SlideShare une entreprise Scribd logo
1  sur  21
WHY FACEBOOK’S “CHECKPOINT”
ACCOUNT SECURITY SUCKS SO BAD
Hollis Thomases
MY SITUATION, MY COMPLAINT
 About a month ago, in early July 2013, I was trying
to remove content administrators of a Facebook
page I own.
 After clicking the “Save” button, I was asked to
enter my password (the same password I had used
to log into my account, mind you)
 At this point, Facebook served me a pop-up
informing me that my “account may have been
hacked” and to take security measures to solve the
problem.
That’s when my fun started…
FIRST I GOT AN EMAIL…
INAPPROPRIATE REQUESTS
 Originally when I clicked on the link, I was
taken to a Facebook page asking me to
upload a photo of myself on one of the
following personally identifiable pieces of
information (as if I would?! This is Facebook
after all.):
 A driver’s license
 A passport
 A state-issued identification card
 A military-issued identification card
 An immigration card with a signature
MY ONLY OTHER OPTION?
 Since I wasn’t about to upload any of those pieces
of personal information to Facebook, I clicked on
the link that indicated I might have other options
 My other option was to “log on from Chrome
browser for Windows XP that you used on May
23, 2013 and May 28, 2013”
 OK, this was totally creepy, and…
 I routinely use at least 3 different computers and when I
do log in using Chrome, it’s usually in Incognito mode so
I think Facebook wouldn’t even connect the dots, right?
 I try to log in using Chrome on all three computers.
Nothing works.
AT THIS POINT I SAID “SCREW
FACEBOOK! I DON’T EVEN CARE
ABOUT THIS ACCOUNT ANYWAY!”
FAST-FORWARD ONE MONTH
 I was on the phone with a colleague recounting this
ridiculous story, when I got curious. “Let me try to
log-on again, and see what I get this time,” I told
her.
 Using one of my 3 same computers and Chrome
browser in Incognito mode, I then tried to log in.
 This time, I documented the entire process.
More fun & games with Facebook...
THE SAME INITIAL WARNING…
So I clicked the Continue button…
A NEW VERIFICATION PROCESS?
 Instead of being asked to upload photo ID, now I
was given a choice of 3 was to prove I was who I
said I was:
THE PROBLEM WITH MY CHOICES
 First of all, I joined Facebook in 2007 when
Facebook didn’t give a hill of beans about your
security. It didn’t even use a secure URL at that
time!
 To my recollection, I never created a Security
Question and I am positive that I never intentionally
uploaded a credit card to Facebook
 In in the off chance I did, it’s quite likely that in the 6
years since joining, that credit card # would have been
discontinued or cancelled.
 Many of the “Friends” I’m connected to on
Facebook aren’t serious friends at all. In 2007, the
only people I could Friend with were other Internet
marketing professionals.
SO I ROLLED THE DICE…
CHOICE #1: SECURITY QUESTION
 My first choice was to attempt the security question.
I was asked a question about my schooling.
 I answered the question 100% accurately (I took
out my scrapbook just to verify I was)
 Facebook said I failed my answer
CHOICE #2: CREDIT CARD VERIFICATION
 Just as I thought, I didn’t recognize this # at all. It
could have been mine, but it’s not any of my current
credit card #s.
Guess I failed ID test #2, too.
CHOICE #3: IDENTIFY YOUR FRIENDS
 So with this final option, I was told I’d be
shown photos of friends I had to identify. I
had to identify 5 friends accurately, but I
could choose to skip twice without penalty.
That’s all I was told.
 Still on the phone with my colleague and
laughing all along about this, I started my
test.
CHOICE #3: IDENTIFY YOUR FRIENDS
 In no more than 5 minutes, I accurately identified 5
out of 5 friends, not skipping a single one –
hooray, right?
WRONG! Facebook said I took too much time
doing so! WTF?!!
FACEBOOK’S LACK OF LOGIC
 While it keeps me locked out like this, Facebook’s
illogic still sends me non-stop email notifications
about the goings-on of my connections:
APPARENTLY THIS STUPIDITY HAS A NAME
 It’s called “Checkpoint,” as in the URL
https://www.facebook.com/checkpoint (Facebook
will automatically redirect this URL to its home page
unless your account is locked and you’re trying to
log in)
 Apparently, I’m not the only one with a problem:
 http://allfacebook.com/malware-checkpoint-locked-
accounts_b94434 (July 2012)
 http://www.pcworld.com/article/259216/facebook_securit
y_checkpoint_hits_roadblock.html (July 2012)
 http://www.youtube.com/watch?v=UvgOsIfOkCg
FACEBOOK APPRECIATES MY FEEDBACK
 If you happen to get sick of the mind-numbing loop
of verification attempts, you can click on a link
below the box saying, “I can’t get out of this flow.”
 What does this do for you? ABSO-FREAKIN-
LOUTELY NOTHING! It just launches a pop-up
where Facebook thanks you for your feedback.
MY CONCLUSIONS
 Facebook remains an
abomination that really
cares little for its users
 Facebook has long
since been of little
value to my life
 I’m fine with Facebook
and me parting ways
permanently
 Need to contact me?
 @hollisthomases
 LinkedIn
 .

