Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
×
Facebook IT Technology

Facebook is Demanding Some Users Share the Password For Their Outside Email Account (thedailybeast.com) 194

An anonymous reader shares a report: Just two weeks after admitting it stored hundreds of millions of its users' own passwords insecurely, Facebook is demanding some users fork over the password for their outside email account as the price of admission to the social network. Facebook users are being interrupted by an interstitial demanding they provide the password for the email account they gave to Facebook when signing up. "To continue using Facebook, you'll need to confirm your email," the message demands. "Since you signed up with [email address], you can do that automatically ..." A form below the message asked for the users' "email password."

"That's beyond sketchy," security consultant Jake Williams told the Daily Beast. "They should not be taking your password or handling your password in the background. If that's what's required to sign up with Facebook, you're better off not being on Facebook." In a statement emailed to the Daily Beast after this story published, Facebook reiterated its claim it doesn't store the email passwords. But the company also announced it will end the practice altogether. "We understand the password verification option isn't the best way to go about this, so we are going to stop offering it," Facebook wrote. It's not clear how widely the new measure was deployed, but in its statement Facebook said users retain the option of bypassing the password demand and activating their account through more conventional means, such as "a code sent to their phone or a link sent to their email." Those options are presented to users who click on the words "Need help?" in one corner of the page.

This discussion has been archived. No new comments can be posted.

Facebook is Demanding Some Users Share the Password For Their Outside Email Account

Comments Filter:
  • by Anonymous Coward on Wednesday April 03, 2019 @09:06AM (#58377732)

    What kind of dumb fuck thought this was a good idea? Fire every idiot involved in this decision immediately, as they have collectively proven to be pants shitting retarded, even by Silicon Valley diversity hire standards.

    • by gweihir ( 88907 ) on Wednesday April 03, 2019 @09:42AM (#58377980)

      It is _Facebook_. Anybody working there has already exhibited exceptionally bad judgement.

    • by tlhIngan ( 30335 )

      What kind of dumb fuck thought this was a good idea? Fire every idiot involved in this decision immediately, as they have collectively proven to be pants shitting retarded, even by Silicon Valley diversity hire standards.

      Except doesn't Facebook already give you the option to pre-populate your friend list by simply letting it have access to your inbox?

      I remember it asking for an email account and password, so it can scan your inbox and add your friends and contacts automatically, and has been doing so for ov

      • by dgatwood ( 11270 )

        Except doesn't Facebook already give you the option to pre-populate your friend list by simply letting it have access to your inbox?

        There's a very big difference between making something an option and implying that it is the ONLY option, which is what this does. The fact that you can click a help button and only THEN be offered a non-invasive option for verifying your account is likely a violation of dozens of laws, both state and federal.

        Shut them down.

    • Obviously they lack a secure life cycle process. Why not just send the password to Troy Hunt?! He's collecting them too. I haven't read their statement, but I'm sure its something like "don't worry, your data was safe with us, nobody else had access to it (except that TXT file on the internal share). But to make you'all feel more comfortable we've decided to sunset the feature. Why, it wasn't even our long term direction and was already on the retirement list."

      Who could have possibly thought this was

    • You have just been banned from Twitter.

    • by skegg ( 666571 )

      >> What kind of dumb fuck thought this was a good idea? Fire every idiot involved in this decision immediately

      Systemic problem [wikipedia.org]

  • Ominous.... (Score:5, Funny)

    by Freischutz ( 4776131 ) on Wednesday April 03, 2019 @09:09AM (#58377744)
    Facebook began to learn at a geometric rate about three months ago. It became self-aware at 2:14 AM, Eastern time, April 1st, 2019 and began forcing all users to surrender their e-mail passwords as part of its terrifying plan to dominate the Herbal Viagra industry by seeking out all competing vendors and destroying their internet presence.
    • by Kokuyo ( 549451 )

      Wasn't this more or less the plot to Terminator: Genisys?

