifying information about you from your bank (e.g. names, emails, phone numbers, addresses) and/or your current bank balance as well. An app that doesn't even provide mint-like functionality (e.g. showing your spending habits) could be pulling years of bank transaction history and you would not even know. That's horrifying.
Again, Plaid can and should take responsibility for not showing a simple permissions page. There is no way this is just an "oversight" on their part. It's a deliberate decision because they know it would be a conversion killer if people actually consciously understood how much information they are granting to random apps.
When I called a prominent bank* recently, I was asked to enter my password via the phone. As in, the digit-equivalent of my password. At least I finally figured out why their password length is capped so low - user experience!
*I began this post with the bank name, and then wondered if given their approach to security, even that might be a bad idea.
But it doesn't really matter how seriously Plaid takes data security, as their whole business is around providing your account data (including your transaction data) to other companies. What matters is if the thousands of business customers of Plaid take data security seriously.
I was incredulous when I first tried to use POLi Payments and realised how it worked—I ran away screaming, naturally. That entire business should be shut down with prejudice.
Maybe if the banks realize their customers are handing over their credentials in large numbers, it will light a fire under them to build a real solution.
Or they might pop a bottle of Champaign over that, in jurisdictions where the bank is by default responsible for all the account abuse risk unless they can prove that the user has shared credentials.
On the other hand, there's an underlying (and valid) concern that handing over bank credentials to a third party is risky and, even assuming good faith from Plaid, they have to store passwords on their servers somehow (probably encrypted). Since they make money from integrations with startups/big banks, there is definitely a conflict of interest between keeping user credentials safe and growing their revenue.
I think as a whole, relying on a modern company which specializes in authentication is better than trusting that thousands of app developers, some of which might big legacy banks with woefully understaffed IT departments, will keep your credentials safe. I'm aware that I'm more optimistic than most people in this thread (and on HN) though.
Here's a stackexchange question with some good discussion about Plaid security:
https://security.stackexchange.com/questions/198005/is-plaid...
Here's a github issue on Plaid's repo, showing that they are at least considering oauth on their roadmap:
https://github.com/plaid/link/issues/68
And here's Plaid's page on security, which is frankly short and a bit vague:
For banking, a better system would allow you to generate some kind of token in your banking site which would allow the kinds of permissions you want to grant to a third party, and which you could unilaterally revoke at any time.
Wow, that's insane. I didn't think I'd ever be happy that all banks here in Brazil require you to install an invasive piece of software to validate your computer before allowing you to use online banking, which as far as I can see makes that sort of business model non-viable here.
Add that on top of increasing fees and I'm seeking alternatives.
We really haven't moved forward at all!
But worse than this, just by installing the Facebook App it liberally takes contact details from your device [1].
I personally use mbasic.facebook.com as it can run without JS and only updates when you refresh the browser. facebook.com refuses to run without JS and causes my browser to use tonnes of resources when JS is enabled.
(P.S. Like many, I can't completely abandon Facebook just yet as lots of older friends and family are "unable" to migrate to other platforms.)
[0] https://developers.google.com/contacts/v3/
[1] http://www.androidbeat.com/2018/03/facebooks-android-stealin...
Why trust him now?
[0] https://www.businessinsider.com/how-mark-zuckerberg-hacked-i...
But Mint works the same way, doesn't it?
The CTO/CEO wanted to add a feature that lets users enter their bank password and through a service (Yodlee/TradeIt) lets the company read their stock portfolio and perform actions.
I told them that I don't think people would trust their bank info to some small fintech startup. Boy was I wrong and people with 4M dollar stock trading accounts would enter their credentials all the time for convenience of not having to copy the data over (since brokers didn't have an API with tokens).
Eventually the company grew and it's pretty reputable on its own but I remember this pretty vividly the surprise of people trusting all their money to us.
It's not really that people trust you that much, it is more that they in the moment you ask don't understand the consequences at all.
Unless you very explicitly tell the users about the risks, that they wold have zero recourse if something goes wrong, they will believe it is okay for them, that somehow everything is taken care of.
Very similar to the why people fall for con men. Nobody expects someone to have the audacity to lie so grandly, act so confidently, while in truth being completely 'naked'.
You tend to assume that the insanity must have a point, that the obvious loopholes must somehow be covered - taken care of - based on nothing but the fact that someone acted with confidence.
After a bit of consideration I went ahead and did it—I consider Google trustworthy as far as security practices, and to be honest, I didn't expect it to work. Chase forces (!) two step authentication despite my very strong password, and I thought that would prevent Google from logging in.
