4 ms·
The request for ID is certainly not standard across all accounts and situations. My guess: the account reactivation came from a different location than OP's hom
by developer2 10y ago
The request for ID is certainly not standard across all accounts and situations. My guess: the account reactivation came from a different location than OP's home country/state, or OP themselves moved states/countries in the past 5 years. The account being reactivated from a different location would certainly be cause for alarm. This would be a reasonable check in my book, as it is the best way to fight against compromised credentials - you know, the exact situation OP finds themselves in for having reused their Facebook password on other (previously compromised?) sites.
What the OP doesn't seem to understand is that the attacker may have been able to technically "reactivate" the account, but they also probably can't actually gain access until they provide ID. This ID requirement has likely saved the OP's account from actually falling into the attacker's eager hands.
OP is complaining about the privacy implications of a compromised reactivation by an attacker, and sour they are being asked to prove that they are not the attacker. Take off the tin foil hat, stop crying foul, be grateful Facebook seems to have saved your password-reusing ass, send them the ID, and then delete the account instead of deactivating it.
- awinter-py 10y agoemail verification would have also stopped reactivation in this case.