6 ms·
Tell HN: Meta is using my 2FA to call and sell me
I run a couple of businesses with ad accounts connected to my personal account.
I received multiple calls this morning on my personal cell that's used for 2FA for my personal FB account. All of them, they were pitching me ads to buy for my business accounts.
None of my business accounts have my personal cell on them.
Edit: Now my personal email connected is getting emails to purchase business ads...
- btilly 4y agoTheir year over year revenue fell in June. They are reporting revenue today after the close of trading, and the stock is currently down 5%: https://finance.yahoo.com/quote/META/ https://finance.yahoo.com/quote/META/? So it may well be that they have bad news and are under pressure to say that they are trying to improve revenue.
- ridgered4 4y agoFacebook already used 2FA gathered numbers for ads in the past so I'm not sure why there is so much doubt in this story. https://techcrunch.com/2018/09/27/yes-facebook-is-using-your-2fa-phone-number-to-target-you-with-ads/ https://techcrunch.com/2018/09/27/yes-facebook-is-using-your...
- umeshunni 4y agoBecause the article you linked has no sources?
- devindotcom 4y agoWouldn't be the first time this happened, but it's hard to verify this without any hard data. Follow up with Meta via your business account and ask them to explain or you'll go the FTC and press (me).
- datalopers 4y agoPlease stop using phones/sms as 2FA.
- uncletammy 4y agoTell that to all the shitty companies who require 2FA and only offer it by phone/sms EDIT: and by "shitty" I mean my bank among many other equally important service providers.
- transcriptase 4y agoSo meta engineers saw all those headlines about Twitter misusing 2FA phone numbers and instead of making sure it didn’t happen to them, kept them available to employees to “accidentally” use as well. Oopsie daisy! Tee hee, it was an honest mistake because ${team} didn’t know they weren’t supposed to!
- MattGaiser 4y agoEngineers don’t make decisions like that. Engineers got told to do it.
- fsociety 4y agoWell no nice rhetoric but there are privacy reviews at Meta now to prevent these things. OP should collect evidence for why they think it was Meta and report it. Then it can be investigated properly and dealt with if true. I’m skeptical that it was Meta, given the zero evidence provided here. Unless the OP just pays for a phone number that is only used for Meta 2FA.. but that is a lot of money to have a phone number per a 2FA.
- dimitrios1 4y agoNice rhetoric yourself. I am sure big mega corp has nice checks in place to try and prevent these things, but no system is perfect, nor exhaustive. That's the problem when you are a data sink as a business, your #1 incentive is to keep the data flowing in. You would think that when you hand someone your telephone number and they promise to secure it or only use it for a specific purpose, the onus is on them to prove they didn't misuse it.
- LegionMammal978 4y ago> You would think that when you hand someone your telephone number and they promise to secure it or only use it for a specific purpose, the onus is on them to prove they didn't misuse it. How could this be acceptably proven, in your opinion, if at all? "This information has never been misused" is the null hypothesis; it can never be proven for certain, from the moment the information is out of your direct control.
- rsync 4y agoDon't use your personal mobile phone for 2FA. Use a "2FA Mule" that is only for that purpose: https://kozubik.com/items/2famule/ https://kozubik.com/items/2famule/ I have the ringers silenced on mine so I wouldn't know if they got any spam calls ... and I assume they do ...
- Dave_TRS 4y agoGoogle Voice is free and will forward SMS's to email, which can then be set up with rules to various other emails. Most banks accept google voice numbers Twilio numbers are a dollar a month and will also forward to email or you can log into the twilio web interface to pick up sms codes if needed. Rejected by more places the demand 2FA
- runevault 4y agoSome services don't allow GVoice 2fa. I tried it for instagram because I refuse to give Facebook my real number and they rejected it.
- dpkirchner 4y agoSame, although my goal was to use a Google Voice number that could be shared amongst a team, for integrating with Facebook's APIs.
- realAzazello 4y agoAgreed. Definitely some USA banks do not (with one of my accounts, neither the SMS nor the automated call would come through the GV number), and although a few years since last I tried, craigslist would not accept GV for account verification.
- rsync 4y ago"Google Voice is free and will forward SMS's to email ..." ... "Twilio numbers are a dollar a month ..." I wanted very much to keep my telephony within twilio and maximize the mini-telco that I built for myself there ... however almost zero 2FA requirements can be fulfilled with "voip" numbers that are not honest-to-god mobile tagged phone numbers. That's the whole point of the 2FA Mule, etc.
