How to get back into a hacked Facebook account
washingtonpost.com
washingtonpost.com
Then, despite my email account not being compromised, such that the person COULD NOT have gotten that code, facebook let them in anyway, let them change my backup phone number and email accounts, take off my phone number and email accounts, change my password, and fully take over my account.
What the hell was the point of that "code" if facebook let them in anyway? As the account no longer has my email address or phone associated with it, I can't recover it through those channels. I got the the point where you can send in a selfie with your ID, sent that, and got an email (with zero "case ID" or communication channel) that said verification normally takes 2 days. It's been over two MONTHS. So I guess there's nothing I can do?
On the bright side though, I don't scroll that much anymore. Maybe they lost a couple $ on advertising by loosing a user but I have regained a small portion of my time I spent there. The only real drawback is that I kept in touch with some people via Instagram only.
A situation like this makes you realise that an account in any of the FB owned companies can be taken away at any moment and you shouldn't get attached to it too much nor make it a single point of failure in your business / creative strategy. I'd advice to:
- Keep a copy of your data (contacts, content posted etc.) and try to diversify as much as possible.
- When using Facebook auth on 3rd party websites, make sure to have another method of authentication available to avoid getting locked out.
- Try to get phone numbers of important contacts so in the worst case you can contact them via iMessage / Signal / Telegram.
- If you have a large following, try to stream some of the traffic to other platforms too. If loosing one account means loosing your entire audience you're risking a lot.
In short - have a backup.
Suing Google apparently does the trick in my country. Google fails to respond? Police shows up at their local office, arrests some executives and makes them 100% available for comment.
https://www.nytimes.com/2012/09/26/business/global/top-googl...
I wonder why the US doesn't do this. Tarnishing an innocent person's reputation by associating them with rape they didn't commit is obviously criminal. They MUST fix it. Doesn't matter how much it costs them either.
They also get plenty of lawsuits over images in the search results. Lawsuits over celebrity nude photos have made the news before. They were removed. A local Facebook executive was also detained after the company failed to disclose the contents of encrypted WhatsApp messages to drug trafficking investigators. To me this was major proof that WhatsApp wasn't lying about its end-to-end encryption.
> The onus should not be on a small time individual to fork out tens of thousands of dollars on a lawsuit.
Agree. Government should always provide free lawyers really. Not just for murder cases. Otherwise, only the rich will ever go to court and seek justice.
Last I checked Facebook/Instagram/Gmail were free. If this had happened to someone with a paying Google Workspace account I'd understand but I hardly doubt willingly signing up to a free service grants you any extensive rights.
Anyway the laws I was proposing wasn't so much for free account closure, it was more for things like false search results, impersonation, account hijacking. These amount to defamation and psychological abuse and these companies are allowing it to happen without providing any human customer service fix.
Take that as a grain of salt.
Probability of having my 24 alphanumeric university alum account pw hacked:
|
Probability of me losing/destroying my phone/not remembering the right 2FA app/having DUO mobile fail: ||||||||||||||||||||||||||
About two months later I got an email saying my account access had been restored. With me doing NOTHING. It seems FB is simply using some sort of automated too long for hackers to care about or be profitable system to monitor account fraud.
I'm beyond caring at this point, but if for whatever reason I get Messenger stripped I'm in for a fun time to try and communicate with some of my west coast friends' group chats.
That would be a way to get the code. Wouldn't be too surprised if facebook was skimping on oversight.
Do you know what the behavior of the account was after takeover? Was there a clear monetization strategy (ex posting links, sending spam messages, etc)?
This is horrendous. I'm sad to see other people live through the frustration here, yet glad we're not the only ones.
It’s like the game that you can never win. So the only way to not be losing is not playing.
[1] I’ve always been able to reach a human being at Apple, so far, so I didn’t mention them. Even for help with out of warranty devices. That’s why the recovery/backup email with my domain registrar and mail host is my @icloud.com email. Earlier it was my Gmail account.
Right now my Gmail account is used in places where I even suspect I’ll get spam. I open it only when I am expecting an email i.e movie/travel ticket booking etc.
Though I’m not really sure what happens to this @icloud.com email if I own zero Apple devices at some point?!
It was tough because at the time I couldn't go to help him in person. And even when I finally could, it took months of waiting and even contacting an old college roommate at FB to help get it unlocked. It was probably 8 or 10 months later that he finally received an email and could go reset his password.
I really wish these multi-billion dollar companies would at least staff a helpdesk to field these basic issues. When these "free" services lock you out, you're basically left with yelling at what feels like a wall trying to get help.
For example, some sort of physical storefront (possibly run by an independent company), where you go and say I am so-and-so and here's my ID and please take my picture and my fingerprints so that if I'm scamming I'll be easy to catch and here's twenty bucks for your trouble.
I'd rather do that then spend weeks or months locked out, uncertain, and talking to a wall.
Privacy advocates won't be happy, but Facebook, Google, etc. don't have the same motivations as privacy advocates.
Also, they are not particularly easy to fake to a degree that passes spot checks, anyways.
