{"id":18563,"date":"2022-03-22T13:10:07","date_gmt":"2022-03-22T21:10:07","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/03\/22\/news-12296\/"},"modified":"2022-03-22T13:10:07","modified_gmt":"2022-03-22T21:10:07","slug":"news-12296","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/03\/22\/news-12296\/","title":{"rendered":"Facebook users wary of security mail find themselves locked out of accounts"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Tue, 22 Mar 2022 20:47:17 +0000<\/strong><\/p>\n<p>It\u2019s not unusual for sites and services to offer additional forms of protection on top of regular security features. Some of the bigger ones even go the extra mile, protecting from attacks up to a potential nation state level.<\/p>\n<p>The most famous example of this recently is likely Google. Its Advanced Protection Program (APP) was deployed to warn people that <a href=\"https:\/\/blog.malwarebytes.com\/malwarebytes-news\/2021\/10\/google-warns-some-users-that-fancybears-been-prowling-around\/\">Fancy Bear was on the prowl<\/a>. We often see advanced security features like the APP feed back into security features for regular service users too. This is all very good.<\/p>\n<p>What isn\u2019t perhaps quite as good, is when not taking up the offer of additional security features results in a total lock out of your account. This is the complaint that&#8217;s been raised by many Facebook users over the last few days.<\/p>\n<h2>What happened?<\/h2>\n<p>Facebook has a service similar to Google\u2019s APP which it is rolling out to users. That service is called Facebook Protect, and it&#8217;s being expanded to more and more countries. As per <a href=\"https:\/\/about.fb.com\/news\/2021\/12\/expanding-facebook-protect-to-more-countries\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Facebook&#8217;s own description<\/a> of what it does:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p><em>We\u2019re expanding Facebook Protect, our security program for groups of people that are more likely to be targeted by malicious hackers, such as human rights defenders, journalists, and government officials.<\/em><\/p>\n<p><em>No action is required unless you\u2019re prompted to enroll.<\/em><\/p>\n<p><em>We\u2019re also making it easier for these groups of people to set up two-factor authentication.<\/em><\/p>\n<\/blockquote>\n<p>Sounds like a good plan! However, the roll out and various interactions with Facebook Protect haven\u2019t gone well for everybody. At the beginning of March, people started to receive emails out of the blue which also included a clickable button to set everything up. It also pointed out that if recipients didn\u2019t enable the feature, they\u2019d be locked out of their account.<\/p>\n<h2>When is\/isn&#8217;t the promise of a lockout real?<\/h2>\n<p>This immediately threw recipients into confusion, as they tried to figure out if they were being phished:<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">So&#8230; I received an email this morning from <a href=\"https:\/\/twitter.com\/Meta?ref_src=twsrc%5Etfw\">@meta<\/a> telling me that my account &quot;requires advanced security from Facebook Protect&quot; because it is a potential target for hackers. There&#39;s a button in the email to &quot;turn on Facebook Protect.&quot;&#8230;<\/p>\n<p>&mdash; Mike Masnick (@mmasnick) <a href=\"https:\/\/twitter.com\/mmasnick\/status\/1498715797434167297?ref_src=twsrc%5Etfw\">March 1, 2022<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script> <\/div>\n<\/figure>\n<p>The fact that Facebook said everything was \u201cfine\u201d if they navigated to the site directly didn\u2019t help ease the feelings of confusion. While the head of security policy at Meta <a href=\"https:\/\/twitter.com\/ngleicher\/status\/1498734352837926918\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">confirmed the mails were real<\/a>, once the deadline had passed people started to flag issues with getting back into the site:<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Nathaniel,<br \/>The system is *literally* broken and has been at least for today (since mine was locked). RN this feels more like you&#39;re holding my account hostage, TBH. <br \/>Would appreciate some help. My DMs are open. <a href=\"https:\/\/t.co\/e9eo158dth\">pic.twitter.com\/e9eo158dth<\/a><\/p>\n<p>&mdash; Jeff Koenig (@DIYdestiny) <a href=\"https:\/\/twitter.com\/DIYdestiny\/status\/1505001792211329029?ref_src=twsrc%5Etfw\">March 19, 2022<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script> <\/div>\n<\/figure>\n<h2>The