news.volyx.in

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card (codewriteplay.com)

962 points by tosh · 1860 days ago · 366 comments on HN

Article summary

The article discusses a person's experience with a Facebook hacker who bypassed their two-factor authentication and accessed their account, resulting in the bricking of their Oculus and unauthorized use of their company credit card. The exact method of bypassing 2FA is not specified in the available comments. The discussion focuses on the security of 2FA methods, particularly SMS-based authentication, and potential alternatives. The conversation also touches on the trade-offs between security and convenience in account recovery processes.

Main themes

  • 2FA security
  • SMS hijacking
  • U2F/WebAuthn
  • Account recovery
  • Advanced Protection
  • Security vs convenience
  • In-person verification
  • Threat modeling

What commenters say

  • SMS-based 2FA is insecure and can be bypassed through social engineering or SIM swapping.
  • U2F/WebAuthn is a more secure alternative to traditional 2FA methods due to its origin binding and resistance to phishing.
  • Google's Advanced Protection program offers a high level of security, but its account recovery process may be too extreme for some users.
  • Requiring in-person verification with a government-issued ID could provide a secure way to recover accounts.
  • Some users may not be willing to pay for additional security features or take on the operational burden of managing backup keys.
  • The security of 2FA methods depends on the threat model and the level of risk the user is willing to accept.
  • In-person verification methods, such as those used by the Post Office for passport applications, could provide a secure way to verify identities.
  • The trade-off between security and convenience is a major consideration in the design of account recovery processes.