Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card
codewriteplay.com
codewriteplay.com
I wish he'd mention what kind of 2FA. The reason you _really_ should use U2F/WebAuthn is because it does origin binding which, unlike entering a TOTP, a code from your hardware token/authenticator app on your phone/SMS/etc is not phishable, i.e. you can't enter it by accident on accounts.google.com.totallylegit.ru and then have them enter it on real accounts.google.com. This is so because the U2F/WebAuthn security key signs a request, sent by your browser, which embeds the requesting page's domain, so a signature on attacker.com will not pass victim.com's verification checks, whereas a code from your authentication app is trivially copied.
edit: correction, beating 2FA without phishing-- like in the post where he lost his account while asleep.
Eventually some required the last 4 of your social security number to port a number, which we all know at this point are pretty much public anyway.
T-Mobile now lets you set an arbitrary pin, which my parents promptly set to their DOB :facepalm:
I haven't looked more into it, but as far as I know, sim swap/port attacks were hilariously simple to execute which is why I only use SMS verification when it's the only option.
I trust that it would be (potentially much) harder than normal, but it still seems to be possible.
I can think of options less extreme than keys gone = account gone that are still very secure.
e.g. To enable "Extra Advanced Protection" you have to visit Google HQ in your region, where your DNA is sampled. If you ever need to recover your account, you have to visit Google HQ again for another DNA sample, after which you're provided with account access, in person.
and who's gonna pay for that? Seems pricey and doesn't scale exactly well.
IMO, this is way too extreme for almost everybody. There needs to be some sort of happy medium so that a person who's lost everything they own (e.g., house fire) can get their account back somehow still. Two ideas I had:
1. When you set up your account, provide your legal name, date of birth, and a photo. If you need to reset 2FA, go somewhere in person with a government-issued photo ID (which we already have procedures to replace) that all of the details of match.
2. When you set up your account, provide 5 trusted contacts. If you need to reset 2FA, get 3 of them to agree.
Very few people are going to want to pay for this labor if the perception of risk of using a free account is as low as it is now.
Simply offering the option would bring the risk to the forefront of people's minds, and once you start exchanging money, lots of other thoughts and liabilities begin to enter.
If it is kept free, then the conversation ends there.
If you ever need to have this done, you'll realise how much house keys and door locks for many cases really only stop the opportunistic "pull the handle and see if it opens" attack. If your door has above average security they'll need to drill the lock, but the time I had to call one they could just push a tool through the letter box and break/move the bolt by applying leverage from the "indoor" side.
Same with 2FA. Just like a Locksmith it's a "human in the loop" situation where you'll need to give identification etc.
The rest of your post isn't relevant it's just about picking door locks.
I would bet that the post office employees are a bit less susceptible to the “hurry up and hit your metrics” pressure than someone at the Verizon call center.
That's most definitely not true, as someone who works in this space. Plain old phishing is much more common, where the hacker tricks a user into entering their code into a malicious website.
To echo OP, this is why it's important to support non-phishable types of 2FA.
The basic U2F + FIDO2/WebAuthn is the least expensive model, around US$25. These days it works seamlessly on Chrome, Firefox, and Safari.
It's also good to know that Yubikey's OTP tokens don't expire based on time, but based on a hidden counter that gets incremented with every issued token.
So if you've accidentally touched your Yubikey and leaked the token publicly, you just have to log out and then log back in using your Yubikey - that action will invalidate all tokens issued before this point.
There's also a WebAuthn extension in the works to at least make it easier to maintain a backup key by not having to pull it out of the safe every time you register MFA with a new service:
https://www.yubico.com/blog/yubico-proposes-webauthn-protoco...
> I wish he'd mention what kind of 2FA. The reason you _really_ should use U2F/WebAuthn is because it does origin binding which, unlike entering a TOTP, a code from your hardware token/authenticator app on your phone/SMS/etc is not phishable, i.e. you can't enter it by accident on accounts.google.com.totallylegit.ru and then have them enter it on real accounts.google.com. This is so because the U2F/WebAuthn security key signs a request, sent by your browser, which embeds the requesting page's domain, so a signature on attacker.com will not pass victim.com's verification checks, whereas a code from your authentication app is trivially copied.
You can do this two ways, one of which will make more sense for your web site:
1. PCs/ laptops/ etc. can use little USB hardware devices, from outfits like Yubico, the word to Google or type into your preferred hardware source is "FIDO" although if you have spare cash and like cool toys FIDO2 is a more capable second generation of the technology.
In this situation the FIDO authenticator is your second factor. Your web browser takes responsibility for telling this authenticator which web site you're looking at, and it's just a dumb machine, so from its point of view obviously refunds-my-bank.example isn't mybank.example because those strings are different. The FIDO authenticator just does whatever the browser tells it.
This could be attacked by specialist malware, but it's tricky because the FIDO authenticator wants you to take physical action to trigger authentication, so the malware needs to not only tell the authenticator "Yeah, I'm totally er, Internet Explorer, and I need you to authenticate for mybank.example" but also persuade you to press the button or whatever to make it happen.
Or I guess bad guys can be like "please FedEx your FIDO dongle to us" if people really are that dumb, but then no need for phishing, just call people "Hey, I'm the IRS, send me $5000 in unmarked bills, in a FedEx box marked er cat food for some reason that totally makes sense, to a residential address in a different state, yeah".
2. High end smartphones, the sort with a fingerprint reader, can do the same exact trick using that fingerprint reader (I think some iPhones do facial recognition instead?) to do WebAuthn instead for their onboard browser.
In this case the smartphone is in charge of everything, it knows which web site this really is, it knows if that's really your fingerprint or not (the fingerprint never leaves your device) and it decides whether to send credentials.
For machines it's much easier to do a secure transaction, but machines don't fall for a lot of phishing scams.
This is actually built into most computers now -- Windows Hello, and Apple has something similar. Websites can check the attestation response to specifically block those, however. (Seems like Github allows it, and I've written code that allows it.)
> I think some iPhones do facial recognition instead?
