2factorauth / twofactorauth

List of sites with two factor auth support which includes SMS, email, phone calls, hardware, and software.
https://2fa.directory
Other
3.38k stars 1.77k forks source link

Facebook 2FA is also one account per phone number #1181

Closed alx9r closed 9 years ago

alx9r commented 9 years ago

I just witnessed the following on Facebook:

"You recently removed your primary phone from your account. Because of this, we turned off login approvals on your account to ensure that you don't get locked out when using an unrecognized computer or mobile device to login."

  • user is now able to login to account1 on a new device with just their password and no second factor
  • checking the 2FA settings on account1 reveals 2FA is indeed turned off for that account

    The Facebook Entry Should have a Hazard Symbol like Twitter

image

À la the twitter entry, the Facebook entry should have a hazard symbol that states something like the following:

"SMS required for 2FA, 1 account per phone"

mxxcon commented 9 years ago

Perhaps this should be reported as a bug to Facebook?

alx9r commented 9 years ago

@mxxcon It's certainly a limitation, but why would "1 account per phone" be considered a bug?

mxxcon commented 9 years ago

Because it might not be an expected behavior. In the case of twitter they explicitly tell you that it's 1:1 relationship, where as here they seem to silently remove 2fa from your 1st account.

alx9r commented 9 years ago

I see. That is true. I wonder if Facebook has a bug submission process...

mxxcon commented 9 years ago

There's https://www.facebook.com/help/326603310765065/ and there's https://www.facebook.com/whitehat/

alx9r commented 9 years ago

I reported this by following the instructions at https://www.facebook.com/help/326603310765065/.

inputsh commented 9 years ago

No, definitely not. On Facebook's Terms of Service it clearly says that having two separate Facebook accounts is against the rules (section 4, point 2).

Considering it, no, it's not a bug. It's perfectly normal for a Facebook person to have a phone and limiting one person per phone is perfectly normal for their service.

mxxcon commented 9 years ago

@aleksandar-todorovic except when you have a personal facebook account and a business one, which you now can not protect with 2fa...

inputsh commented 9 years ago

@mxxcon Do you by "business account" mean a Facebook page for your company/project?

mxxcon commented 9 years ago

@aleksandar-todorovic for my company/project/organization/client/however else it can be used.

jamcat22 commented 9 years ago

Yeah. Facebook Pages can have separate accounts that aren't linked to a personal account.

jamcat22 commented 9 years ago

Closing due to #1250.