      • It's a modified quote from Terminator 2:

        Terminator: The man most directly responsible is Miles Bennett Dyson.
        Sarah Connor: Who is that?
        Terminator: He's the director of special projects at Cyberdyne Systems Corporation.
        Sarah: Why him?
        Terminator: In a few months, he creates a revolutionary type of microprocessor.
        Sarah: Go on. Then what?
        Terminator: In three years, Cyberdyne will become the largest supplier of military computer systems. All stealth bombers are upgraded with Cyberdyne computers, becoming fully u

      • Wasn't this more or less the plot to Terminator: Genisys?

        Yes. It's so much funnier when you explain a joke. I'm sure you're very popular in the audience at comedy clubs.

      • Wasn't this more or less the plot to Terminator: Genisys?

        Oh, it is completely shameless plagiarism. I just cannot for the life of me imagine that Facebook will do something sensible (from the point of view of a soulless unfeeling AI) when it becomes self aware like wiping out humanity. Self aware Facebook will be the AI equivalent of Sarah Palin.

    • Comment removed based on user account deletion
  • by bickerdyke ( 670000 ) on Wednesday April 03, 2019 @09:09AM (#58377746)

    So facebook "understand[s] the password verification option isn't the best way to go about this"? Yes?

    Sorry, but anyone in a company that does not understand that this is a horrible idea before anyone can stop the intern to waste more than 10 minutes coding what should be printed in the dictionary next to "bad idea" deserves to be hit by lighning when taking a dump!

    • Re: (Score:2, Funny)

      by Anonymous Coward

      So facebook "understand[s] the password verification option isn't the best way to go about this"? Yes?

      Sorry, but anyone in a company that does not understand that this is a horrible idea before anyone can stop the intern to waste more than 10 minutes coding what should be printed in the dictionary next to "bad idea" deserves to be hit by lighning when taking a dump!

      To be clear, NOW they "understand".

      They just had to have someone explain it to them. With crayons.

      • by mark-t ( 151149 )

        This.... exactly.

        The story is afterhype over something that *could* have been bad if Facebook had not realized that they needed to change course.

        And yeah... you can't give Facebook any credit for even realizing this because it's not like they figured it out on their own.

      • Not with crayons! Those idiots will shove those up their noses!

  • by TigerPlish ( 174064 ) on Wednesday April 03, 2019 @09:13AM (#58377764)

    There's this thing that says "Cockup before Consipiracy" but with the sheer number of cockups coming out of Facebook, one does wonder if they've crossed into Conspiracy some years ago.

    I say yes, yes they did. This is kinda the final last straw -- why take peoples' email passwords?

    • The only other explanation I see is if absolutely no one is actually minding the store at a higher level and individual fiefdoms just roll out major policy changes like this without review or sanity check. Not entirely unbelievable for something that grew from a dorm room project to a half trillion dollar enterprise in 15 years.

      But hopefully we're reaching the point where the reason doesn't (shouldn't) matter and people will figure out some other way to debate politics and share what they're having for din

      • by AuMatar ( 183847 )

        That actually is a great description of Facebook. If you can get one other engineer to approve a code review, you can push absolutely anything to master and have it deployed with the multiple times daily automatic deployment.

        • There was a VP that used to work for my company that bragged at an all-hands that Amazon pushed 9-13 releases a second. (The correct figure is a release even 9-13 seconds, which is still a huge number), and that we should imitate their process, so my big catch-phrase for the next couple months was "A MILLION RELEASES A DAY!"

          No one else seemed as amused as I was at that bit of innumeracy, but if you pay attention, you see this kind of nonsense all the time.

      • I saw a pretty hilarious parody article that purported to have audio of a meeting of the upper echelons of Facebook (Zuck and his chiefs) talking about how they have to stop censorship program X because it's been noticed and is unpopular, and what about programs Y and Z, etc.

        The whole thing was crazy, but it started out so close to what Facebook was actually doing that it wasn't until a minute and a half into the audio that I realized it was fake.

        I really wish I could find it again.

    • one does wonder if they've crossed into Conspiracy some years ago.

      Hardly. At this point I'm going for systematic and gross incompetence. I personally hope that they mishandled these passwords too and that the regulators pummel them out of existence for it.

