I was banned because of a security flaw in Facebook’s password recovery system
zuckbannedme.com
zuckbannedme.com
It's ironic that Jeff Atwood phrased OpenID/third party logins as an internet driver's license. 10 years later, we've learned the pitfalls of such a system, namely that your login is at the mercy of organizations without customer support, and they can turn you off for no personally attributable reason.
https://blog.codinghorror.com/your-internet-drivers-license/
But yes, in 2023 you probably shouldn't use 3rd party authentication. You're much better off combining email/password login with a password manager, which effectively allows you push authentication on a 3rd party while retaining full control.
I feel like this is part of the reason we need real data protection laws in the US. There doesn't seem to be any downside for a company with lax security practices.
I intentionally don't let the clients integrate with the browser. I let the browser itself cache the unimportant stuff for convenience, and anything important I always paste from the password manager and have to get a code from the totp app also anyway.
I don't think anyone should use a fully 3rd party full featured password manager like lastpass or onepass.
I would say it is NOT better that they use that vs nothing. 'anything is better than nothing' is not true here. Some things are better than nothing, and some are not.
You misspelled "definitely" as "probably" here.
It's getting harder and harder to send email from your domain without being send to spam, bouncing, or the server just discarding your email without notice.
Currently using their lowest paid tier US$10/month, as that's 10k emails a month which is far more than we send. At least at this stage. ;)
Wish they'd occasionally look over the PR's submitted to their GitHub repo's though. ;)
All in all, it’s no different than delegating to your email provider to prove your identity via a password reset / login link.
But well, that may be too radical an idea to be executed. I'm sure privatizing logins is the way to go.
https://api.singpass.gov.sg/library/login/developers/overvie...
> MinID provides access to online public services at a substantial level of security (level 3).
> MinID is issued by the Directorate of Digitization and can be ordered from the year you turn 13.
https://minid.no/en/about-minid/
There is also BankID which we can use in order to log in to all public services.
> BankID is an electronic credential for secure identification and signing on the web.
https://www.bankid.no/en/private/
> Work on developing BankID as a joint infrastructure started in 2000, and the first customers got BankID in 2004. In 2014, BankID Norway AS was established. In 2018 BankID merged with Vipps and BankAxept in order to improve product offering and prepare for competition against global tech firms.
https://www.bankid.no/en/private/about-us/
I have both MinID and BankID and I can use either of them for things like taxes and such.
Statens Vegvesen, who are in charge of driver licenses and more, allow us to sign in with BankID and a couple of other methods, but not with MinID from what I can tell.
Norge.no, which is a guide developed by the Norwegian Digitalisation Agency, has the following to say about MinID and BankID:
> Electronic IDs are available at different security levels, and thus give access to slightly different types of services.
> MinID is at a medium-high security level ("Significant"), and can be used for many public services, but not for health services at helsenorge.no, for example.
> BankID, Buypass and Commfides, which can also be used for public services, are at the highest security level (“High”) and give access to all public services.
Estonia though has an electronic ID which uses X.509 certificates.
MinID is by the government. BankID is private.
> It's a proprietary application from a private company, owned by the banks, which only works on certain operating systems
If you want to use the BankID app to generate codes then you will need iOS or Android. But you don't need the BankID app to use BankID.
Instead of using the BankID app, you can use a physical dongle to generate codes.
The device that you sign in with needs nothing other than Internet and a modern web browser. You can sign in with BankID on Linux or whichever other platform you desire. This device does not need to run any proprietary code aside from maybe some JavaScript executed by the browser.
Very many years ago the device needed Java to sign in with BankID, but that has not been the case for many years.
So yes, you do need to use the BankID app, not just in case you "want" to use BankID, but in order to be able to log into some sites period.
One way of thinking about public vs private is, private companies are for cases where we care about efficiency more than fairness and government is for the opposite. Auth seems to have gotten to the "rural electrification" stage, where handling the corner cases fairly is more important than efficiency or innovation.
Uhm, not without requiring you to log in with the other auth as well - otherwise your account security is as weak as the weakest supported auth instead of the just weakest auth you added.
