11 ms·
It may not be Facebook themselves that caused the account reactivation. I'm was very recently in a similar situation having a Facebook account that was deactiv
by webignition 10y ago
It may not be Facebook themselves that caused the account reactivation.
I'm was very recently in a similar situation having a Facebook account that was deactivated about 5 years ago (I thought I had deleted it).
I received the exact same account reactivation notification email as in the article and I also started receiving photo post notification emails.
Upon attempting to sign in to my Facebook account to investigate, I was presented with a screen informing me that my account had been locked due to recent suspicious activity. In my case I did recall my password and as such didn't encounter the ID verification process.
I was presented with the details of the most recent login which was shown to be from a Samsung phone and from a Russian IP address. I have never owned a Samsung phone nor have I ever visited Russia.
My girlfriend's Facebook account was also recently accessed in similar suspicious circumstances.
I suspect that account credentials acquired from breaches of non-Facebook services are being used to attempt to access Facebook accounts.
- csydas 10y agoI would suspect a similar circumstance for the author's situation. Facebook does do some weird things to try to resume user engagement, but I've not really seen them re-active accounts on their own. More than likely it was password reuse resulting in a breach. The Author even considered that the password was checked by some automation against sites like haveibeenpwned, which makes sense to me to some degree for Facebook to be actively checking against, but they seem to dismiss this in favor of a spying option. I agree that having to submit a government issued ID seems a little incredulous for being able to deactivate the account, but as others have suggested, I'm not really sure how else the author can prove they are who they say they are. It seems that any such approach would be equally egregious to the public eye (i.e., anyone can make a fuss and shut down a facebook account), but certainly there must be some middleground, such as multiple authentications. A lot of the sanity checks used by companies are pretty unreasonable for most users to remember or pass - Microsoft and Skype, for example, have basically locked me out of my main skype account; their recovery challenge was to name the exact account names of 6 of my contacts as well as the the last two group chats I had been a part of. Since I hadn't used the account in about 2 years, this was really difficult for me, and the account names were even more difficult since people were using handles instead of real names, so the exact formatting was all but forgotten. Riot Games Inc. had similar methods, asking "what was the first skin you were gifted and who gifted it?" when my friend was trying to recover their hacked account. That was stuff that had occurred years ago, and we had no idea who gifted what and when. Again, I don't really pretend to have a good solution for these scenarios, but such solutions seem like they're just obstacles for the actual owner instead of neerdowells that overtake accounts.
- tokenizerrr 10y agoThe author clearly has access to the email account associated with the account. I don't see why they demand identification when they can just send a verification email, like literally every other website. What facebook is doing would make sense for a bank. They're not a bank. I know they think they are super duper important, but they're just another website that has no business demanding anyone's ID. Can you imagine the chaos once they get hacked and their ID database leaks?
- crottypeter 10y agoFor many third-party websites your facebook account is your identity, i.e. they are super duper important.
- csydas 10y agoThis is primarily why I'm a little torn about the "just send an auth" - Facebook, whether we like it or not, has wedged itself into a huge number of websites far beyond just the facebook domain. Surrendering control of a facebook account doesn't just let you mess with someone's social profile, it's potentially access to store accounts and much more. Whether or not people should be doing this is sort of irrelevant as the damage is already done and the situation is already entangled in Facebook's federated login.
- tokenizerrr 10y agoWhich in turn is just delegated to an email address + password combination. If the user controls that email, they obviously should control the facebook account, and everything else connected to it.
- Sir_Substance 10y ago>For many third-party websites your facebook account is your identity, i.e. they are super duper important. Correction, for many third party websites a facebook account is /an/ identity. If you closed your facebook account, what are the odds you're going to be using it as your openID login all over the place? Probably none.
- deleted 10y ago[deleted]
- wfunction 10y ago> I suspect that account credentials acquired from breaches of non-Facebook services are being used to attempt to access Facebook accounts. Given you more or less gave away the idea that you reuse your own passwords, if you haven't already, I suggest you start using a password manager and changing all your passwords to something random.
- oneeyedpigeon 10y agoThey did mention it was 5 years ago; password managers have become a lot more popular in that time.
- crottypeter 10y agoYou don't need to manage a password of an abandoned account. Just make it long and random.
- AstralStorm 10y agoTheoretically, it should require an email to reactivate an account. OP didn't get one I bet.
- crottypeter 10y agoOP did get an email. It's mentioned on line 4 of the post!
- webignition 10y agoI certainly didn't manage passwords very well years ago. I've been using a password manager for some time now.
- Quequau 10y agoThis would be less an issue if Facebook would forthrightly handle account deletion. As it is now it's simply not possible for a regular person to decide that they do not wish to further participate with any of facebook's services, remove their account and all the data associated with it, and be confident that all of the data collection, analysis, and 3rd party identification/authorization that goes on with active facebook accounts stops when their account removal process is complete. So no matter what any one individual does in regards to their unwanted facebook account there is always the possibility that something they would really prefer not to happen with it comes to be... like some hacker from who knows where gaining control of it and so adding another key element to their identity fraud dosier collection.
- joezydeco 10y agoI'll add my data point, since this has been happening to me as well in the last week. I've gone in three times now, made sure the account was "deactivated" (using quotes since we know it's not really ever deleted). And I'm still getting notifications. Something else is going on here.
- rmcfeeley 10y agoIf anyone knows what is happening, spill?
- nthcolumn 10y agoPossibly. Could we all help a guy by 'report abuse' the hell out of the account so it gets deactivated? That would be wrong - what if he isn't the actual owner? So you see the problem. Maybe fb need to make it easier for him to identify himself? But by means other than actually identifying himself? Well that is hard. He should tell his friends he is no longer in control. That would at least be a start.