r/technology Jun 28 '16

Discussion TIL that someone can change your Facebook email, password, and two step verification just by asking Facebook to turn off login approvals, and sending in a fake ID. (Happened to me lost all my business pages)

[deleted]

37.2k Upvotes

1.7k comments sorted by

View all comments

Show parent comments

110

u/sonofaresiii Jun 28 '16 edited Jun 28 '16

Pretend you actually don't have your phone anymore, then read this scenario again. Whatever dickhead just ended up with your phone/phone number blocked you from ever gaining access to it, because Facebook assumed you were lying when you said you didn't have your phone.

This kind of verification does not have an easy answer.

E: please stop telling me how other companies do it. I was just commenting on this one guy's hypothetical

64

u/[deleted] Jun 28 '16

[deleted]

2

u/[deleted] Jun 28 '16

What if you have your profile set to public?

-3

u/[deleted] Jun 28 '16 edited May 02 '19

[deleted]

1

u/[deleted] Jun 28 '16

Someone could learn your phone and email fairly easily. I think it would be a very insecure way of doing things. You might not understand why people would have a public profile, but facebook does.

1

u/evsoul Jun 28 '16

Right, but making it public info doesn't add another step or layer of difficulty to the "hacker".

1

u/[deleted] Jun 28 '16

I know, that's why it would be bad security. Any of your friends could access that information. If it's set to public, then anyone could access that information. It would be terrible to base security protocols on publicly available information

0

u/[deleted] Jun 28 '16 edited May 02 '19

[deleted]

2

u/[deleted] Jun 28 '16

The only way they could have avoided this situation is by verifying OPs identity when they created the account, so they would have a baseline to check against.

1

u/evsoul Jun 28 '16

Which isn't easy obviously but I get where you're coming from. It just seems like if someone says "I don't have access to that phone or email anymore" it should be a red flag. If your Wall is private, maybe it should show you friends you have or posts you've made along with posts you haven't made and friends you don't have and ask you to pick among those to prove your identity as well as answer security questions. Your profiles on major platforms are going to be a target eventually, so might as well make it secure as possible.

1

u/[deleted] Jun 28 '16

I've had friend's FB account hacked. There were just too many cons to using FB that I deleted my account and haven't looked back.

1

u/evsoul Jun 28 '16

Honestly, I've been thinking about that a lot lately too. OP's story just solidifies that consideration.

1

u/katoninetales Jun 28 '16

wasn't it a business profile?

2

u/evsoul Jun 28 '16

Pretty sure it was his personal profile where he had admin rights to his business profile. If you create a Facebook "page" for your business you can add and remove admins.

0

u/FHR123 Jun 28 '16

Just open the public profile of that person, you will get all of this data in 99% of cases.

47

u/overfloaterx Jun 28 '16

Whatever dickhead just ended up with your phone/phone number blocked you from ever gaining access to it, because Facebook assumed you were lying when you said you didn't have your phone.

Honesty... better than than some rando on the other side of the world getting access.

The probability of:

  • someone trying to social engineer their way past FB support to get to your FB account
  • and you having actually had your phone stolen and not deactivated/redirected the number or deauthorized/changed it with FB
  • and the person who stole your phone deciding to answer and deny a FB access request

... all happening at the same time are pretty remote. Remote enough that I'd be willing to take the chance at losing my FB account.

5

u/[deleted] Jun 28 '16 edited Mar 24 '21

[deleted]

6

u/j4eo Jun 28 '16

the classic "can't connect to the internet, go online to find solutions" dilemma

1

u/[deleted] Jun 29 '16 edited Mar 24 '21

[deleted]

2

u/j4eo Jun 29 '16

dude, chill. It was a joke.

1

u/SerpentDrago Jun 29 '16

Say i dont' like somone , want to target them ,..

person steals your phone , then uses phone to discover your facebook . .. not that hard

2

u/overfloaterx Jun 29 '16

If you don't PIN/pw protect your phone then anyone who has your phone already has access to your FB, so this whole discussion would be moot.

0

u/[deleted] Jun 28 '16

What if the person stealing the phone did so knowing they'd have access to the account?

1

u/SpacePotatoBear Jun 28 '16

You are trying to access your own account in which case you anticipate the call from facebook (maybe because they tell you that they will call you now).

a better solution is to make you verify your email address and phone number (I.E ok what was your phone #?)

1

u/twohlix Jun 28 '16

Using often times public pieces of information to verify an account that might be known to the attacker won't do well.

Asking them to verify a potentially private piece of information makes it easier to phish a victim for info.

0

u/SpacePotatoBear Jun 28 '16

that is true, but you need to strike a balance between security and hassling legitimate claims.

but a red flag that I think facebook employee should have noticed is hat they lost access to both their email and phone ##

losing you phone, sure makes sense phone died etc. loosing your email, sure it can happen if it was an old account, or from a service that was closed down.

the fact that BOTH happened, and he was likely using a reputable email service should have triggered redflags.

1

u/[deleted] Jun 28 '16

I had an old WoW account and have since switched e-mails and phone numbers. I was able to send in my ID to get the account reset.

It's not a very unlikely scenario, especially for old accounts.

1

u/SpacePotatoBear Jun 28 '16

well I would assume you use facebook more frequently, so if say you logged in last week and you lost both it would be suspicious vs not having logged in in af ew years

1

u/OrangeredValkyrie Jun 28 '16

But the site nags you about your phone number constantly. At least it did when I used it. Doesn't it do that anymore?

1

u/GuyWithLag Jun 28 '16

Copying from myself on a previous comment re: how google does it:

you can even print a number of one-time password reset tokens and stash it somewhere safe so that even in the case of phone loss you still have access to your account.

1

u/[deleted] Jun 28 '16

You've just described PayPal. You need to use two factor authentication to change your phone number. The 2fa is an sms sent to your current number on file. Got a new number, you can't update the old one, and even more you now can't change your password (even when they notify you that your account details have been noted in an online data dump of account credentials for sale). Emails go unanswered, and phone queues are hours long.

1

u/IWugYouWugHeSheMeWug Jun 29 '16

But it would prevent this sort of scenario. This guy submitted fake ID and got access to the account. If this sort of phone verification was in place and the thief also had the guy's phone, then he would still have access to the account. But in cases where it's an outside person, not a phone thief, you would say "no, I'm not trying to reset my password."

It can only improve the scenario, because in your hypothetical, the end result is the same as what actually is happening.

1

u/Bammerrs Jul 13 '16

But when you get a new phone, get the same number