4 ms·
I'm curious what you mean by that. I work on security at Facebook (and actually help with the system that detects malicious logins), and think we have a pretty
by mkjones 14y ago
I'm curious what you mean by that. I work on security at Facebook (and actually help with the system that detects malicious logins), and think we have a pretty good / secure login system, even compared to a lot of banks.
The odds of a phisher who knows a bunch of valid Facebook credentials getting into any significant percent of the corresponding accounts are pretty low.
EDIT: If you want more protection than this, you can also turn on 2-factor authentication for your account, with "Login Approvals:" https://www.facebook.com/settings?tab=security§ion=approvals&view https://www.facebook.com/settings?tab=security§ion=a.... I don't think I have the ability to do this at login time with my bank (though they do offer / require it when taking high-risk actions like initiating transfers).
All that being said, you're absolutely right that sharing passwords across sites is a bad idea.
- tnorthcutt 14y agoThanks for the two factor info and link. I wasn't aware that was available.
- mkjones 14y agoGlad it's helpful! If that's too hardcore for you, check out "Login Notifications" as well (on the same page). This sends you a text whenever someone logs in from an unrecognized browser (but allows the login).
- deleted 14y ago[deleted]
- tnorthcutt 14y agoThanks for the two factor info and link. I wasn't aware that was available.
- statictype 14y agoAlright - It's nice to know that Facebook has an industrial strength login system. Nobody would know that unless, like here, someone like you chimed in to mention it. (And thanks for that) My point was more that - as a user you should not expect a site like Facebook (or Twitter or FourSquare) to spend as much time firming up their login system as you would your bank. The fact that you actually do so is a nice bonus. But users would be well-served by not expecting the same level of attention to security from social sites and treat them accordingly. (And sorry if I came off as being unfair to Facebook. I meant my comment to apply to that genre of sites in general)
- mkjones 14y agoIt's true that a lot of sites don't go to the trouble of implementing particularly secure login systems (it's a lot of work!). Sadly I think this includes many banks. One way around this is using SSO with a site who does spend a lot of resources on making their login system secure. For example, using Facebook Connect is a great way to get all that security (plus all our fake account detection) and the added bonus of not having to store (and properly hash) passwords. If only RockYou, Gawker, Sony and others whose credential databases have been compromised had done something like that... Fortunately, we have an answer even to problems like that with 3rd parties: http://bucks.blogs.nytimes.com/2012/04/02/how-facebook-tries-to-protect-users-online-credentials/ http://bucks.blogs.nytimes.com/2012/04/02/how-facebook-tries.... I've spent multiple nights up late trying to crack hashed passwords on a big dump before attackers can, so we can help the victims who shared credentials between the compromised site and Facebook secure their accounts. I'd love to raise awareness around the stuff we do to protect users. We've done blog posts and people have written articles, and users often see this stuff when e.g. they're traveling (ever been asked to identify photos of your friends?). What else do you think we could do? Here are some example articles about what we do around login security - if you're interested, check out http://www.facebook.com/security http://www.facebook.com/security to see other related stuff. https://www.facebook.com/note.php?note_id=10150172618258920 https://www.facebook.com/note.php?note_id=10150172618258920 https://blog.facebook.com/blog.php?post=389991097130 https://blog.facebook.com/blog.php?post=389991097130 https://www.facebook.com/note.php?note_id=425136200765 https://www.facebook.com/note.php?note_id=425136200765
- tjoff 14y agoFor example, using Facebook Connect is a great way to get all that security (plus all our fake account detection) and the added bonus of not having to store (and properly hash) passwords. With the downside of compromising your users integrity and open your users up to even more tracking as well as relying on a 3rd party for a system-critical component and force your users to sign up for a facebook account. Storing and properly hash passwords is not hard to do. While I appreciate the work you do, facebook connect (as well as most, if not all, similar solutions) just sickens me and any service that exclusively rely on it is just pathetic (for the reasons above). Todo: Create multiple fake facebook accounts for such services, can't believe I haven't done this already. If you would just care to acknowledge that there might be potential issues with the things you mention your posts wouldn't seem like pure PR-statements.