Yup, they use whatever you use to unlock your phone. So if it's a FaceID phone, you can use FaceID to log in. You can also hold up your NFC Yubikey to the back of the phone and use that, even if you registered the key over USB on a PC! It's really, really good.
So old workarounds like using the lightning port are no longer necessary, though AFAIK are still supported. It's nice to have it there as well since to really be most effective every platform a user has needs to support hardware 2FA. If something still needs SMS or OTP or whatever that becomes the weakest link.
----
0: https://www.yubico.com/blog/yubico-ios-authentication-expand...
1: https://developer.apple.com/design/human-interface-guideline...
For the client side of things WebAuthn contains a standard option to block/allow "platform" authenticators, which I empirically know includes Windows Hello, and I'm not sure about Apple's or other equivalents. Of course you'd still want to verify the attestation on the server side.
You almost certainly do not want to do this for a public web site. If you insist on attestation right thinking people will hit "No" and block the site.
Think about it, what is attestation doing for you in this scenario? You're saying that you don't trust your users/ customers to pick the authentication methods that work for them, and instead you're going to insist on methods you prefer. Do you also choose each user's passwords? "No, sorry, that resembles an English word, we have selected the password 48'J3X$q)M3NBfr_2 for you instead" ?
In a corporate environment this could make sense. If you issue every employee a $100 FooCorp Security Key with their photo engraved on it, maybe you decide to require attestation that the keys used are FooCorp brand keys to prevent employees adding some off-brand Yubico product. I don't know whether that's a good idea, but it's no crazier than lots of corporate policies, however doing this for a public site makes no sense, please just skip attestation.
And there's no reason to do this! It's not like they're liable if I get my money stolen. If they prove 2FA was used and the security issue was on my device, not their app/server, it's my fault! As you said, if you're a custodian of something sensitive (an account, documents, money..), not the owner of it, it makes sense that the owner shouldd be able to dictate how you should protect it (like if you're accessing confidential company documents using 2FA). But in any other case, the service provider should never be allowed to force you to use a certain type of authentication device.
Firefox does NOT support Touch ID for webauthn
webauthn basically forces use of HTTP as the application level protocol, whereas a client side TLS certificate will work regardless of which application protocol is in use.
My FIDO authenticator has no idea who I am, no opinion who I am, so you can't use it to do identity correlation. It's only useful for the very specific problem we wanted to solve "Are you still you?" "Yes".
In contrast a client certificate for u801e is enduring proof you're u801e and signatures the client cert makes during login will be durable proof that u801e logged in. PornHub can show Facebook and GitHub that the same user is using their site. So that's a privacy hole you can drive a truck through.
There are numerous practical problems with trying to leverage TLS client certificates for this work, but that's a big privacy problem.
Client certificates can certainly be separated based on different domains. So, there would be no way to really determine my identity across multiple websites if I sent each one a different CSR and they each gave me different client certificates. The browser should only send the client side TLS certificate that's relevant to the server it's trying to connect to via TLS.
The main purpose of the client side TLS certificate is to verify the identity of the client on the server side, just as a server side TLS certificate signed by a trusted CA allows the client to verify the identity of the server. In the case of the client side TLS certificate, it doesn't have to be signed by an outside entity. There could be an internal CA the server uses to sign those CSRs and when the client connects, the server need only to verify that the client cert presented has a valid internal CA signature.
Why would you want passwordless authentication? Isn't the whole point of 2FA that you have to have something and you have to know something?
Besides, there's nothing that dictates how secure the key should be. You could use your hardware cryptocurrency wallet for this, which is probably much more secure and convenient than the average Yubikey (you can duplicate it with the seed phrase).
Wouldn't the ability to duplicate it make it weaker?
What's different compared to having a web site password? The web site knows the password, but they don't know your PIN. This means suddenly relatively weak human memorable passwords are good enough, because bad guys can't break in and steal 40 million of them in seconds or leverage them across multiple sites, the PIN is useless without the authenticator.
But other FIDO2 authenticators can do fingerprints, making it something you are (a person with that fingerprint) and something you have (the authenticator) so two factors again.
Usernameless (rather than passwordless) is the differentiator. You can literally have the sign-in flow be a "Sign In" button and the user does the thing (finger on reader, types in PIN, or maybe looks at camera) and they're authenticated. No step where you type in an email address or a username. This has a privacy cost because it means the authenticator knows in some sense who you are, but it is super convenient if that's what you're all about - while being much more secure than today's username + password dance.
In 1) I don't think my YubiKey knows anything about the sites I use it for? It just creates keys, so a phishing site could presumably still steal the key created by YubiKey and pass it on to the real site.
2) My fingerprints definitely don't know anything about web sites. So WebAuthn being unphishable has nothing to do with fingerprints. It is only incidental that some devices decide to unlock the functionality with fingerprints.
2) Correct. In fact you don't even need a hardware token. You can do the whole thing in software. It could even theoretically be built right into your browser (but you would have the problem of logging in to the account on a different device or different browser). The fingerprint protects against physically stolen devices, and slightly against malware on your computer.
Then again, it doesn't have to be the password manager that does this, but it'd be nice if it were integrated.
It's even a little bit cleverer than that. During enrollment (to say, Facebook.com) your Yubikey provides a random looking "identifier" to Facebook.com, and it promises that it can sign future logins if Facebook.com shows it the same identifier. The identifier is bound to the DNS name!
So a phishing site has a few choices, none of which help the bad guys even a tiny bit:
* It claims to be Facebook.com, but it isn't, so the web browser just doesn't even show the UI for Security Keys. There's a behind the scenes Javascript error basically, "What? You aren't Facebook.com fool".
* It admits its real DNS name, and makes up a random identifier. The browser gives the random identifier and the real DNS name to your Yubikey. But, it has never heard of this combination, so, it blanks the entire authentication figuring this must be for a different Security Key plugged in on another port or something.
* It gets that identifier code for your login from Facebook, and then admits its real name to your browser and provides the identifier taken from Facebook. This still doesn't match, and the Yubikey again assumes it must be for some other Security Key on your system.