They may be "free" to use, but Facebook is making real money off of every account, certainly enough to fund human help for critical issues like this.
I use Instagram only in a separate container in Firefox. I have no phone number connected to it. I tried to manually delete my pictures the other week. Got half way through before being locked out for suspicious activity. Message said account would be deleted if I didn't give them my phone number.
So, I bought a prepaid SIM card and proceeded with SMS verification. They told me I had to wait 24 hours. After 24 hours I got a message saying I was still suspicious and had to send a picture of myself holding a sign with my username. You could mistake this process for a reddit gone wild submission.
I'm done with Insta. Went ahead and deleted my FB account too, while I could still get in.
Asked me for my phone number. No way.
Goodbye, Facebook.
I lost access to my Amazon account. They want bills with my phone number on them. I don't have utility bills and I don't have phone service at the moment. I am an insignificant edge case and simply not worth their time.
And even if you're not a human, how would Facebook prove it?
And even if Facebook could prove that you are not human, what right do they have to deny you what they clearly claim is yours ("your" photos)?
First, if the terms of service didn't have any exclusion against a dog then absolutely yes it's reasonable to expect them to accommodate recovery when you do so.
Second, if the terms of service explicitly state that you own anything then is it reasonable that they deny you your owership? We're talking about HUMANS here. If a business states that you are not permitted to enter their building but you do so anyway, and in doing so you lost your wallet, then is it reasonable to expect them to return it to you? Yes it absofuckinglutely is. This is no different whatsoever.
Third, terms of services are not a contract because nobody reads them. A contract specifically requires that both parties understand and comprehend the terms of the contract. Websites provide services despite the fact that 99% of people do not understand the terms presented. You're deluding yourself if you think it's reasonable to think that everyone fully understands "Facebook is not a place for pictures of my dog".
Why shouldn't one crate an account for a dog?
Might seem silly to some and only have two followers but they have fun and it doesn't harm anyone.
Obviously you should routinely backup your data, yet here we are. Last year I noticed that most of the photo albums I shared on FB over the years just disappeared. They were not hidden by some app setting, nor temporarily unavailable, the data dump FB offers has no trace they even ever existed. The data was gone. I reported the issue but never got any answer. Thankfully I had the original photos on my old desktop. So when your data may randomly vanish, do backups, just my two cents.
You have to be careful how you use Facebook. I've gotten aggressive about blocking all from every single group and cute kitten post. Facebook is a great way to share pictures with my friends and family. For news, jokes, buying/selling, and learning about my hobbies it is useless (because the algorithm doesn't show me everything). As a rules, if it isn't something you wouldn't mark as personal information with limited distribution it shouldn't be on Facebook. (this also implies Facebook needs high security)
I don't think FB actually has a fraud system outside of "wait a long time" so its not worth it to hackers.
If you haven't logged into the account or the email address long enough that the email address domain expired. Then that's poor planning and isn't necessarily a problem with Facebook. I'd say most of my online accounts that don't have 2FA would be difficult to reset passwords for if I lost access to my email account.
If I signed up to a Facebook account and put my dogs name on it, how would Facebook ever know who human the owner is?
After a few days of trying filling out all sorts of weird forms on facebook that went most likely no where I came across an older reddit thread that says to try and go through Oculus.
Filled out a trouble ticket saying that when I tried to link my Oculus account with facebook that facebook had appeared to lock my account due to "Suspicious activity". They asked for my facebook information and for a picture of my Oculus' serial number or proof that it had been purchased and being shipped. Whoops, didn't have either. My friend on the other hand had a few and was gracious enough to send me his serial number, that did the trick.
Oculus said someone from facebook would be in contact within a week. That still hasn't happened (Been 6 weeks now). BUT, after approximately 3 days my account recovery options changed and I could choose 5 of my friends to unlock my account. Viola, I was in.
Not sure if it was spamming some of the "unused" forms or going through Oculus. But if you are desperate a friend with an Oculus might just save you.
This doesn't jive well with:
> Getting in touch with a human is rare.
It needs to be easier to deal with a human.
But I understand why it's hard to get to a human. Having humans in the loop is expensive and doesn't scale when you have a user count measured in the billions.
But you know what else doesn't scale? Trying to get all of your users to understand basic account security. Not enough people are using password managers. Not enough people are using 2FA. Too many people are falling for phishing campaigns and responding to silly posts like "Your porn name is the name of your first pet and the street you grew up on" and giving away the answers to security questions.
SSI is an interesting approach that has been slow to build up steam, but there are a large number of people developing it. It has some bumps and warts to work out still, but overall I think it's a workable technology, and definitely better than what we have now.
For more information see https://en.wikipedia.org/wiki/Self-sovereign_identity and https://tykn.tech/self-sovereign-identity/
Should a SSO provider ever stop working, you simply "reset their password". Send them a message to validate ownership of the account, then ask them to set a password OR authenticate with a different SSO provider.
----
These are the types of threats engineers _love_ wasting time analyzing.
Indeed, that design helps address the problem. But it also has implications for signup flow as you now need an email — which is why I'm advocating that engineers "consider" the issue.
