4 ms·
I'm not sure what you are suggesting facebook should do. They can't very well just assume all attackers will set the evil-bit now can they? https://en.wikiped
by crottypeter 10y ago
I'm not sure what you are suggesting facebook should do.
They can't very well just assume all attackers will set the evil-bit now can they?
https://en.wikipedia.org/wiki/Evil_bit https://en.wikipedia.org/wiki/Evil_bit
The automated system has done "the right thing" and fallen back to manual verification when it detected suspicious activity. They can't request id for every activation or reactivation.
- tokenizerrr 10y agoThey assume their automated system can catch evil users in the act. It couldn't. It failed it's job and let the attacker do what they wanted while preventing the legitimate user from controlling their account. So the automated system did more harm than good. It should either be overhauled or disabled.
- crottypeter 10y ago> They assume their automated system can catch evil users in the act. Where do they assume that?
- tokenizerrr 10y agoThe system exists. If it can't do that, it has no purpose.
- ufmace 10y agoIt did that, in this one particular case. Facebook has what, hundreds of millions of users, maybe billions? No system anybody can come up with can handle every case that every one of those users will have perfectly. They have something that their experience leads them to believe is at least pretty good for most cases. They're not going to change it because it did the wrong thing for one guy. They don't even know right now that it did the wrong thing. Presuming the root cause is a login from somewhere else from a password DB, all they know is they have 2 logins with the right password from 2 widely separated places. How are they to know which one is the right one? Asking for a real ID sounds like a good start, but the author refuses to provide one. Understandable, I suppose, but how else can he prove that he's the real account owner and not the other guy?
- tokenizerrr 10y agoBy controlling the email account that was used to sign up. This is standard practise and quite simple.
- AstralStorm 10y agoWhy not? Deactivation and reactivation is a very rare activity that warrants secondary authorization. A simple confirmation email does the trick most of the time.