Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mkjones
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
mkjones
14y ago
Shoot - sorry if I came across as disingenuous! You're right that a lot of the reason we spend time on login is because we want our users' accounts to be secure - but a big advantage of our API is that we extend all that work to third part
32.
▲
by
mkjones
14y ago
1. What's irrelevant about having robust and constantly-evolving phishing detection, and optimized flows for getting people back into their accounts? Both of these are important in a high-quality login system IMO. 2. You're right that a
33.
▲
by
mkjones
14y ago
My point is that you shouldn't bother spending any time rolling your own registration / authentication step. Do you think that using 3rd party auth in lieu of your own auth decreases security?
34.
▲
by
mkjones
14y ago
So I like a lot of the analysis in this article, but couldn't help taking issue with some of it. Here are some thoughts that came to mind. Worth noting that I work on security / spam fighting at Facebook, but these are solely my personal op
35.
▲
by
mkjones
14y ago
Hey folks - I work on the Site Integrity team at Facebook. We work to keep people safe from scams, spam, fake accounts, and having their account taken over. We're always looking for ways to better understand how people represent themselves
36.
▲
How Facebook sped up off-site clicks by hundreds of ms
(facebook.com)
9 points
by
mkjones
14y ago
|
0 comments
37.
▲
by
mkjones
14y ago
You mean like one of these, right? http://cache4.asset-cache.net/xc/87800053-deadbolt-lock-and-...
38.
▲
by
mkjones
14y ago
Hey folks - thanks for the post. I'm an engineering manager at Facebook and worked a bit on this issue earlier today. As some people have pointed out, we've since pushed an update to the Graph API. A bug in a recent update to our code cau
39.
▲
by
mkjones
14y ago
I'm glad to see people talking about this. I get that it's somewhat scary to depend on a third-party site for authentication to yours, but it seems like that tradeoff is more than worth it given how difficult it is to implement secure logi
40.
▲
by
mkjones
14y ago
I think it's only a handful of certificats that are pinned (they call it "HSTS preloading" here: http://www.imperialviolet.org/2011/05/04/pinning.html ). While this does include gmail and some other Google properties, it doesn't seem to i
41.
▲
by
mkjones
14y ago
What are some cases where you've been asked for a password in an iOS app? I've only ever seen this for initial login with like facebook or instagram, and when updating apps (very annoying, I agree).
42.
▲
by
mkjones
14y ago
This article's about a year and a half old. We have pretty good unit test coverage on a good chunk of our code (especially core stuff), though admittedly not everything. Some groups put particular emphasis on this (e.g. the messages team i
43.
▲
by
mkjones
14y ago
I actually haven't seen this much as an issue at Facebook (I've been an engineer there for a few years). There are some (usually very smart) people who care a lot about systems working reliably, and almost always seem to be a few who are w
44.
▲
by
mkjones
14y ago
What do you mean? I've worked with some of our DBAs, and they're quite good. In fact, I can't think of a single site issue that was caused by a DBA. I work on fighting spam at FB, and we make use of mysql quite a bit.
45.
▲
by
mkjones
14y ago
Most web sites don't 404 when fed unrecognized get params.
46.
▲
by
mkjones
14y ago
I just searched for "memorialized" on our help center and got a link to the page that lets you fix this: http://mkjon.es/memorialize.png If I search for "facebook memorialized" on the google, the first result takes me to https://www.face
47.
▲
by
mkjones
14y ago
Ah, I have the 6.5M file. Not sure why I'm not finding stuff from my wordlist in it, but I do see things from e.g. https://twitter.com/mikko/status/210341669944573955 . Sorry for the confusion!
48.
▲
by
mkjones
14y ago
Interesting, I tried this with a bunch of different passwords (though using php's sha1 function, which obviously gives the same output as ruby's), and found no matches. You're using the "combo_not.txt" file from the zip file in the ggp, ri
49.
▲
by
mkjones
14y ago
Interesting - I wasn't able to find the hashes of any passwords in the list. What list were you using?
50.
▲
by
mkjones
14y ago
Those just look like hashes - are there usernames / salts somewhere? They do indeed seem to be salted.
51.
▲
by
mkjones
14y ago
Ah, I thought they made that change for everyone a few months ago. Didn't realize it was only for https clicks.
52.
▲
by
mkjones
14y ago
Maybe I'm missing something, but doesn't Google redirect through an interstitial page that's always over HTTP, so you do get a referrer that says the traffic came from them?
53.
▲
by
mkjones
14y ago
Do you have an example of FB blocking imgur images? We certainly don't intend to, and I'd like to get it fixed if we are for some reason.
54.
▲
by
mkjones
14y ago
I don't think that's how sharing someone else's post works. If I make a friends-only post, and you share it to your friends, only the intersection of our friends can see it. I agree this is maybe not as clear as it could be on the UI, but
55.
▲
by
mkjones
14y ago
I agree - we've turned off the classifier that caused this false positive, as it's clearly too aggressive.
56.
▲
by
mkjones
14y ago
Another FB engineer here - I actually work on the system that caused this false positive. You're right that if we were actually trying to stop constructive discussion from happening, that would be bad. We're definitely not trying to do th
57.
▲
by
mkjones
14y ago
> With the downside of compromising your users integrity and open your users up to even more tracking as well as relying on a 3rd party for a system-critical component and force your users to sign up for a facebook account. Obviously us
58.
▲
by
mkjones
14y ago
It's true that a lot of sites don't go to the trouble of implementing particularly secure login systems (it's a lot of work!). Sadly I think this includes many banks. One way around this is using SSO with a site who does spend a lot of res
59.
▲
by
mkjones
14y ago
Sorry I don't understand, but why not what? Often times users change their password because they've forgotten the old one, so we cannot ask for their last password in that case. In other cases, users may have a number of previous passwords
60.
▲
by
mkjones
14y ago
Glad it's helpful! If that's too hardcore for you, check out "Login Notifications" as well (on the same page). This sends you a text whenever someone logs in from an unrecognized browser (but allows the login).
More ›