Behind the scenes this is actually done with AEAD cryptography, maybe with AES keys baked inside your Yubikey. The "identifier" is actually something like a private key (likely elliptic curve parameters) that has been encrypted using an onboard secret AES key in an AEAD mode, with the DNS name (well, a hash derived from it) as a factor.
As a result, your Yubikey can't even decrypt the "identifier" correctly in order to log you in without the matching DNS name. This means goofs in the implementation fail safe - e.g. one brand of cheap Security Keys can fail to sign in once every 256 tries on average due to a logic bug. But they'd never sign in where they shouldn't because of mathematics, to do that they'd need to "accidentally" completely break the mathematical foundations of the cryptography!
The browser will only give access to the Yubikey token for a specific domain name - so if the attacker phishes for examle.org, rather then example.org, then there is just no tokens (signing keys) available the Yubikey could use and give to the browser.
In the early days WebUSB in Chrome had bugs that allowed to bypass that same origin check but that has been fixed 3 years ago.
Just don't click on giveaways and never enter your secret code
1) Get on with their day to maybe hit a support request quota 2) Make sure this person doesn't give them a bad customer satisfaction score
I manage an authentication and identity provider and if someone gets locked out of 2FA and can’t prove their identity via a previously-uploaded gpg key, they get locked out for good. I never honor requests to reset the device sent by email, no matter how much they beg or offer to prove identity by sending copies of official IDs - I don’t care who they are now, I care about them being the same person that set up the account and 2FA, which can only be proven via a valid 2FA device or a GPG signature.
I'm not sure I trust that I'd be as good an attacker as a professional, and there's not a great way to replicate "hang up, call again" approaches likely to work with a big org.
Re-enabling the account after a certain period of time without activity would also be a good measure (on top of the id verification).
Here is a description how it works:
https://github.com/wunderwuzzi23/KoiPhish
Unless you use Yubikeys (webauthn) etc these phishing attacks just continue to work. I do consultancy in this space at times and about 95+% of folks who enter their password will also enter their MFA token.
I only use Facebook trapped inside Facebook Container in one Firefox on one computer. But my understanding is that it's possible to sign in to Facebook from say a phone and a laptop at the same time, so the bad guys could get you to give them working credentials one day and persist those until you're asleep before using them. If you went to Facebook's security settings "Where you're logged in" and it lists two logins, one in "Paris" while you are in New York, you might realise there's a problem and force them out. But most people likely never look at that, why would they?
I can imaging some variant of outlook.microsoft.developer.really.yes.com catching me unawares one day.
Isn't this vishing? https://youtu.be/BEHl2lAuWCk
Phishing SMS and TOTP codes is way more common than SIM-swapping. Outrageously so. SIM-swapping does not scale. You need to call up a company each time you want to do it. Yes, it works. But you cannot sell a tool that just automates it. In comparison, there are many off-the-shelf phishing kits that fully automate SMS and TOTP 2FA theft.
How exactly does this get executed? I'm pretty technical, but I cant fathom exactly how this occurs;
You hijack a cell tower, then have some system to listen to un-encrypted SMS traffic??
Plz ELI5
I've worked with a bunch of streamers and YouTubers, and the threat model is such that people have shown up with professionally made printed fake IDs to attempt hijacking in an actual retail carrier store.
No, not always and many password manager solutions do integrate with your browser and know the domain for the password.
Imagine a hash function that generates a number from the number of minutes since epoch hashed additionally with some seed. You have it on the server, you have it on your, say, phone. When you enroll you share a seed for the generator. Since your time is synchronized, the server knows what value(s) to expect, and the phone knows which value to generate.
The real scheme is a bit more involved: https://en.m.wikipedia.org/wiki/Time-based_One-Time_Password...
- You and I share a secret at my first login. Let's say our shared secret is "wibble".
- For any subsequent successful login with my username and password, for the second factor I send you the last six digits of the SHA1-hash of ("wibble" XOR current timestamp)
- You calculate the second factor yourself as well by doing the same operation (you have stored "wibble" for my username, and know the current timestamp), and verify those last six digits. If they are wrong, I am an attacker!
An accurate version: https://datatracker.ietf.org/doc/html/rfc6238
Like, what happens if I set my phone to a different time?
What if the server has lost connectivity to an NTP service and its clock is a few minutes off?
Some systems have some extra magic that allow the server to adjust for each device's clock skew; this was particularly important for hardware tokens that didn't have network connections. To imagine how that might work, suppose the server normally accepts responses that are valid at times t-2, t-1, t (the current time, per the server), t+1, and t+2. If a user consistently replies with the t-1 token, we know that her device is running slightly behind and we can instead authenticate against t-3, t-2, t-1, t, t+1.
The TOTP implementation for AWS logins is particularly prone to doing this for some reason, and you have to enter simultaneous TOTP codes to resync.
"a code from your hardware token/authenticator app on your phone/SMS/etc is not phishable"
That certainly seems like it's wrong, and doesn't include an acronym other than SMS.
But apparently there's more depth to this space than I was aware of.
"U2F/WebAuthn is secure because it does origin binding which is not phishable, unlike entering a TOTP or a code from your hardware token or authenticator app or SMS"
Putting the original parenthetical in between the start and end of the main clause definitely makes it easy to misread. I just moved the parenthetical to the end of the sentence.
The exchange between browser and key includes the domain of the site. It only works on the same site where registered the key.
(Note that most YubiKeys also support non-U2F modes, most commonly HOTP (HMAC(shared-secret, counter); counter +=1))
AFAIK some websites allow you to use the previous TOTP code for convenience for some more seconds. That makes the total time to impersonate you to be 30 (or whatever was configured while issuing the TOTP secret) plus the grace period websites allow.
Edit: formatting
It shouldn't matter, because it's irrelevant to the point of the article, which is that Facebook (at least as reported) leaves a hacking victim with little or no recourse to get their account, and sometimes livelihood back.
An imperfect real-world analogy of your question is like asking about what precise brand of bear mace an assault victim was or was not carrying, and whether a better one would have helped. Perhaps it would have, but that's not the point. If having hardware tokens is so important, Facebook should be making them mandatory at its scale.