If the service notices that an account with the same email already exists, you may ask me to login with the original provider again to link the accounts, and indeed, this would probably be my favorite solution. Second best would be to just create a second account without complaining.
Playing fast and loose with authentication processes in the way you're describing is a guaranteed way to lose me as a customer if your service handles any valuable personal/confidential information.
What if tomorrow a vulnerability is discovered where, say, Facebook provides the new unverified email address rather than the previous verified address during the OAuth login flow? It would immediately result in an arbitrary account takeover on your website. There are so many possible edge cases with this setup and the surface area increases with each new auth provider.
My hope is it's a password hash or they forward the sign in request to MS servers, but who knows.
Edit: I was not done reading and realized he addressed this.
Or - you can opportunistically pick a time when you drive by and there's no obvious line out the door.
My account has now been "under review" since Saturday which means I can't log in, and my messenger, my fb profile and the associated businesses and groups that I manage have all disappeared from fb.
Having googled around my initial hopes that it will soon be resolved has flatlined: there seems to have been a surge of this lately and nobody that I have seen have had their access back (the reviewers have been fired?). I will likely loose my WhatsApp as well, judging by the reports.
Of course I realize that as an unpaying user of Meta products people might say "serves you right for being stupid". But I don't buy that. Fb is the de facto online directory of ordinary people (not counting much of the HN crowd as "ordinary" here).
It's totally unreasonable (understatement) that fb can effectively erase me and my online history and business without recourse because their systems leak and they don't have manpower who can do a human review of the facts in the case.
In the short term I'll be looking for other solutions, in the longer term I'll be supporting calls for making services like fb a public utility, with certain legal obligations (like not erasing online presences).
I've always wondered how someone who is locked out of a service like Facebook is supposed to delete their content.
Let's say that I'm a resident of some location with better-than-average digital privacy rights. If I can't log in to Facebook, how can I get my stuff deleted?
How do people handle this in places like the EU (or maybe California)?
Written requests to their privacy officer. datarequests@support.facebook.com
It can be a bit of a pain; https://ruben.verborgh.org/facebook/emails/2019-02-15-dpo/
HN isn't much better. I've emailed them asking for my data to be removed, as is my right as an EU citizen and dang simply refused saying it wouldn't be fair to other users. As if that overrides the law.
I think the part that bothers me most is that you seem to have firmly decided the EU regulators aren't real human beings trying to solve a legitimate problem in a way you disagree with. That'd be too respectful and humanizing. They're pure evil?
On the other hand, I agree with GP. It's surprising that you cannot delete an account. That HN stay "readable" without the [deleted] is clearly secondary to the possibility of having an account be deleteable. Imagine if I were part of an at-risk group.
Please read this in good faith: If you want your data gone, why do you keep sending more (posting)? Is it about retention time?
https://oag.ca.gov/privacy/ccpa
> Right to delete: You can request that businesses delete personal information they collected from you and tell their service providers to do the same, subject to certain exceptions (such as if the business is legally required to keep the information).
One of my clients willingly applies GDPR to everyone, regardless of jurisdiction. If you want your data, you can get it. If you want your stuff deleted, you can do so. I think this is the ethical approach.
> Unfortunately, our website is currently unavailable in most European countries. We are engaged on the issue and committed to looking at options that support our full range of digital offerings to the EU market.
Those US newspaper sites you can't access: well, you can access them via archive.org.
> Being accessible from the EU doesn't make your business subject to EU law. The EU doesn't claim universal jurisdiction.
Collecting data related to EU individuals does make you subject to the specific GDPR law though, unless I'm mistaken.
Nope, GDPR attaches regardless of whether you market in the EU/to EU residents, as long as you provide goods or services to people in the EU you're beholden to their rules.
Theoretically, a company that only offers services to US residents (mortgage/banking/legal) could still be beholden to GDPR, since their cardholders might access their website (i.e. be provided services) while in Europe, though as far as I know it's never been tested in court.
The EU has full jurisdiction within the EU, and zero without. The EU has no ability to demand action or inaction from an entity in the United States. They can ask all they want but it's just that - a request.