- toomuchtodo 4y agohttps://reportfraud.ftc.gov/ https://reportfraud.ftc.gov/
- izzydata 4y agoAssuming this kind of thing is fraud how does it manage to even happen at a company as large as Facebook? Is it on accident through some reckless merging of databases or is it on purpose and they think they are just too big to care about laws? It seems like Facebook must know what the law is.
- foobarian 4y agoSeems like a case of scraping the bottom of the barrel in a panic
- MereInterest 4y agoMy guess would be institutional pushes against any checks on data usage. Somebody implements 2FA. Somebody reduces the number of redundant databases. Somebody implements a new marketing plan. Somebody audits their legal compliance, and finds nothing wrong because the database doesn't record the provenance of each entry. Individuals at Facebook know the law, and may even have individual incentives to follow the law. Facebook as an emergent entity, as an inhuman eldritch being built upon humans as component parts, cares nothing for the law.
- rkagerer 4y agoThis is why I really hate how the big players are gating user access through phone numbers and smartphones. Even government portals are copying the tactic. (I didn't agree to a draconian ToS recently for an online fee filing, and it took months and hours on the phone just to make a simple VISA payment).
- ok_dad 4y agoDidn’t Twitter just get hit with fines for this?
- humanistbot 4y agoYes: https://www.ftc.gov/news-events/news/press-releases/2022/05/ftc-charges-twitter-deceptively-using-account-security-data-sell-targeted-ads https://www.ftc.gov/news-events/news/press-releases/2022/05/...
- gamegoblin 4y agoI have a feeling that Meta has some kind of internal system for slurping up everyone's contact info, and that some kind of bugs/criteria occasionally cross some streams. Meta recruiting somehow got a hold of my name@amazon.com employer email -- which I have never posted publicly -- and started sending me recruitment emails to my work email. This struck me as incredibly unprofessional, though I understand it's almost certainly an automated system doing it. I still don't know how they got the email address (though I guess it's just lastname+first initial, so they could have guessed?). I may have DM'd it to someone in a FB messenger chat? Maybe I used it in an "work email" field during sign up for some industry conference whose data later got hacked? A colleague accidentally merged their work/personal contact list and uploaded it somewhere? Who knows.
- minraws 4y agogenerally most people check company then do, - firstname@company.email - firstnamelastname@company.email - firstname-lastname@company.email - firstname.lastname@company.email from the recruitment side, cause I have asked this question to my company's HR... :P hackers do it as well hence why I am always stressed about phishing, though recruitment mail on professional ids is still rather rare, recruiters also prefer to use personal email if available or so I have heard from a subset of them. Try checking if it maybe some kind of phishing scam, I have seen those a lot, recruitment phishing is like the most common case of successful phishing.
- gamegoblin 4y agoIt was definitely not phishing -- I had a friend of mine who works for Meta reach out to the specific recruiter internally and ask them to not do that. They apologized, but a few months later a different recruiter reached out to the same work email. They have my personal email, because they send recruitment spam to that one too.
- bryan_w 4y agoAre you sure it's not in LinkedIn system? That's where a lot of recruiters buy data from.
- Invictus0 4y agoYour anecdote isn't really evidence of anything and I'm skeptical that this is the case.
- thereare5lights 4y agohttps://en.wikipedia.org/wiki/Anecdotal_evidence https://en.wikipedia.org/wiki/Anecdotal_evidence
- codyZ 4y agoPerhaps I am an isolated incident and honestly hope for the sake of the community that it is. But they followed up with an email to my personal email tied to my personal email from sign up from @business.fb.com domain per their help center https://www.facebook.com/business/help/372703956148310 https://www.facebook.com/business/help/372703956148310
- usea 4y agoVote for candidates that support stronger consumer protection and data privacy laws. Do not give your personal information to companies that do not directly need it for the service you're engaging in. Delete your facebook accounts yesterday. Services that require a phone number like twitter, discord, blizzard, signal, twitch, etc are giving you a heads up that they're abusive and will work against your interests. Stay far away.
- cmatthias 4y agoIf you are in the USA, then what you received are unsolicited marketing phone calls under the TCPA, a law which allows you to personally collect up to $1500 per violation of the law or associated regulations, per phone call that you received. If your personal phone is on the federal "Do Not Call" registry, it's possible that there are at least two violations of the law per phone call you received. I would suggest sending a demand letter to Meta's legal department offering to settle for somewhat less than $1500 per violation. Here's an example: https://www.junkfax.org/w/images/0/0b/SampleDemandLetter.pdf https://www.junkfax.org/w/images/0/0b/SampleDemandLetter.pdf If they ignore you, be prepared to file a local case in small claims court (which you can do yourself without an attorney). The court can force them to pay you if you present evidence of the calls and the law(s) or regulations that were broken. Disclaimer: I am not a laywer and this is not legal advice, but I have collected money from TCPA legal settlements in the past, each without needing to go to court.