How was the account hijacked? Via cookie theft. The author installed malware, maybe some dodgy windows binaries or malicious browser extensions. No amount or type of 2FA on sign-in will protect you against the session cookie being stolen. (Now, additional 2FA on sensitive actions might).
Why was the account was banned with such finality, with no chance of appeal? Probably for something outright illegal, like the hijacker uploading CSAM to the account. It's totally plausible that in an obvious enough case, the policy is e.g. to refer the case to law enforcement and keep the account disabled.
Why did the attacker want to get the account permanently disabled? Maybe an account disable doesn't stop ad campaigns on FB. So the attacker sets up an ad campaign, and then gets the account banned so that the owner can't reverse it.
Happened to me!
Account restricted from modifying ads. But yet the account kept going, spending money, and I couldn't stop them!
Thankfully I had a second admin on the account and was able to get back in.
Now I make multiple accounts to run Ads.
If you search, it's a common problem!
Whats infuriating is that FB want you to use your own FB account to run business accounts, and it's against T&Cs to make fake accounts.
But yet you can be attached to a clients account and get Ad banned for something they do!
Gah! The attitude of FB and Google is infuriating!
I haven't used FB in a while but I remember login from other places were detected.
IPv6 privacy extensions are generally considered a feature
I think that's quite likely. I have a (somewhat throwaway) FB account, not much of a profile and mainly used for a local cause. Co-admining a page I'd clicked on a clickbaity headline posted to the page and several days later my account was disabled.
The account recovery process was completely broken/circular but somehow the account revived itself after a week.
The fact that my 'friend suggestions' were untainted by a friends list seemed to confirm the hack as all my suggestions were from people in an entirely new continent.
Nd ads/CC attached to the account.
Did you ever use the password of the FB account anywhere else? You getting phished is also much more likely than a browser 0-day. Did you have a security key on the FB account?
No phishing.
I concluded that there's perhaps a cross-origin issue on Facebook's side that allowed cookie hijacking. The clickbaity link was almost tailor made for our group "[something ominous happened] in [your part of town]". Looks like it was auto-shared by someone whose account had been compromised as they were local. Reasonably confident it was a session hijack, my password remained the same while account locked.
The only other plausible thing wrt my account's case was that it was almost empty (i.e. no photo, no friends, not much to go by) and was somehow flagged but was given a misleading reason why it was.
That sounds much more likely to me.
When facebook has a website vulnerability that is exploited, they log everyone out, post a blog post, and makes big news:
https://www.wired.co.uk/article/facebook-hack-beach-single-s...
https://krebsonsecurity.com/2018/09/facebook-security-bug-af...
https://about.fb.com/news/2018/09/security-update/
>"[something ominous happened] in [your part of town]"
Those ads are all over. They determine [your part of town] through geoip or FB tells the advertiser your city. It's like the "singles in [your city]" ads.
And that being the plausible answer doens't explain why me as a Northern European post-ban-resurrection ended up getting all my friends suggestions from Africans. It was never the case before that and all my activity simply involved campaigning against losing a local park and looking at local news.
It's possible some people (or bots) from Africa viewed your page and no one else did in the recent past, and thus Facebook thought there was some connection between you and Africa.
In fact, Facebook has had numerous authentication blunders in the past. [1] One of them was a zero-click mechanism very recently. [2]
Facebook's security team is a joke, or worse -- they're muzzled by product teams and forced to do their bidding. [3]
[1] https://threatpost.com/facebook-patches-oauth-authentication...
[2] https://about.fb.com/news/2018/09/security-update/
[3] https://appleinsider.com/articles/21/04/22/facebook-dangerou...
That hasn't happened here.
I don't really consider 3 years ago to be very recent.
I think that 3rd link is arguably not a vulnerability. If you intentionally want people to be able to look up future friends by email address, then that's basically the desired behavior. Now arguably allowing people to look up future friends by email is a privacy problem. Some users probably want that feature though. Yes a lack of rate limiting is a problem, but rate limiting won't stop attackers from doing it, it just slows them down.
Ask yourself why Facebook doesn't just make available a spreadsheet of all names associated with which emails on the platform. It's because it's private information.
Why doesn't Facebook's security team do anything? Either they're incompetent, or they're being muzzled by product.
Additionally, Facebook's privacy policy explicitly says that they don't share your private information that you have chosen to set private. That's an egregious lie.
>In a statement, Facebook said: "It appears that we erroneously closed out this bug bounty report before routing to the appropriate team. We appreciate the researcher sharing the information and are taking initial actions to mitigate this issue while we follow up to better understand their findings."
https://arstechnica.com/gadgets/2021/04/tool-links-email-add...
I'm not sure whether you're just concerned with this apparent rate limit bypass vuln or with the entire concept of lookup by email.
>Ask yourself why Facebook doesn't just make available a spreadsheet of all names associated with which emails on the platform. It's because it's private information.
That would be Facebook telling you the email of every account. The behavior we're discussing is not doing that. Facebook allows you to find a person's profile given a person's email (assuming the person didn't disable that lookup it in privacy settings, and also considering rate limits which might be bypassable by a vulnerability). Facebook doesn't allow you do to the reverse unless the person sets email visibility to public.
>Why doesn't Facebook's security team do anything? Either they're incompetent, or they're being muzzled by product.
What do you think they should do?
Just because someone disagrees with you doesn't make them incompetent.
>Additionally, Facebook's privacy policy explicitly says that they don't share your private information that you have chosen to set private. That's an egregious lie.
What private information is being shared? Your profile URL? Your first and last name?
Facebook has an option to disable this lookup. Are you saying people are disabling the lookup and Facebook is disobeying that?
>Who can look you up using the email address you provided?
https://github.com/Niek/Niek/blob/master/facebook-scam/READM...
They want to link a new GV account to a real phone number that is not theirs, so that they can use the GV number for other scams.
It only works when your phone number doesn’t already have a GV linked to it.
Just a quick safety precaution to make sure: I'm going to text you a code, can you just send it back to me to confirm?
Thanks!
The attacker was probably trying to create a new Google Voice account forwarding to OP's phone number. They could then use the new GV account as its own "legitimate" phone number in order to engage in other scams.