If it is PII then EU laws like GDPR apply, but if it is posts more generally then they are not covered, and it would be unfair to people who have responded to them and those reading those responses later (sans context, if your post were removed). The right to be forgotten covers information about you, not information by you (with an edge-case that if somehow your words in a post unambiguously identify you, that post falls into the first category as well as the second so is covered).
And meta (etc) make more than enough profit to not be this bad. It’s just that view ‘if I don’t pay, I deserve nothing’; that really should only be true if the company makes nothing from the service (aka a charity).
"All of our agents are currently busy. Please hold and we will answer your call as soon as possible."
Meta had $116,610,000,000 in revenue last year. It can find a way.
It's always so baffling to see people on HN rush to defend these massive companies, pretending that they're resource-strapped like two guys in a startup working out of a garage.
It's always so baffling to see people on HN parrot this line as if it was fact or truth, when it's far from either.
Yes, there are lots of businesses that exist only to make money. But there are millions more businesses that exist for other reasons. And, no, I'm not talking about non-profits. Kelloggs, for example, was founded to improve the nutrition of people at a health retreat.
The whole moustache-twirling moneybag-hoarding billionaire thing used to be a cartoon, because it was so misaligned with the reality of society. But in the Silicon Valley bubble, this has been turned on its head and elevated into some desirable goal, as if the only way to judge a company's value is by dollar signs. It is not.
(It wasn't even Silicon Valley that started this flip. It goes back to the 80's, as parodied by the character Gordon Gekko in the film Wall Street.)
2. Revenue is how much money company can spend on various things, they just need to prioritize which things are the most important for them. Facebook obviously do not prioritize customer support.
3. Recent layoffs mean then now have more free cash to hire support people :)
--
[1] For now at least. It is failing a bit and likely to fall off worse over time, that is why they are scrabbling for the next big thing (pinning their hopes on VR until something less “meh” comes along)
What is the issue?
Meta has announced a 40 Billion dollar stock buyback.
It's not like Meta is unprofitable or a starving scrappy small startup.
If, however, the support is of the "you've modified or cancelled my account" type, that should just be counted as part of the cost of doing business.
It's their problem to solve.
What prevents you from recreating a new account? When I left facebook I did a backup of it. Why aren't you making regular backups if your business depend on it?
> In the short term I'll be looking for other solutions, in the loger term I'll be supporting calls for making services like fb a public utility, with certain legal obligations (like not erasing online presences).
Public utility? Really?
If anything it is contamination and pollution that prevent decent options of having room to be the public utility of choice.
Just that they're held to certain expectations with regards to service, as critical infrastructure basically.
They shouldn't be able to terminate an actual human's account unless they can provide a damn good reason
Can we please stop blaming the victim?
Simply put every business will behave in this manner eventually if not subjugated by monetary penalty of state regulation.
That or you can scurry around every year to a new provider as the company you're doing business with is bought up by monopoly movers in the market leaving an ever decreasing pool of choices.
This is just a matter of common sense. The same applies to Amazon, Youtube, etc. Even if they're fine now they can and will unilaterally change their conditions and employ algorithms with false positives. Your business can become the victim of algorithmic discrimination and plain old bugs anytime.
Same thing with Amazon - it's been one of the easiest ways to sell. I listed my stuff, spent a little on ads, and things have just been slowly and steadily up and to the right since then. Even if they kicked me off tomorrow, I've still made good money in a very time-efficient manner.
It's one thing to say you should get Fastmail instead of Gmail, but to just say you should avoid using services that are valuable for your business because you might lose access later is cutting off your nose to spite your face.
EVERY direct-to-consumer ecommerce company buys Facebook and Google ads. Every single one.
Like Facebook - by which you mean Facebook, Google and Twitter, I suppose?
So what are you supposed to do, exactly? Hand out fliers door to door? Create your own social network?
These large corporations have inserted themselves into every single part of our lives as a gatekeeper. They believe that they have no responsibility to actually treat their clients with fairness, and they have made sure of that by having no way to actually reach anyone who can change anything. And yet for a small business, they have no choice.
The system was designed entirely by these big companies to make sure that these big companies could do exactly as they pleased, giving us no recourse except legal action.