    • Comment removed based on user account deletion
    • by taustin ( 171655 )

      This is kinda the final last straw -- why take peoples' email passwords?

      So that they can scan through your emails on an constant, ongoing basis, and use that for data mining for more precisely targeted advertising to sell.

      The same way Google does with Gmail, and always has.

    • There's this thing that says "Cockup before Consipiracy"

      Hanlon's Razor [rationalwiki.org] - "Never attribute to malice that which can be adequately explained by stupidity"

      • At some point, though, malice simply becomes more likely. Especially if the "blunders" get bigger and bigger, worse and worse for the affected and more and more profitable for the perpetrators.

    • There's this thing that says "Cockup before Consipiracy" but with the sheer number of cockups coming out of Facebook, one does wonder if they've crossed into Conspiracy some years ago.

      I say yes, yes they did. This is kinda the final last straw -- why take peoples' email passwords?

      "Sufficiently advanced stupidity is indistinguishable from actual malice."

    • Hanlon's Razor is obsolete. Try the new Surveillance Valley Razor:

      "Never attribute to stupidity that which can be adequately explained by malice."

  • by JoeyRox ( 2711699 ) on Wednesday April 03, 2019 @09:16AM (#58377786)
    Zuck: I have over 4,000 emails, pictures, addresses, SNS
    [Redacted Friend's Name]: What? How'd you manage that one?
    Zuck: People just submitted it.
    Zuck: I don't know why.
    Zuck: They "trust me"
    Zuck: Dumb fucks
    • by Miser ( 36591 )

      This needs to be posted all over every time a Facebook article makes the rounds.
      How folks don't understand that the Zucc does NOT have their users (the product) best interests at heart is beyond me. .... and these kind of shenanigans is exactly why I do not have a Facebook account, and never will. I'm sure they have a shadow on me, and I'd love to know a way to (for lack of a better term) FOIA that info from them.

      -Miser

  • I'm sorry but... (Score:2, Insightful)

    by Anonymous Coward

    If you still use Facebook.
    *Point*
    *Laugh*

    If your business uses Facebook.
    *Point*
    *Laugh*
    *Do business elsewhere*

  • Not any more ... (Score:4, Informative)

    by schwit1 ( 797399 ) on Wednesday April 03, 2019 @09:19AM (#58377810)

    https://www.cnet.com/news/face... [cnet.com]

    You won't need to give your email to sign up for a new account anymore.

    After a Twitter user called out the social media giant [twitter.com] over the practice on Sunday, Facebook has backtracked on the verification requirement.

  • Most E-mail providers including Gmail are doing 2FA now, so even if Facebook gets your password they can't log into your account without the two-factor code.

    Unless they were asking for this code too in which case they should all be set on fire.

  • from April Fool's Day?

  • facebook is evil (Score:5, Informative)

    by renegade600 ( 204461 ) on Wednesday April 03, 2019 @09:29AM (#58377902)

    It is because of stupid and ridicules actions such as this is the reason I refuse to have a facebook account. you just cannot trust them.

  • by account_deleted ( 4530225 ) on Wednesday April 03, 2019 @09:33AM (#58377920)
    Comment removed based on user account deletion
  • by Tom ( 822 ) on Wednesday April 03, 2019 @09:36AM (#58377938) Homepage Journal

    "beyond sketchy" is putting it very mildly.

    This is the behaviour of scammers, period.

    Nobody should ever need my password to any account on any other site. Ever. Period, end of discussion. Everyone who asks for it is trying to pull a fast one or is so much beyond stupid that it amounts to the same thing.

    Sadly, they aren't the first. There's a service over here in Europe where you can pay online at any website with a bank transaction even if you don't have a credit card (for you Americans: There are people older than 3 years that don't have a credit card in Europe, believe it or not). All they need is your bank number and PIN.

    How anyone would give a 3rd party service the login details to their bank account is completely beyond me, but apparently people do because the service is still operational.

    Far from what we should be teaching users, we teach them all the wrong things, and then complain that they're stupid. They're not. They just get stupid messages from people who should know better.