(Alternatively, OP's password might have already been compromised, and this was the last stage of a targeted attack by someone trying to get into their account.)
I fell for it, but since I already had a Google Voice account linked to that phone number, it didn’t work for the scammer. But he didn’t realize what it didn’t work.
I quickly realized that something wasn’t right (and Googled the mechanics of the scam) and then was able to waste his time for another 30min.
The reason I fell for it was because they use a text message from Google in some African language, so I didn’t immediately realize what was going on. Still dumb to not pay more attention…
But it taught me to not list my phone number in the open on Craigslist.
When they figure it out, I receive threats ranging from reporting me to the authorities all the way up to killing me and raping my family.
I then point out exactly how their scam works, and that they are either criminals directly or working for them as patsies. At this point, they usually stop responding.
If they don’t, then I take the chance to vent some of my own vitriol at them. It’s usually therapeutic, but it’s always fun.
I have accumulated a lot of hobbies over the years, and I count this among them.
Those "3rd line specialists" can get really angry when they realize the unsecure but rich old man they are talking to is far beyond them in tech and have been having fun and recording them ;-)
This is why I commented on an article here some weeks ago that if they ever offered any paid user experience they'd be in trouble because they'd actually have to help their users with their issues.
These tech companies should offer actual support the moment you spend money with them with some actual recourse to solve problems, especially if it's caused by them. It's insane to me that they can just go and run away with your money or burn your account at a moment's notice, even when it's just some automated filter going crazy. At the bare minimum something like Amazon has should be the standard the moment you operate a paid digital software repository or sell a digital service or ads. Losing your investment should not happen to you unless you're a really blatant abuser and if you're the one getting abused your bank or credit card provider should never be your only line of defense.
I'm baffled that they have not been in any real conflict over this with any consumer protection agency for any of our governments.
Looks like it is time to remove all my Single Sign On from Google, Facebook, GitHub etc. And have individual user/pass for all of them. I have the same fear as you and way more so after reading this article, just way too much risk now.
Facebook has offered a paid user experience to Oculus users for several years now, and so far no one has forced them to actually help users with these issues. Not the market, not regulators, and certainly not users. They will keep getting away with it simply because they can. What are you going to do about it?
It's a stock android phone with no google account and no apps installed except for "SMS Forwarder"[1].
It is configured to forward all SMS to an email address via encrypted SMTP. This means that I can receive these 2FA codes anywhere I have Internet access - such as an airplane or newly arrived in a foreign country where my SIM card does not work.
The "2FA Mule" itself is plugged in at my office in a corner.
I'm not employing this for anything sensitive but it's interesting to consider that I can use SMS based 2FA while divorcing it from my day to day SIM identity ...
[1] https://play.google.com/store/apps/details?id=com.frzinapps....
If anything SMSs are much more dangerous than OTP and services should eschew them.
Sadly some of them still force you to have SMS.
>[...] via encrypted SMTP
In addition to establishing a secure socket, does the mule validate the mail server's TLS certificate name?
Will actually go this route in the future.
I also have it auto-answer 2FA calls and automatically hit the # key.
Yeah, call it not real 2FA, but it's really companies that choose to not use U2F are at fault.
One year at defcon - maybe 20 years ago - the speaker told an anecdote about a user who had set up a webcam and put their RSA token under it.
And we all laughed ... "haha what a dummy ... I can't believe users are so stupid" ...
But secretly I thought it was genius.
That's only stupid if anyone other than you has access to your webcam.
I keep a UK number for some 2FA systems, it costs about £0.10 per year. I just have to send an SMS every 6 months to keep the line active.
However, depending on how I choose to use it I can point 2FA for numerous different services to this one SIM. I just don't want to point multiple accounts at the same service to this SIM since that's a clear, common identifier and correlates those two accounts better than probably anything else could ...
- Yet, confirmer SIMs can't really be throwaways. I'm 'stuck' with a prepaid the same way people are stuck in to gmail — they have 400 accounts with the e-mail address.
I've had it before, where I got locked out of accounts, with no way to delete the account, or even do a data takeout. The only way forward has been the same SIM.
The only way forwards would be to 'start a SIM farm': buy those SIM slot AliExpress boards, and sell(/use) a forwarder service.
(here is business plan, on how risky, and expensive to the customer it'd be)
The 'challange' is keeping track of multiple people, to avoid same-site conflicts. Users would hopefully be encouraged to tell where they are using the phone, as to not get an used one themselves.
For Estonia, the minimum of keeping alive a prepaid is topping up 3€ every 6 months, per SIM (whereas new is 1€).
Of course, IoT numbers are available, but they aren't likely a valid option, as they definitely aren't meant for burners, and even a single misuse/complaint would likely shut everything down. More on this later.
Assuming there would be (monthly) paying customers, prepaids could do. It'd be a bit pricey, I'd start at ~10€/mo/user, assuming small users (few sites) would use the same sites, and larger ones needing many, many numbers. Billing per new site isn't likely very cheap either.
That aside, hardware is the most concerning, AliExpress pricing is 12-22€/slot depending on how bulk you go. Hundreds or even few thousands of euros in upfront needed. (Side note, on a >100 users scale, old phones etc aren't feasible; otherwise go with android dual SIMmers (using feature phone nokias for the price of nothing and stuff would be cool, but custom fw, and soldering each one isn't worth the time), and WiFi (on the scale WiFi stops working, you'll have bigger problems to deal with, and it'd be extra hardware cost as ell) (Side note 2: 'sim banks' exist, what allow to connect many SIMs to one modem, it'd bring the hardware cost to ~2€/sim, unsure if they can be online at once (though 'click here and wait 5-10s before clicking send SMS' could work for the user); even if they can be online, you still run in to the interference and 'why is there 1000 phones in this house' problem)
I'd say after a few hundred, it probably makes sense to start building them yourself.
For a good user experience, you have to keep them always online as well. Building a SIM-switcher would be likely as expensive, as well. The real concern is interference and infrastructure — having hundreds or thousands of devices in the same spot will not work well in physics, nor the service provider coming knocking.
