17 ms·
It's probably worth clarifying that a "compromised login" means "you know the username and password for an account, but we suspect you may not be the actual acc
by mkjones 15y ago
It's probably worth clarifying that a "compromised login" means "you know the username and password for an account, but we suspect you may not be the actual account holder." Basically, knowing someone's username and password is not enough to get into their Facebook account.
Every time this happens, we don't let the suspicious login into the account, and instead make them pass some additional authentication challenge. Often this involves a "social captcha" (see http://lifehacker.com/5743872/facebook-experimenting-with-social-captchas-for-authentication http://lifehacker.com/5743872/facebook-experimenting-with-so... or https://www.facebook.com/blog.php?post=486790652130 https://www.facebook.com/blog.php?post=486790652130), which basically tests that you are the account owner based on the shared knowledge of who your friends are.
Accounts are often compromised outside the facebook ecosystem (via phishing, malware, sharing their password with a site that was compromised, etc). I think the fact that we catch so many is actually pretty awesome.
A more-accurate (but less link-baity) headline might be "Facebook prevents 600,000 compromised logins / day."
- Joakal 15y agoI don't believe Facebook was able to prevent someone who knows enough of that person (eg Palin attack). Or am I misunderstanding you?
- mkjones 15y agoI don't know the specifics of that attack, and I'm not claiming that we have 100% recall. I just think we do pretty well against many attacks.
- notahacker 15y agoProbably the most common compromising of user accounts is friends borrowing users' computers or mobile devices whilst the user remains logged in. I'm not sure whether Facebook does much to prevent this, although I'm not convinced it's reasonable to expect them to do much either.