What you are doing is called blaming the victim and it isn't very nice. Morally, ethically, _and legally_, this system is wrong. Facebook is the villain here, not this man who used Facebook in exactly the way they advertise to us to do so.
I've experienced this as well. Facebook seem to have gone through some lengths to insulate themselves from interactions with the public. They're now too big to trust with anything important to you. You'll get no support if you get in trouble.
Some months after a family member passed away, his Facebook account was hacked and the thief started posting stuff. It's been almost a year that I've been trying to close that account, or at least memorialize it. I've provided everything requested by their circuitous knowledge base to prove that the person has indeed died and even personal documents proving that we're related. For reasons known only to them, the help desk decided that something is missing. They wouldn't say what and just became totally unresponsive. There's no way to talk to anyone.
We sent multiple requests via their page and nothing. It is really really depressing.
SSO is handy for security until your SSO provider breaks or (as in this case) bans you. Given that most consumers have very limited recourse to fix issues with their account, I'd say that for most consumers they're possibly more of a risk than a benefit.
Imagine if one day Mr. Musk decided to kick everyone off of Twitter who didn't align with his politics or philosophy. Think of the millions of accounts that people suddenly got locked out of because they used "Sign in with Twitter."
These situations used to be so theoretical that they were dismissed as hyperbole. But it's a lot less outlandish a thought these days.
So fast forward to now, 4 years later. Maybe a last report was the final straw, and I've just received a notification that my page would be shutdown... And at the same time, surprise! My personal Facebook account gets deactivated too for violating community standards!
An automatic email notifies me that my account is deactivated, so I reply something like "please don't delete my account, all I did was post soup reviews that went against the deep state of soup reviews". Probably Facebook is also controlled by the soup-review-deepstate, because their next automatic email mentions that my account is now deleted.
So in that process, I didn't get to talk to any human, and my account created over 10 years ago gets deleted along with all my Messenger history, and thousands of memories.
But in the end, I'm not unhappy: at least I won't lose anymore time scrolling on that hell of a an empty network.
The problem is not, that a false positive happens, or the user does get locked out by an algorithm, etc. - that sort of thing is impossible to avoid entirely. You have to stop bad actors, and you'll never be 100% accurate with that.
Imho the big problem is, that people who get locked out wrongly, have no recourse. There's no support, neither free nor paid, no avenue, absolutely nothing they can do, to get help. THAT's the problem.
People have to resort to trying to go viral, because only then their problem will get fixed.
As a company, that's probably not what you want. To see your false positives cause waves all over the internet... You'd probably want to see those problems be solved silently. But that would require that you offer an avenue for the user to get their problem solved quietly - doesn't it?
In this specific case, if keeping the account for a longer time had been the goal, the bad actor wouldn't have gotten the account suspended immediately by violating the Terms of Use, nor would they have used a Vietnam IP to do so.
Secondly - whenever such a thing does go viral, and Facebook comes under pressure - they all of sudden become very able to tell:
- that the person who has been using the account for years without incident, with an US IP address, who can provide 2FA codes, controls the original sign-up email, can produce credit card statements for payments the account made, sent in a copy of their drivers license, is probably the good actor
- that the person who (within just a few hours) reset the password, changed the email, disabled 2FA, and caused the suspension - all from a Vietnam IP - is probably the bad actor.
Facebook doesn't have that problem because they are unable to differentiate between bad actors and good actors... Facebook has that problem because they don't want to differentiate good and bad actors - because that costs man-hours and thus money.
The support teams dealing with that stuff are probably under-staffed, under-paid, lack the tools/knowledge for deeper investigation, and are being pressured to close as many tickets as fast as possible.
Since that account should still have alot of photos for us, I'd really appreciate if someone from meta can help us recover it. I wrote on HN asking for help back then: https://news.ycombinator.com/item?id=21234651 .
How does a government agency even allow something like "sign in with Facebook"? Sure it's convenient but this case shows why this is stupid. Also, isn't this a privacy issue? I'm not an american but it baffles me that something like this is possible.
I've been unable to add my main email address in Facebook because "The account that owns the email address you entered has been disabled.". If I check my emails history, apparently someone named "Kyle" (not me) tried to create/activate an account in 2016 and now I'm prevented to use it... Forever?
