Facebook sees 600,000 compromised logins per day—0.06% of all logins
arstechnica.com
arstechnica.com
Every time this happens, we don't let the suspicious login into the account, and instead make them pass some additional authentication challenge. Often this involves a "social captcha" (see http://lifehacker.com/5743872/facebook-experimenting-with-so... or https://www.facebook.com/blog.php?post=486790652130), which basically tests that you are the account owner based on the shared knowledge of who your friends are.
Accounts are often compromised outside the facebook ecosystem (via phishing, malware, sharing their password with a site that was compromised, etc). I think the fact that we catch so many is actually pretty awesome.
A more-accurate (but less link-baity) headline might be "Facebook prevents 600,000 compromised logins / day."
I just think we do pretty well against many attacks.
I'm assuming a "login" is the specific act of typing in your username and password into the site to authenticate into a specific account - pertinent here because we're talking about people logging in with compromised credentials.
When I visit Facebook, I'm usually cookied and so to me that isn't a login. If I had compromised the account I wouldn't consider myself 're-compromising it' just by visiting it again with the cookie already in place.
Maybe this is just semantics but seeing as we're making a headline out of a stat, it seems worth drilling down on.
Nope, we have 800+ million monthly active users (logged in w/i the past month). On one day, we had 500+ million active users in a single day. Though I don't know the exact number, it's probably safe to assume that not every account was logged into in the past month (people pass away, etc.), so the number of accounts is probably larger than 800 million.
They have more like 500 million active right now.
Even my 80+ grandmother is on Facebook and she doesn't even own a computer, but she check it every week at her friends house. And get this she is thinking of getting a computer to use Facebook (and find recipes and knitting patterns).
Most people I know check Facebook every hour or some leave it open all day long. Many have IM hooked up so they can chat at will. So login rates are far as I'm aware are very high for the average person. I do hear the odd person who doesn't log in very often but I can stereotype them as grumpy sys admins who tend to hate everything and probably don't have the critical mass of friends to make facebook useful anyway. Because in reality it is a useless service if you aren't a people person.
Anyway thats a penetration level I can barely fathom, and from what I understand my experience is actual the norm and not the exception.
If you look at the metrics people pull out every so often, Facebook alone is larger than the entire internet a decade ago. One website is BIGGER than everything. How ridiculous is that? to be that big they could only do it with numbers which analysts are suggesting.
Assuming we = you work for FB, can you help us out with what a "login" is defined as internally, given that the stat is 1 billion logins a day and you're saying you have 500+m active users.
...does that mean on average every user physically logs into the site (username + password) twice a day?
(I work on the team that does these classifications.)
PS: Ok, 1-(1-.0006)^(2.5 *365) = 42% but that's still terrible odds IMO.
And I don't think anyone is saying that any number of compromised accounts is a good thing. I question how much control Facebook has, though, given that many people will inevitably have passwords such as "abcd1234."