> These are the types of threats engineers _love_ wasting time analyzing.
Sheesh, where's that hostility coming from?
Expecting ordinary users to make these kinds of decisions is unrealistic.
Apparently for her and her friends Facebook was the “safe” place to store photos.
Only 20 minutes after she got an email saying new login and it was to late. They had changed recovery info and no way to change it back. Only thing we accomplished was disabling the account.
Almost all of her friends have lost their accounts.
If Facebook is that lax with their own internal documents then I have to assume that their user account security is no better than at any company I've worked for as a software developer - which is to say completely non-existent.
As far as I'm concerned, anyone who uses Facebook, Instagram, WhatsApp or any other FB-owned company is as good as making all their information, including DMs, public.
Frances Haugen is being dubbed a "whistle-blower." The documents that she leaked have been damaging to the company. In addition to that, she said that she was expecting IT to flag her account activity and ask her what she was doing, but it never happened. So Frances herself described the access control policies as lax.
Security begins with risk assessment. You identify your assets and how they may be vulnerable. You then model your security protocols in accordance.
In my experience, this is almost never done. The typical approach to security is reactive, not proactive. And when proactive approaches are done, it is usually done with an eye towards covering the company's ass rather than giving the slightest concern to the interests of their users.
That's how I arrive at my conclusion. If Facebook takes such a lax approach to their own internal security that means they likely have a perimeter approach to security, rather than a layered one. They may try to block attacks coming from without but have little measures in place with regards to segregating, isolating and restricting once within.
All of this is speculative of course. Facebook might be the one single example of a company that actually takes some serious measures to protect their users' data while not being as concerned with their own internal data. I suppose such a unicorn is plausible. I just don't consider it very likely. I've never seen it happen once in my 25 years of industry experience.
If a Facebook employee is reading this ... I don't want to create a fake new Facebook account (which would be against the TOS, anyway). I want my own back.
Seriously, I am out. I didn't even bother to open a new one.
Before someone brings up Oculus: I don’t care. It’s dead to me. Any technology that requires me to have a FB account might as well not exist in my world.
(BTW, `facebook-delete -rateLimit 40000`, ie a 40 second wait between actions, is what it finally took to run without hitting rate limits and stopping after removing a few actions. I’m leaving it running in tmux until it’s finished.)
The only social media accounts I still have are twitter (locked down account, never post, use it to follow a few local businesses and local public figures), HN, and Reddit.
I'm also getting pretty close to pulling the plug on Reddit, the site feels somehow even more toxic and polarized than it did years ago. Although, that's probably also partially a function of me growing up and maturing.
I’m really torn on Reddit. It still has lots of good communities, but it’s so easy to pop over to something mean-spirited to get a little “I’m a superior person!” endorphin rush. I don’t need that in my life.
I still have and enjoy a Mastodon account. It feels like Twitter, but more chaotic in a good way, and with people being on the whole much nicer to each other.
Reddit and Twitter I already nuked last year. Trying to think of other things I can go and delete now, as it's quite cathartic.
Reddit has been read-only for me since the Digg migration so I lose nothing and give nothing.
Unfortunately, even the small subs that are just as good as the Reddit of old still have a time bomb of when the subscriber base grows to the point that the mods can’t stop the user base from spamming irrelevant IRL political discussion in the comments.
[1] https://web.archive.org/web/20171218060100/https://www.datap...
I don't think this supports the argument.
Found with Googling. ;-)
But there's still whatsapp and that now plugs into FB, and there's no longer an evolution to SMS and MMS, a way to message purely by having a phone number, no matter what account you have.
You can't opt out of this except by going totally off the grid.
After some discussion he told me that he did receive an email from Facebook saying that his password had changed, but the email didn't have a link to say "this wasn't me" to allow him to revert it.
I would then go through Facebook's account recovery processes on his behalf and it wouldn't recognise any of his email accounts as having been linked to that account. Despite it clearly being the email address associated, which lead me to think that someone had changed his primary email address on the account, something that again he didn't receive an email about, if this was the case.
I have tried almost all avenues, using his mobile number as an identifier, using his email addresses. It then says if these methods don't work, try finding the account using their name, so I found his account using his name and it simply keeps asking for his password with no other recovery options.
I am honestly shocked that I can get into the account. It's almost like Facebook has disassociated his account with any of his normal identifiers like mobile number and email address. Leaving us with no way of being able to recovery the account without someone at FB verifying his identify and flicking a switch on their end.
It turned out logging into Spotify some how re-enabled my access - my only guess is because I had a Spotify account before they were under the Zuck umbrella it somehow grandfathered me in
Didn't really make much sense, but I was very glad to get back into my account to chat to some old friends mid-pandemic
I started getting emails asking me why I hadn't been logging into facebook lately. I ignored them the way one ignores any such spam. Then over the years they got more specific. I got one of those do you know so-and-so emails for a person I'd only ever spent a single evening with. That creeped me out to the point that I password reset the account for my email that I never created and deleted it. Does that make me a hacker?