Now, even small scale, it'd make sense to be your own service provider. This way you could get SIMs, and can connect directly to the network. You could emulate devices a this point, not needing any SIM cards either.
Problem is, all of your network activity is for SMS confirmations. That is going to get many strange looks.
The bonus of being in a small country is, that the other way, you can be friends with the person, who happens to be a head or person actually doing things, at a telecommunications provider.
Though, on a large enough scale, you're going to have actual overhead to their network. That's when you'll need to start paying for the service. Pricing for businesses isn't cheap.
**
Well, that was a wall of text. Insanities.
So — assuming you aren't a large-enough service provider already, normal long-term vEriFiCatIoN is deadly, assuming you need captchas on many accounts.
That should help against SIM swap attacks
Recent memory: 7-11 app and eBay both made me use a number that's associated with an actual SIM card.
I'm going to have to steal that.
This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the cost to most users - you can sell the headset, but you can't transfer the value of the library to anybody. That is a straight up and very significant financial loss.
While other aspects of the ban policy are obviously still very problematic, the fact that an arbitrary ban that is caused by actions outside the user's control can result in hundreds of dollars of losses sits at a whole different level and should be legally problematic for Facebook.
https://www.oneangrygamer.net/2020/06/steam-user-loses-game-...
Looks like this user received this message[0] after being banned from the community and only because he mentioned russian law did Steam suspend his account.
> Going to support and blalblab again my rights and the russian law, they slapped me with a perma community ban and 1 month ban to contact the support.
This incentivizes abusive behavior by users who want refunds, and cheapens the cost of abusive behavior. This mechanism was discussed in relation to OnlyFans somewhat recently -- creators that wanted to ban abusive "fans" had to refund them. (Unfortunately, I don't have a link handy.)
The problem here is that Facebook couldn't tell OP had been impersonated by an abuser -- as you say, "actions outside the user's control."
But I still had to buy a headset, put in a real credit card, pass Facebooks initial "real identity" checks etc. With real human review and some basic policies to prevent repeat abuse this doesn't seem like something that would really open a wide level of abuse. Perhaps sporadic situations where the headset breaks the user decides its the easiest way to get all their purchases refunded.
It's that brand new price Facebook would be refunding after a ban.
So the same perverse incentive exists even with a 2nd hand market.
Of course no one in their right mind would pay the retail prices for a "rental" so screws the business model, but honestly, they need to pick one, either they are selling products or renting them
This mixed model where they try to have the best of both has got to stop, if you ban my account you need to refund me, done want to refund on ban well do not sell me things, rent them to me under a service
In this case we can’t accurately identify cases where a user has legitimate cause for refund without false positives letting through a few abusive users.
The decision to be made is whether we skew the system to be in favor of the corporation or the consumer.
In this age where we no longer own the software we run I find it strange when people advocate for less protection of the digital goods they use.
1. Allow the user to play it's purchases, just without social features.
2. Refund the user
If this was the law they'd figure it out I promise you that.
it’s their decision to introduce this account, when there is really no need for it, let it be their problem to fully refund everything when this affects you. the solution is simple: quit forcing people to use the account nobody asked for.
The status who incentivizes abusive behaviour from the company, and cheapens the cost of mistreating users
If the purchases were < 6 months ago, I would do credit card charge backs...
But let them keep their hardware running, and access their game library.
Seems good for business, tbh. You might not want neo-nazis posting whatever they want on their profiles, but who cares if they're buying video games?
I guess we can’t be purist anymore but being pragmatic is still possible and you can divert funds away from FB this way to a company that cares about the headsets they sell and the user experience
And then people wonder why I'm never buying anything digital. That's the reason. Buying digital makes your continued access to the thing dependent on your account being not banned and the servers being up. In other words, even if you "own" it, you're still at the mercy of the seller. But if you bought something on a physical medium (or torrented), no one could take it away from you.
Remember people who used to have a huge collection of video tapes or CDs? They hardly used them for anything except decoration of their living room. Hoarding old crap that you never use isn't the best use of money.
Physical things can readily be taken away in divorces and debt recovery or less common things like police seizure if you're suspected of a crime. The world's richest man had half his wealth taken like that. Property rights aren't as secure as you think.
Sure, if one buys a newspaper, chances are that one won’t hold on to it for long. But it is important that one can. If one wants to cut out a story from it and hold onto it, perhaps in a scrapbook, one can do so.
It is also important for archival and preservation purposes.
People gather enjoyment from different types of things. Not everyone aspires towards minimalism.
If you're talking about Bezos, all of their wealth was made after they got married. The news can say it's "his wealth" but it always belonged to both of them. It's not "taking half his wealth," it's splitting their co-owned assets.
lets start with this
>The world's richest man had half his wealth taken like that
I assume you are talking Bezo's divorce, you might want to actually look into that if you believe that. he did not have half his wealth taken, far far far from it.
>Physical things can readily be taken away in divorces and debt recovery
That is not being "taken away" in the sense you are talking about in context, for debt recovery it is being "taken away" because you did not actually own it, the lender did, you do not own it until you have paid it off. I own my car, that means I have no debt on my car...
Divorce is not "taking away" it is splitting assets owned by multiple parties. Sure the process can been seen as unfair, however legally the assets is owned by both people, the courts then choose who the new owner of the asset is.
That is a far cry from what we are talking about in this context.
>Just think of it as like paying to see a movie.
But it is not, That would be like a Netflix Subscription, where I pay to access content, not pay to own the content. Ownership and Renting is different.
If they want to rent content there are methods to do that, however most people will not pay the prices they charge for a rental that is why they need to guise it as a "purchase" not a rental
>Remember people who used to have a huge collection of video tapes or CDs?
I used mine, then I ripped them (legally) to enjoy them on other technology... Sad you just used them for decoration. Probably should have spent money on something else you found enjoyable
Who?
It is perfectly possible for games to be sold digitally online with no drm, such that you could easily (without requiring uncommon technical know-how) copy it to a flash drive and run it on a computer with no internet connection.
Of course, games sold this way are extremely easy to pirate, because it is, essentially, pre-cracked. But one can distribute a product like this, and on occasion people do.