Class action might be possible as well
Indeed: https://www.shuchow.com/so-i-took-a-huge-corporation-to-arbi...
For example, I created my account before there was a TOS, and FB used easily-bypassable ways to get users to agree to a TOS, and eventually they stopped asking me, leading me to believe they think I agreed. Without my wet signature on anything, how can they prove I agreed to something when they can just flip a bit and claim their records show I did?
I guess the user would get a notice that FB/Meta filed something and that they could respond saying that's not true?
If you live in the US, it turns out that EULA (which TOS are a subset of) are completely valid: https://www.canlii.org/en/commentary/doc/2006CanLIIDocs118#!...
The argument that you provably never read the EULA is apparently no form of legal defense, which I personally feel shits upon the letter and the spirit of the law, but that's an unfortunate consequence of living in a society where business is the pinnacle of everything.
Now I live in Europe and that sort of shit absolutely doesn't fly here - EULAs are not enforceable.
Right. Keep in mind this is civil court so the standards of “proof” aren’t the same as criminal court. The judge only has to believe you more than them. It will be an uphill battle though because the judge probably doesn’t want to hear the case. They’re going to want you to try arbitration first.
"I've repeatedly tried to organise arbitration, however Facebook is refusing to do so."
So you don't know if your gmail account was hacked or accessed? I would be worry about that.
None. This company that "connects the people of the world" has no email, phone, chat...nothing. It's not like you can talk to them yet they won't listen, no...you can't talk to them at all.
This specific example is especially criminal, as the person is a paying customer (invested in ads).
When attempting to log in, my password was not recognized. I successfully reset my password, but upon logging in I was presented with a validation prompt demanding I get several people to vouch for me, from a selection of 6. Only problem was I only knew one of those people.
At that point my entire profile vanished from FB. Friends and family no longer see me in their lists, even my wife. There's no way to contest this or get support, so I vanished.
Later I found out an astroturf profile of me was created, but its not me (I have a globally unique name). There's no way I will ever use a Meta product or account in the future based on this experience.
My situation was unique because my Facebook account administered the pages of government agencies and they were very helpful in putting pressure through back channels to get it sorted out. It still took over 30 days after they acknowledged that they dropped the ball to get the account back, and 60 days to get everything back and running.
But I'll pass along this link to my AG as they're collecting stories like this, and there's hundreds we've found so far.
The first time around I got unbanned after several days, sending them my selfie etc.
The second time is now. They require phone number to send me a code, so I can „ask them to reconsider”. But I don’t receive the code. After several tries the page says „too many requests, wait 24h”.
I obviously have 2FA using authenticator. Got no other email than „you got 30 days to take action”.
The only reason I’m even trying is messenger and a few sad groups that are funny from time to time. Meh.
I don't mean to blame the victim; it's clearly not his fault. But placing so much reliance on a provider of free services that lacks a proper support channel, isn't a great plan. I also note that the author relies on gmail - which has very similar problems.
And yet the first person you blame is... the victim.
Blaming the victim is in fact defending Facebook.
> I also note that the author relies on gmail - which has very similar problems.
And your solution is... what?
For two decades, I ran my own mail server, just for this reason. I finally gave up this year, because Google finally made it impossible for me to deliver email to them no matter what I did.
I resent it bitterly.
Well, like you, I ran a personal mailserver for nearly 20 years. Initially I had trouble delivering to gmail and Hotmail; those problems resolved themselves after a few years. My ISP now hosts my mail, using the same infrastructure that I used to use: Postfix, SpamAssassin, Dovecot, Sieve. I use my own domain.
Obviously email isn't the same as social media. I never liked the social media landscape; I've always seen the internet as fundamentally distributed, and I always regarded MySpace/Facebook et al as a trap. I have an old Google account, but I never use it. Otherwise the only social media account I've ever had is HN.
I'm not in business, I'm not selling anything. Also I'm rather reclusive; I don't need a large circle of friends, about three has mostly been enough for me. So I'm not like everybody else, and I can see that for some people, there isn't much alternative to the giants.