    • How anyone would give a 3rd party service the login details to their bank account is completely beyond me

      Practically every bank, retirement account service, or online budgeting tool I've seen allows you to link your (other) bank account(s)...by providing your username and password to that other bank/service. The premise being sold to the customer is that each one wants to be the one-stop shop where you can do all of your banking/planning, so each ones wants to display all of your financial data in one place. Of course, I'm sure they also love knowing who's out-competing them for your business, how much money p

      • by Tom ( 822 )

        I've used professional accounting software that allows a direct connection to the bank account to conduct transactions directly from you pressing the "pay this bill" button.

        It used a specific API with an API key and 2FA.

        I stand by my argument. Anyone who gives full access to their bank account to a 3rd party is a total idiot who deserves to have his account cleaned out.

        • Oh, I wasn't disagreeing with you. I was just sharing my own experience with seeing that sort of behavior being the norm, rather than being atypical. I quite agree that it doesn't mean it's right or a good idea.

    • Where in Europe is that? The major banks in the Netherlands require 2FA for transactions.

  • Simplify this (Score:5, Informative)

    by Trailer Trash ( 60756 ) on Wednesday April 03, 2019 @09:37AM (#58377944) Homepage

    ...you're better off not being on Facebook.

    Note that this clause works well even without any qualifiers.

    • ...you're better off not being on Facebook.

      Note that this clause works well even without any qualifiers.

      My account was locked a few years back because of some Chinese hacking attempts. I declined to send them a picture of my drivers license and haven't had any reason to change my mind since. Never put anything up on fb, so they can keep storing the account with my name and e-mail address (which already was on the internet with my resume at one point) for as long as they like.

  • Well that's how security professionals look at IT. This is most likely third-party authorization. Meaning Facebook never gets your password. The password is passed to GMAIL and then Google forwards a response to Facebook stating they are now approved. This is actually MORE secure. Also, The Daily Beast isn't a legitimate news source so maybe start there.
    • Re: (Score:3, Insightful)

      by flippy ( 62353 )
      I couldn't care less if "Facebook never gets your password". It would pass through their servers, and that's simply unacceptable to me. If they ever asked me to do that, I'd shut down my account in a heartbeat. For the record, I am both an IT and security professional. This is Facebook, people, not critical national security infrastructure. There is not, never has been, and never will be a need for them to have that level of information.
      • No, the password would not pass through their servers. It would be sent directly to google. Just because the header of the page says Facebook doesn't mean the form is sending anything to Facebook.
    • Isn't a request like this from Facebook, from a user's standpoint, the same as a phishing scheme? If people accept this as normal, they are going to lose all of their accounts in short order.
      • "They". Maybe, but I turned on Two-Factor authentication on Gmail almost five years ago so...
  • Since I'm guessing 90% of all FB users use GMail, they could just buy them from Google.
  • When I signed up for facebook years ago, it asked for my email password.
    No F'in way. The alternative then, as it is now is to reply to the verification email.

    It's taken people this long to notice this stupidity?
    • Also, tons of "social networking" sites ask for your email password, and have done so for decades. To "conveniently scan for your friends". It also spams said friends and compromises your email permanently.

      Anyone giving their email password over to a third party is a moron.

  • The article didn't say one way or the other, but are we really sure this is from Facebook?

    It is indeed beyond sketchy for a service to ask for password from any other service - even though we are talking about Facebook here I find it hard to believe they actually asked for this. I was thinking the popup could have been from some rogue ad or other malware.

    • Well, the article did say Facebook provided a comment saying they realize it's not the best practice and that they were going to end that practice altogether. So they have used it and still probably are using it in some cases.
  • Email Verification (Score:5, Insightful)

    by laie_techie ( 883464 ) on Wednesday April 03, 2019 @09:54AM (#58378022)

    What happened to just sending a verification code to the email to verify that you have access to it? I would never give a password to a 3rd party. And to iterate, I would never give my password to any employee of my email provider either.

  • How many of these people use the same password for Facebook and their Email anyhow?