Does a master list exist of companies that don't use SMS, or allow the user to exclude it? Otherwise it seems like most 2FA is just opening up a much easier attack vector (social engineering a phone number port) vs guessing a long, random, unique password. A password manager with browser plugin (or iCloud Keychain) mostly solves the phishing issue if you stop a second to think on the rare occasions when you need to manually copy/paste because of a weird subdomain or partner domain.
I've been 'about to' set up 2FA for over a decade now, but it always seems like a bad idea.
Edit: Also, who's to say customer service agents won't/don't fallback to sending an SMS reset code even if the account supposedly requires a dongle or app for 2FA.
One possible point is that you could still log in somewhere that has internet but no cell service
The ones that let you configure a single MFA method or single with backup are usually where I run into issues, personally
For instance, on Github, I have 2x U2F tokens and paper recovery codes but there's not even a phone number configured on the account
Most people probably use it because it’s more convenient and reliable than SMS, not because it’s more secure.
All of these were obvious scammers directing traffic to a single profile - some forex guru or whatever. Shilling get-rich-quick schemes doesn't meet Facebook's definition of "spam", apparently.
What a garbage app.
> You anonymously reported ...
> You *anonymously* reported ...
> *You* *anonymously* reported...
"Greetings, human. We have masked your identity from... o̧u͢rs̢e͘lv́e҉s."
It's pretty scary. I think they're really willing to let facebook die off and just keep instagram and whatsapp, I think that's their strategy.
Even facebook dating is buggy and not worthy of a giant like facebook. Maybe it's the how GAFA will start to decline.
I was going to make the following point to the parent comment then read this reply and realized the situation is even worse:
1. (According to parent comment) 2FA can be disabled without 2FA
2. Having 2FA makes you look studious/thorough/decisive
Presumably the tech support is indeed told to pay attention to 2FA.
Presumably the entire management/instruction chain there isn't aware of the fact it can be turned off without 2FA confirmation, which effectively neuters it.
So you have the worst of all the worlds. Niiice.
DO IT. Please, do it.
While it's a damning write-up, words won't change anything. Lawsuits might.
Why is customer support so... unfriendly and unhelpful? No escalations possible? No way to reach anyone?
Facebook has such a MASSIVE user base. And people are getting accounts stolen a LOT, from either social engineering or password reuse.
But there's also a ton of people knowingly breaking rules, getting banned, and then trying to cry that their account was hacked.
Trying to differentiate between someone's account being taken over and abused versus someone just simply being abusive and lying about it to support costs a lot of time, and time is money. And with the scale of Facebook, that adds up to a LOT of money. You have to train a large staff to understand social engineering and be able to tell the difference between someone who actually can't figure out how to log in, versus a jealous ex who is trying to social engineer their way into someone else's account.
It's a lot cheaper to just let the bans stick, even if it loses a few customers.
If 0.1% have account issues in a year, that's 8,200 support tickets per day.
If each of those takes 20 minutes to resolve, then you'd need 115 support techs ... for three shifts, or about 350 total.
Oh, and covering several languages.
I'm guessing my 0.1% issue rate is low by a factor of 10--100. Resolution time may also be generous. Increase all other values correspondingly.
The Whatsapp purchase worked out to about $30/user, though proably factored in both further growth and the potential competitive risk.
An enterprise software company I was closely familiar with in the 1990s budgeted about $50/call for user support. Mind that was 20+ years ago, and it was enterprise, rather than end-user support. But odds are strong that one service call per user eats up all, or multiples of, the actual worth of that user to Facebook. Cutting the account loose may well be the rational choice for the company.
ARPU varies by region. Within the US it's closer to $110/yr, in Europe, $35/yr, Asia & Pacific, $10/yr. Expect that support offerings are going to be measured against that, though possibly with a consideration as well to future growth and economic development.
At $25/call and servicing 1% of users/year, that's $750 million in support alone. If the cost or rates are doubled ... the maths are pretty easy.
Probably some person randomly clicking "accept" and "deny".
Other question is, why there is no escalation; even paid one. Although probably everyone would escalate.
It's possible that's not true, but there's such an endless stream of these stories, that that's the attitude you have to take.
If your Google account is borked, nothing is unrecoverable from the computer and any other account can log into it.
That being said, you will be screwed in various other ways, mainly that all of the information you'd lose because it was normally stored on the you've now lost because you got the ban hammer
source: recently had to help someone get a developer account out of this position, account was reinstated. just gotta know the right people i guess?
this is the biggest example of all, to me, why big tech needs regulating... if you are going to take away access to things i paid for(or worse yet, my families livelihood depends on), you dang well better be willing to explain very explicitly why and provide me with a real person to appeal to. not some automated system(im looking at you too Google and Apple!)
As if this wasn't an obvious problem.
Relying on any of Facebook, Twitter, Instagram, TikTok, etc. for anything is a risk. Doubly so if it involves your business or a product that won't work without permission from $PLATFORM.
The only people I've heard have positive experiences with the Quest either:
- haven't had it for very long, or
- use Virtual Desktop or sideloading to break out of the walled garden. And are willing to frequently repair the issues that arise after frequent breaking updates.
I predict that gap in the fence will closed off and non-Oculus Store games will no longer work within the next two years and Quests will be junk. Please consider other options if you're thinking about buying oculus.
Thinking about it for a bit, I'm sadly hesitant that it might need to be built as a browser extension or mobile app, rather than a website, because none of these services provide programmatically-accessible (even read-only) feeds of what you're looking for, so you'd need to scrape everything. This brings up two issues: 1) the headache of IP ratelimiting (and/or flat-out IP bans from trigger-happy systems optimized for fighting fraud/bots hosted on cloud infrastructure). IIUC there are proxy services that you can outsource the workaround problem to, but this is awkward to get behind in the face of 2), which is that users would need to input their actual usernames and passwords so that the service could request the account page with the details on it in order to scrape the data.
Given that these are broadly web services poked at via HTTPS, you could potentially get everything you needed from a browser extension (as long as the service doesn't require you to set any HTTP headers that extensions aren't allowed to touch).