lockout begins<\/h2>\n<p>As it turns out, many people are <a href=\"https:\/\/www.theverge.com\/2022\/3\/18\/22984802\/facebook-protect-lock-out-twitter\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">now indeed experiencing some form of lockout<\/a>. Worse, they\u2019re having major issues trying to resume business as usual. Most of the complaints I\u2019ve seen are focused on the fact that they thought the clickable button email was some sort of scam attempt:<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">I got locked out from Facebook  indefinitely today because I didn\u2019t respond to emails from FB (that looked like a scam) about its new Facebook Protect system, which I was required to enable by today. So far, the text and security key options don\u2019t work, many report. <a href=\"https:\/\/t.co\/0aXbiqzLv7\">pic.twitter.com\/0aXbiqzLv7<\/a><\/p>\n<p>&mdash; Liv. (@Olivia_Thiessen) <a href=\"https:\/\/twitter.com\/Olivia_Thiessen\/status\/1504825280229253120?ref_src=twsrc%5Etfw\">March 18, 2022<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script> <\/div>\n<\/figure>\n<p>This on its own is fairly problematic for those affected. It\u2019ll no doubt be fixed, but if you\u2019re one of the people who ignored the mail, unfortunately there\u2019s no ETA for a fix. What I find particularly interesting in this story is the knock-on effect on additional Facebook\/Meta services.<\/p>\n<h2>A virtual headache<\/h2>\n<p>At launch, users of the Oculus Quest 2 headset found they <a href=\"https:\/\/www.androidcentral.com\/what-do-if-your-oculus-quest-2-facebook-account-gets-banned\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">needed to have a Facebook account<\/a> in order to play. If the account was banned, bad luck &#8211; no more Oculus Questing for you. While it\u2019s been mentioned a few times that <a href=\"https:\/\/www.pcgamer.com\/uk\/oculus-quest-vr-headsets-to-eliminate-mandatory-facebook-account-log-in-requirement\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Facebook-free headsets<\/a> will be with us at some point, this doesn\u2019t help people caught by the Protect problem. This is because not only will you lose the ability to use your headset if banned, you\u2019ll also suffer the same fate if the account is disabled for some reason.<\/p>\n<p>Locked out due to not clicking through on an email from the start of March? It&#8217;s not just your social platform impacted, it&#8217;s your headset, too. As one device owner put it, they\u2019ve <a href=\"https:\/\/www.thegamer.com\/facebook-protect-deactivated-quest-2-protect-disable-brick\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">had their headset \u201cbricked\u201d<\/a> to protect them from hackers. They too are suffering from the various options to re-enable things not currently working.<\/p>\n<p>As we mentioned above, this will no doubt be fixed down the line. However, a lot of people really need access to their accounts and devices as soon as possible. For now, it\u2019s a case of the waiting game &#8211; all because of an unexpected email and a suspicious looking button.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2022\/03\/facebook-users-wary-of-security-mail-find-themselves-locked-out-of-accounts\/\">Facebook users wary of security mail find themselves locked out of accounts<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2022\/03\/facebook-users-wary-of-security-mail-find-themselves-locked-out-of-accounts\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Tue, 22 Mar 2022 20:47:17 +0000<\/strong><\/p>\n<p>We look at multiple reports of Facebook users being locked out of accounts and devices because of a security mail they thought might be fake.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2022\/03\/facebook-users-wary-of-security-mail-find-themselves-locked-out-of-accounts\/\">Facebook users wary of security mail find themselves locked out of accounts<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[3589,25457,5897],"class_list":["post-18563","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-facebook","tag-facebook-protect","tag-privacy"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18563","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18563"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18563\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18563"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18563"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18563"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}