3 ms·
They aren't aware of suspicious activity because they think OP reactivated his own account!
by crottypeter 10y ago
They aren't aware of suspicious activity because they think OP reactivated his own account!
- tokenizerrr 10y agoSo supposedly OP was allowed to reactivate the account without any hassle at all, but then to actually sign in ID has to be shown? That is even more ridiculous since that just leaves the account in a limbo state for no reason at all. Should have asked for ID prior to reactivating if going down that road.
- lazyjones 10y ago> So supposedly OP was allowed to reactivate the account without any hassle at all, but then to actually sign in ID has to be shown? That is even more ridiculous Try to think about it without all that negative mindset. Someone quite obviously obtained the (careless) author's password from a leaked user database of another site. They used it to log on to FB and reactivate the account. That isn't suspicious, because the last login IP address FB had is 5+ years old and having a different one now is not unlikely. Then, the author logged on with his IP address - which was suspicious to FB, because they thought the legitimate owner of the account had recently logged on using a different IP address (perhaps even from a different country). In addition, it took him several attempts to get the password right. Therefore, they demanded some ID.
- crottypeter 10y agoAnd yet GP suggests facebook should frustrate returning customers who log in first time with the correct password.
- tokenizerrr 10y agoSo their automated systems detected malicious access as legitimate access, and legitimate access as malicious access? And this is somehow working as intended?
- crottypeter 10y agoI'm not sure what you are suggesting facebook should do. They can't very well just assume all attackers will set the evil-bit now can they? https://en.wikipedia.org/wiki/Evil_bit https://en.wikipedia.org/wiki/Evil_bit The automated system has done "the right thing" and fallen back to manual verification when it detected suspicious activity. They can't request id for every activation or reactivation.
- tokenizerrr 10y agoThey assume their automated system can catch evil users in the act. It couldn't. It failed it's job and let the attacker do what they wanted while preventing the legitimate user from controlling their account. So the automated system did more harm than good. It should either be overhauled or disabled.
- crottypeter 10y ago> They assume their automated system can catch evil users in the act. Where do they assume that?
- tokenizerrr 10y agoThe system exists. If it can't do that, it has no purpose.
- ufmace 10y agoIt did that, in this one particular case. Facebook has what, hundreds of millions of users, maybe billions? No system anybody can come up with can handle every case that every one of those users will have perfectly. They have something that their experience leads them to believe is at least pretty good for most cases. They're not going to change it because it did the wrong thing for one guy. They don't even know right now that it did the wrong thing. Presuming the root cause is a login from somewhere else from a password DB, all they know is they have 2 logins with the right password from 2 widely separated places. How are they to know which one is the right one? Asking for a real ID sounds like a good start, but the author refuses to provide one. Understandable, I suppose, but how else can he prove that he's the real account owner and not the other guy?