The second possibility is using an app. Writing a thin layer that lets you craft custom HTTPS/whatever requests from a WebView would probably be the most straightforward approach.
The main issue with both the extension and app approaches is that they code-dump both the idea and methodology of "here is how to do X" into the hands of the IQ-99 skiddie group (especially with an extension). So now you have more people running around scraping pages and whatnot and trying to figure out how to weaponize everything. Probably won't go anywhere (in terms of producing actual attacks), but the noise may potentially make your life harder.
The least-complex solution seems to just be a giant boring list of links, for example:
- https://myaccount.google.com/permissions
- https://twitter.com/settings/connected_apps, https://twitter.com/settings/connected_accounts
- https://github.com/settings/apps/authorizations, https://github.com/settings/applications, https://github.com/settings/installations, https://github.com/settings/apps, https://github.com/settings/developers, https://github.com/settings/tokens
Hmm, that's kind of all over the place for some things. A single aggregate view that combines everything could definitely be very interesting...
This guy’s story is why I try to split book and other media purchases between Amazon, Google, and Apple - so, if I lose any account I only lose about 1/3 of my purchases.
I guess they have data that shows this particular kind of user will almost never buy ads ever again, so at least let a scammer do it.
You're right, this is weird, but if you look at the profit model, it makes sense, and there are no laws that would really protect the user.
Any positives that come out of this for the author are just a Facebook PR move. If they did care about users, their support system wouldn't be so anti-user.
The sad thing is that this person actually is a customer because they bought a product and pay for things on it, but Facebook still doesn't realize that, or more likely these customers are such a small amount of their revenue they just don't care (and don't think it matters for growth of this area or don't care about that growth).
That's the reason the "you're not the customer" line is just a distraction.
It totally misses the point that Facebook doesn't have customers any more than any other first world power has. Facebook has treaties with governments and follow laws when it's less costly than breaking them.
FTC actions are like one country taking another to the WTO -- not something to ignore, but not really threatening either.
I don't think it is. If Facebook wasn't coming from a place such as that, then we wouldn't necessarily see them act like this. It's not just about size.
> Facebook has treaties with governments and follow laws when it's less costly than breaking them.
So do most large companies, but they don't all act the same to their customers. Apple may be guilty of other ways of mistreating their customers, but to my knowledge they're mostly innocent of this specific brand of it, and anything you want to attribute to Facebook's size that you can't attribute to any of the other tech big 5[1] should be examined for whether that's really the relevant underlying cause.
1: https://www.fastcompany.com/90651160/facebook-is-now-the-fif...
FB is super annoying when you want to separate the business from any form of a personal account. Eventually you need to have some sort of personal FB account linked to a business to manage some key ad buy things AFAIK, at the small business scale at the very least.
People valuing it sufficiently to choose an alternative (and most likely paying for an alternative) over the benefits of free access to an established network.
It's part of the business model - each FB user generates so little revenue for the company that you can't afford to offer anything resembling "real" support channels. The company is massively profitable by sheer scale - by making a small amount of money per year off of a vast number of users.
This applies to Google as well - or really any ad-based engagement-centric business. Your individual users aren't worth enough to have human-intensive labor assigned to them, hence heavily automated support channels and little to no ability to ever have something processed by a human.
One of many reasons I pay Google to host my email rather than use a free Gmail - when you are generating a non-negligible revenue stream suddenly companies' willingness to answer emails and pick up phones increases.
When it comes to FB there's often the pithy "when you're not paying for a service you're not the customer, you're the product" - which is a simplistic take. In this case though at the very least this is true: "when you're not paying for a service your support needs are dead weight".
If you think that does any difference, I hope you good luck. Google is unreachable for support, even if you are a paying user.
...They accidentally CC'd in a public mailing list into our discussion and leaked enough information that someone would be able to use the automated support system to change the company AdWords password. There was basically no way of contacting anyone further, the engineer couldn't contact anyone that could help us. We ended up making a new adwords account.
"Live chat, email or call us".
Last I checked, FB actively banned using their APIs to build a competing product. I wish the government would make it mandatory to offer federation if you had, say, more than a million customers. But alas, governments rarely do what's convenient for customers.
Google isn’t remotely comparable, and I believe Amazon has APIs for their store fronts / merchants (still can’t access reviews you leave)
Why do we treat government services and certain large private services separately? Why are government publications public domain, private publications not? Why does free speach apply to the government, but not to corporations? Why can't we treat amazon like a utility?
I believe the difference is because in the past people fought for these concessions from the state. They decided for example it would be sensible that the government should not restrict free speach. And before, they decided not to take feudalism as a given but to democratically elect their government. I know I'm being a bit dramatic, but there's no reason people couldn't get together and demand these kind of concessions from powerful corporations, too. Access to Amazon's product API is really the least example of what would change.
or what's in the long term best interest of their citizens let alone the rest of the world. Silly humans.
- Make a telefone-book style listing, or searching for "all metalheads < 25 near Chicago" where people entered that into their profiles -> OK
- Tracking users on your site -> OK
- Tracking users on third party sites, and then aggregating this data, so you can see "people who searched for baby carrages" or "people who bought diapers with their credit card" -> not OK
- Having some kind of database where people could concievably look up what user tqi purchased, searched, what their political affiliation is (when not made public) -> not OK (unless you have extreme auditibility, four-eye principle, and so on)
I think the data captured by CA was also entered for the purposes of sharing, (often) limited to friends and friends of friends. I think the crux of this all is that as a society we haven't really established how those rights are transferred. If I share my email address with a friend, can they share it with their contact management app? I'm not sure how you create a consistent policy in a federated model.
I'm well aware of "more is different" aka the dialectic transform of quantity in quality. Lots of data that in individually innocent can be problematic if somebody amasses it. But especially for this reason I think it is not good to have these kind of semi-public spaces where the data is public and the only protection is it is cumbersome to collect. Public data should be clearly public, and private data should be clearly private, and the UX should be really clear so people know what is happening.
(By the way, I'm not even sure CA was a "scandal" or that it was bad for FB. I think the only effect was that FB used it to justify locking down their API more.)
"He did?"
No, but are we just gonna wait around until Zuckerberg does?