To my surprise, the process appears to have worked fine—my bank account was verified. I also didn't get a "new sign in from" email from Chase. So I wonder if they actually logged in or did something else...
Sure you do. They have it in plaintext on their servers. It can end up in logs. It's also not just Plaid - Mint uses Intuit, Yodlee is an option. There's a whole lot of people you need to trust to use these services
For many banks, it also means you need to disable 2fa on your banking account, so using these services directly weakens your security.
Providing any company my banking or email account login password sounds like a really bad idea. And something I'm not willing to provide.
Facebook already has a messenger, so they definitely don't need access to my emails.
It just seems like an unwritten rule that sites are not to ask users for other sites' passwords. It's basically phishing.
They certainly don't like it when you do it to them. https://www.gizmodo.com.au/2018/08/facebook-wanted-us-to-kil...
For that purpose alone I kept it.
And they have a point, it's easy to find out if someone is single or not via Facebook, and you are bound by your friends to be truthful.
I'm not single anymore, but I'm still curious, in those countries where everyone is not sleeping around with everyone what would replace Facebook?
That was many, many years ago. Ever since, they've been tightening up privacy defaults, and now when checking out that person you met, the best you'll get is a profile picture and a list of mutual friends. Everything else tends to be locked down by default for non-friends, and Facebook keeps regularly reminding people posting widely that they could tighten their posting range.
Whether that's a good or bad evolution depends on one's use cases and the views on whether being able to do little background checks on other people is OK or not.
wat?
Accidentally log that data somewhere, and you've opened a way for attackers to take over your users bank accounts, social media, and pretty much every other online account, as they all rely on email verification.
If we had privacy laws with teeth, somebody at FB would be calculating how many millions in liability each piece of data collected represents. This one would be astronomical and an automatic "no" by those calculations.
Verifying email addresses is a solved problem that doesn't require _any_ of that... you just send a time-sensitive, signed link containing a unique identifier to that email address, and users click it to verify their address.
I really can't understand why they would choose to go a different way -- and particularly _this_ one.
I am not sure if allowing users to use non-email addresses as a user-name helps solve that problem, though. I would be interested in reading research on the subject.
What a dishonest article. Facebook is not demanding users to give them the password to their email to be able to use the network. Instead, it looks like they are giving the option of doing so to verify the email address, but you can still go the traditional route of verifying your email by clicking a link.
Hiding something under completely unrelated link is not presenting your options in any way which is remotely close to being honest.
Lookup the password re-use rates among users of the Internet.
People may have weak and strong password for less and more important services. Guess how would they rate the Facebook...
Gmail, for example, detects a new computer by cookie and "fingerprint" (ip address, browser, UA, etc). You then get 2fa'd or at least "robot checked".
How did they make this a smooth experience?
Presumably google and other high security email providers got the OAuth option and this more insecure option was offered to users with ESPs that don’t have the gmail security features you mentioned.
Maybe they can also scan users' e-mails for "suicidal ideation" and have their swatting algorithm send in the police to "protect" them.
Or is it that people would support this use because of a 'noble intention?' (ends justify means)
Stop patronizing us. Seriously, you look foolish and ignorant. Drop the marketing speak and own your screw-up.
Simply asking for my password is enough to make me distrust you forever.
Well, of course.
> Surely (BigCompany) measures would prevent that?
What do you mean?
(This is not a defense of Facebook's actions here)
It's definitely a dark pattern though. And Facebook rarely seems content to only use data for the purpose they advertise when asking for it. For instance, there was an article recently that proved they were using phone numbers collected for 2FA to do ad-targeting as well.
The next social network would also have to provide the simplicity, performance and features people expect, while showing real, understandable improvements in terms of privacy or the economic model (e.g. no risk being bought by Facebook like WhatsApp).
In general, 'new social networks' seem rarely discussed, here in HN or elsewhere; can you maybe name a few of the options you have in mind?
Only somewhat joking.
The passwords have to be forwarded over to the email provider, so they are flying around log files, unsafe in the database. There's actually a programmer somewhere who can read all of them and put them in a text file and take them home.
Still, one has to wonder why do it at all, considering the simple alternative of sending a verification email, which was already implemented.
If there's an error isn't there a chance that the password leaks out into an error log somewhere?
Probably, yeah.
> If there's an error isn't there a chance that the password leaks out into an error log somewhere?
Sure; there are ways of avoiding that, but who knows what they did.