Contenu connexe

Dernier

Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 

Dernier (20)

Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 

En vedette

How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
ThinkNow
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

En vedette (20)

Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 

Why Facebook’s Checkpoint Account Security Sucks So Bad

  • 1. WHY FACEBOOK’S “CHECKPOINT” ACCOUNT SECURITY SUCKS SO BAD Hollis Thomases
  • 2. MY SITUATION, MY COMPLAINT  About a month ago, in early July 2013, I was trying to remove content administrators of a Facebook page I own.  After clicking the “Save” button, I was asked to enter my password (the same password I had used to log into my account, mind you)  At this point, Facebook served me a pop-up informing me that my “account may have been hacked” and to take security measures to solve the problem. That’s when my fun started…
  • 3. FIRST I GOT AN EMAIL…
  • 4. INAPPROPRIATE REQUESTS  Originally when I clicked on the link, I was taken to a Facebook page asking me to upload a photo of myself on one of the following personally identifiable pieces of information (as if I would?! This is Facebook after all.):  A driver’s license  A passport  A state-issued identification card  A military-issued identification card  An immigration card with a signature
  • 5. MY ONLY OTHER OPTION?  Since I wasn’t about to upload any of those pieces of personal information to Facebook, I clicked on the link that indicated I might have other options  My other option was to “log on from Chrome browser for Windows XP that you used on May 23, 2013 and May 28, 2013”  OK, this was totally creepy, and…  I routinely use at least 3 different computers and when I do log in using Chrome, it’s usually in Incognito mode so I think Facebook wouldn’t even connect the dots, right?  I try to log in using Chrome on all three computers. Nothing works.
  • 6. AT THIS POINT I SAID “SCREW FACEBOOK! I DON’T EVEN CARE ABOUT THIS ACCOUNT ANYWAY!”
  • 7. FAST-FORWARD ONE MONTH  I was on the phone with a colleague recounting this ridiculous story, when I got curious. “Let me try to log-on again, and see what I get this time,” I told her.  Using one of my 3 same computers and Chrome browser in Incognito mode, I then tried to log in.  This time, I documented the entire process. More fun & games with Facebook...
  • 8. THE SAME INITIAL WARNING… So I clicked the Continue button…
  • 9. A NEW VERIFICATION PROCESS?  Instead of being asked to upload photo ID, now I was given a choice of 3 was to prove I was who I said I was:
  • 10. THE PROBLEM WITH MY CHOICES  First of all, I joined Facebook in 2007 when Facebook didn’t give a hill of beans about your security. It didn’t even use a secure URL at that time!  To my recollection, I never created a Security Question and I am positive that I never intentionally uploaded a credit card to Facebook  In in the off chance I did, it’s quite likely that in the 6 years since joining, that credit card # would have been discontinued or cancelled.  Many of the “Friends” I’m connected to on Facebook aren’t serious friends at all. In 2007, the only people I could Friend with were other Internet marketing professionals.
  • 11. SO I ROLLED THE DICE…
  • 12. CHOICE #1: SECURITY QUESTION  My first choice was to attempt the security question. I was asked a question about my schooling.  I answered the question 100% accurately (I took out my scrapbook just to verify I was)  Facebook said I failed my answer
  • 13. CHOICE #2: CREDIT CARD VERIFICATION  Just as I thought, I didn’t recognize this # at all. It could have been mine, but it’s not any of my current credit card #s. Guess I failed ID test #2, too.
  • 14. CHOICE #3: IDENTIFY YOUR FRIENDS  So with this final option, I was told I’d be shown photos of friends I had to identify. I had to identify 5 friends accurately, but I could choose to skip twice without penalty. That’s all I was told.  Still on the phone with my colleague and laughing all along about this, I started my test.
  • 15.
  • 16. CHOICE #3: IDENTIFY YOUR FRIENDS  In no more than 5 minutes, I accurately identified 5 out of 5 friends, not skipping a single one – hooray, right? WRONG! Facebook said I took too much time doing so! WTF?!!
  • 17.
  • 18. FACEBOOK’S LACK OF LOGIC  While it keeps me locked out like this, Facebook’s illogic still sends me non-stop email notifications about the goings-on of my connections:
  • 19. APPARENTLY THIS STUPIDITY HAS A NAME  It’s called “Checkpoint,” as in the URL https://www.facebook.com/checkpoint (Facebook will automatically redirect this URL to its home page unless your account is locked and you’re trying to log in)  Apparently, I’m not the only one with a problem:  http://allfacebook.com/malware-checkpoint-locked- accounts_b94434 (July 2012)  http://www.pcworld.com/article/259216/facebook_securit y_checkpoint_hits_roadblock.html (July 2012)  http://www.youtube.com/watch?v=UvgOsIfOkCg
  • 20. FACEBOOK APPRECIATES MY FEEDBACK  If you happen to get sick of the mind-numbing loop of verification attempts, you can click on a link below the box saying, “I can’t get out of this flow.”  What does this do for you? ABSO-FREAKIN- LOUTELY NOTHING! It just launches a pop-up where Facebook thanks you for your feedback.
  • 21. MY CONCLUSIONS  Facebook remains an abomination that really cares little for its users  Facebook has long since been of little value to my life  I’m fine with Facebook and me parting ways permanently  Need to contact me?  @hollisthomases  LinkedIn  .