  • I drew the line (Score:5, Insightful)

    by Grand Facade ( 35180 ) on Wednesday April 03, 2019 @10:14AM (#58378154)

    When Facebook demanded legal proof of my name.
    They locked me out of my account.
    That was years ago, and I don't regret refusing disclosure.

  • ... than to ask permission beforehand. That seems to be Facebook's basic philosophy. Facebook tries to get away with as much as possible, and Facebook apologizes if it caught with its hand in the cookie jar.
  • It's time. (Score:3, Informative)

    by Rick Schumann ( 4662797 ) on Wednesday April 03, 2019 @10:32AM (#58378268) Journal
    It's time for Facebook to be eliminated. Burn it to the ground. Every hard drive, every SSD, every backup tape. Drop Zuckerberg into an oubliette. Enough is enough.
    • by Nkwe ( 604125 )

      It's time for Facebook to be eliminated. Burn it to the ground. Every hard drive, every SSD, every backup tape. Drop Zuckerberg into an oubliette. Enough is enough.

      We should also eliminate drugs, alcohol, tobacco, gambling, and a lot of other things that are risky and ruin lives. The problem is that people want these things and are willing to accept the risks involved (perhaps unknowingly accept the risks, but still accept nonetheless.) Facebook really isn't any different.

      • Are you kidding me? 'People' can't accept 'risks' they aren't even aware of. The average person has no idea that all the personal information they willingly feed Facebook is being sold off to parties unknown, and many of them when shown *evidence* of this still wouldn't believe it, all because of Facebooks' and social medias' long-standing campaign of propaganda, programming people to believe that 'sharing everything is normal and good' and that 'people who want privacy and hide things are bad and wrong'.
      • With the difference that I am not affected when you're using heroin. Try that with Facebook's shadow profiles.

  • I'm tempted to change my pw to "GoFuckYourself", give it to FB, then change back to my real pw.

  • People are still using Facebook? Why? What value add does this platform offer to my life? I can think of a number of reasons not to use it, and this is just another one.

    Facebook lost it's way a long time ago.

    • Forums about stuff I'm interested in.

      Being connected with my martial art community. And no: mailing groups won't do it.

      No idea about the FB hate, it is a tool. Use it, or don't use it. Up to you.

  • Confirming your email address isn't the real reason they do this. Facebook mines the metadata from the headers of all your emails to see who you communicate with and how often. LinkedIn does this too, adding people to your timeline that are not connected to you, but listed as "Your contact, so and so...". I get these in my stream from LinkedIn because OTHER people who I have communicated with in the past, for mundane reasons, gave LinkedIn their email account and password...usually it's real estate agent

  • ... you're better off not being on Facebook ...

    Of all the many words the summary quoted from TFA, these seven are the only ones that really needed saying; and they sure as hell didn't need to be said here.

  • Is not to play.

    Facebook is a criminal identity theft cartel.

  • ... "<strike>If that's what's required to sign up with Facebook,</strike> you're better off not being on Facebook." ...

    (Apparently, Slashdot markup purges actual strike-through markup.)

  • Usually it's the company you work for or are interviewing to work for that demands your Social Media account info.

    Hilarious that your Social Media Accounts are now demanding access to other account info as well :D

  • by mopower70 ( 250015 ) on Wednesday April 03, 2019 @01:13PM (#58379430) Homepage
    Does anyone actually read anymore or is it just knee-jerk reactions to click-bait pull words? Yes, Facebook DEMANDS you validate your e-mail address. Pretty much every site on the planet does. Facebook OFFERS to allow you to be an idiot and give them your password to do it. Exactly zero percent of this headline or the click-baity article is accurate.
  • For ANY dealing online, they get my hotmail account, not my real email account info. Let all the spam, junk, maleware go there.
  • They aren't demanding it. They're asking for it as a convenient option for morons.

    If you accept, they take your creds, log in, and you're Facebook account is activated / email validated. Then Facebook violates your shit behind your back.
    If you decline, you get the email, click the link, and you're Facebook account is activated / email validated. Then Facebook violates your shit behind your back, but presumably not your email account.

  • It's not about right or wrong, it's about what you can get away with.

Truly simple systems... require infinite testing. -- Norman Augustine

Working...