I'm against designating them "critical infrastructure". That would simply deepen the moat. If they really are critical infrastructure, then they should be provided by the government. What they do that's useful isn't hard; what's hard is the part that isn't useful - advertising, and constant user-engagement.
I think something like Mastodon probably has the potential to defeat the giants. It's truly distributed, and not under central control. Mastodon seems to be designed as an alt-Twitter, based on short messages. That doesn't suit me, but I expect something like a long-form Mastodon will rock up sooner or later.
Regarding victim-blaming: this is like making a deal with gangsters. I have every sympathy with the victims; but if you place your business in the care of a giant, with no proper support channel, that don't take money off you for the service, then your only recourse is to ask for your money back (i.e. zero). You can't even sue for breach of contract. That's an extremely squishy foundation to build a business on.
Facebook has lasted rather well; Twitter seems to be going down the tubes. MySpace died a long time ago. But Facebook will fade away - they all fade away. What lasts isn't websites and services; it's protocols.
Yesterday my account was suspended again for the same reason and was unblocked today.
I use a password manager and 2FA so I doubt someone managed to access my account.
I’m afraid to definitely lose my account
I gave up on it for two years - finally, I reached out to a friend of mine who literally just started working there (I’m 19, he’s 21), and he raised an internal support ticket which generated temporary 2FA codes for me in 6 hours, and I was back in my account. Actually shocking how much nepotism can help you solve these problems.
Good luck OP.
I just refuse to be forced into someone's idiotic security requirements that completely forego any other considerations user may have, other than this stupidly absolute focus on security.
Every time I imagine this glorious new world of webauthn replacing everything... it's just not appealing. I lose the HW key, so I need to buy a new one. I can do it online, except I can't because I need the lost HW key to confirm the card payment or login to my bank account and initiate a transfer. I have to go buy it to some physical shop or pay on delivery. Most don't carry it. Now this happens on a vacation, where it's generally easier to lose things, and gerneally impossible to buy things like HW security keys.
It would be possible to have a SW based solution, by emulating the USB FIDO interface, or whatever, but I really don't want to get locked into a solution where there's a constant threat that some services will just start requiring HW key attestation.
So, no. Security is important to me, but so is reasonably doable disaster recovery not requiring anything more than an internet connected computer and things I can remember.
This is why I will never use gmail. Yeah - my current email provider might scan my mailbox, but it will not ban me for saying something wrong on youtube or twitter.
And I never post anything on facebook to not lose access to my VR headset.
I would expect governments to step in when a flaw like this is detected. It could ruin thousands of lives.
It's not "could". It has ruined thousands of lives. How many depressed people out there have had their last little connection with humanity severed because of a dumb algorithm? How many small businesses have died because a random business account was shut down overnight with no recourse? I'm convinced that there's been at least some suicides over the problems caused to peoples' lives from the deliberate decision to not provide human customer service in some fashion from these Silicon Valley giants.
The really infuriating part is that this isn't even a selfish decision about money, which would be evil, but at least understandable on some level. Customer service can be revenue neutral or even a profit center if these companies were willing to charge a fee for actual good, human support to resolve the most important issues.
They already decided if the user should be locked out if some set of circumstances occurred.
The author claims that he was permanently banned from all Meta products (including Facebook, Messenger, Instagram, and WhatsApp) due to a security flaw in Facebook's password recovery system.
Despite having two-factor authentication turned on, the author believes that his email password was compromised and there is a backdoor to disable 2FA after a password reset request.
The author has tried to resolve the issue and appeal the decision with no success and has lost his personal and business accounts. The author suggests having a backup admin for your Facebook page, and he has found other instances of similar bans happening to other people.
The text ends with an update, where someone from Meta reached out to the author on Reddit to help resolve the issue.
Which, given that the report here is anonymous, seems at least not implausible. There's a real name in one of the screenshots, but a quick search doesn't find any other content associated with it.
Folks need to recognize that this kind of content, presented without verification, tends strongly to be one-sided and at least partly misleading.
What other content would you like to find with my name on it? My website, jcforbes.com (which currently has nothing on it)? You could search my name with the NC department of commerce and find my business name easily.
I presented all evidence in form of screenshots... exactly what do you think I'm hiding?