6 ms·
Not much more to say I am afraid. I get frequent (weekly, sometimes more) emails from Facebook containing password reset instructions "as per my request". At le
by callumprentice 7y ago
Not much more to say I am afraid. I get frequent (weekly, sometimes more) emails from Facebook containing password reset instructions "as per my request". At least two people have begged me to give up my account name (just my first name) that I seem to have got years ago - not sure it's even used or relevant anymore.
My initial assumption was that if they can't get the account, they would just try and mess it up for me.
On reflection it's probably unrelated and just one of those things.. I guess if they're reading this post, I'll find out soon :)
- umvi 7y agoCareful, people have been known to hire hitmen to get the name they want[1] [1] https://www.google.com/amp/s/www.theverge.com/platform/amp/2019/12/9/21003858/instagram-polo-rossi-lorathio-adams-ii-sentenced-14-years-domain-name-state-snaps https://www.google.com/amp/s/www.theverge.com/platform/amp/2...
- callumprentice 7y agooof! terrifying.
- jwilk 7y agoNon-AMP link: https://www.theverge.com/2019/12/9/21003858/instagram-polo-rossi-lorathio-adams-ii-sentenced-14-years-domain-name-state-snaps https://www.theverge.com/2019/12/9/21003858/instagram-polo-r...
- mirimir 7y agoHuh. I vaguely recall reading something similar, within the last couple years. Probably on HN, but not for sure. In that case, the victim did temporarily lose a domain. And the exploit involved taking over their email. Maybe use two-factor authentication with a third-party app? I don't know specifics, though.
- throwaway95273 7y agoI remember this story where someone temporarily lost their domain: https://susam.in/blog/sinkholed/ https://susam.in/blog/sinkholed/ HN discussion: https://news.ycombinator.com/item?id=21700139 https://news.ycombinator.com/item?id=21700139 But it did not involve an email takeover. Which story are you referring to?
- mirimir 7y agoNo, not that one, which I do remember. It was longer ago. And I don't remember any more about it. I only said HN because it's my main source for random reading.
- relm777 7y agoI get password reset emails on my account weekly too. What’s strange is it’s not a common email either, but one I use under my own domain. Not sure what the angle is? Like, I don’t see how requesting a password reset would help them exploit the account. Maybe they are just testing for flaws in FB’s system, still weird though.
- maxheadroom 7y ago>Not sure what the angle is? Maybe a new version of the directory harvest attack[0]? For example, if someone has an email address (or list of email addresses) from somewhere else, one can easily tell if you (or they) have a Facebook account by simply requesting a password reset against it (them). If there's no throttling on password reset requests, one could process a large list rather quickly. [0] - https://docs.microsoft.com/en-us/exchange/recipient-filtering-on-edge-transport-servers-exchange-2013-help#tarpitting-functionality https://docs.microsoft.com/en-us/exchange/recipient-filterin...
- callumprentice 7y agoOh - that sounds entirely likely. I'd be surprised if Facebook allowed unthrottled password resets but the bad people are so clever these day, who knows. Thanks for insight.
- callumprentice 7y ago> I get password reset emails on my account weekly too. What’s strange is it’s not a common email either, but one I use under my own domain. Interesting, thanks for letting me know - I'd assumed the same - hoping I'd click on the reset link perhaps and that would help them access my account.