- ignite 4y agoI thought that companies you are doing business with are allowed to call you. He has an account, they can call. Also not a lawyer.
- cmatthias 4y agoThe TCPA requires express written consent to send marketing messages or phone calls to any personal phone number. Legal precedent dictates that online, this usually takes the form of a specific checkbox on the form where you're giving your phone number saying that you agree that the company can use the phone number for marketing purposes. I doubt Meta collects this type of express written consent for your 2FA phone number, but I guess it's possible. There indeed used to be an exemption to the law involving an existing business relationship, but 1) this was only for residential land lines and never applied to cell phones, and 2) it was revoked on October 16, 2013. [1] [1] https://tcpablog.com/new-tcpa-regulations-take-effect-on-october-16th/ https://tcpablog.com/new-tcpa-regulations-take-effect-on-oct...
- Jochim 4y agoI'd assume in this case that they'd be allowed to call his business. It sounds like his personal contact details are entirely separate from his business ones. I don't believe they should ever be using personal details to contact a business. Even if he did provide them his phone number. In many places, that data may only be used for the purpose for which it was given. If they request a phone number for 2FA and then use it to contact you it could absolutely be considered illegal.
- ardit33 4y agoSounds like alarmist reaction without proper evidence. How do you even know it is Meta? Anybody can get your phone #, and it is super easy to get spam.
- codyZ 4y agoI also thought it was a scam call but they followed up with an email to my personal email tied to my personal email from sign up from @business.fb.com domain per their help center https://www.facebook.com/business/help/372703956148310 https://www.facebook.com/business/help/372703956148310
- pengaru 4y agoI have a bridge to sell anyone who actually believed companies requesting your phone number for "security" purposes wouldn't make that information available to the rest of their business activities.
- nicolashahn 4y agoIt's more likely that you gave your phone number out somewhere more sketchy. The personal email thing sounds like straight fraud. As someone who works for Meta and and sees all the privacy trainings and the hoops you have to jump through to do anything with user data anymore at this company, someone is definitely getting fired for this if it was indeed Meta's fault and intentional.
- rodric 4y agoYou should probably use an app like Aegis (Android) or Raivo (iOS) for two-factor authentication rather than your personal phone number.
- therealmarv 4y agoFB does not allow you to use 2FA apps like that without giving them a phone number first (at least this is how it worked in the past).
- rodric 4y agoShame if that is (or was?) the case, but it hasn’t been my experience at least.
- kleinsch 4y agoThey already paid a multi billion dollar fine for misusing 2FA phone numbers and have insane process to prevent this specific scenario. Way more likely that OP put their phone number somewhere else.
- persedes 4y agoDid not get a sales pitch, but added my phone number as 2FA a couple days ago and started receiving FB notifications via text msg. Despite having muted all FB notifications years ago.
- celestialcheese 4y agoFacebook is the absolute worst with this, Google second. We spend >$10m on ads annually on FB, yet haven't had a dedicated account rep since 2019. Instead, they farm out "account marketing specialists" who pitch you on giving up more control to FB algo and generally have significantly less insight and experience with FB ads than the people they are calling. One week last summer, I received 8 calls in a single day from different FB marking reps. I think they had some kind of call queue system based on the number of ad accounts, instead of on "Business manager" accounts, but it took a lot of firmly saying "Remove me from this list" and accusing them of phishing to get it to stop. I just assumed I gave my cell to FB at some point, never thought of 2FA.
- xvector 4y agoIt probably wasn't Meta but some scammers.
- deleted 4y ago[deleted]
- crazygringo 4y agoJust to be clear... You're absolutely sure, 100%, this is Meta employees themselves calling you? And Meta sending you e-mails? Not spammers, of which there are many, and they get your contact info from all sorts of places? And which often lead you to believe they're Meta when they're really just scamming you or trying to sell ad placement consulting/optimization services? Because with "multiple" calls and emails... this sounds like 3rd-party spammers, not something Meta does. And while Meta has been loose in the past with walling off information internally (to put it mildly...), it's not like they sell your contact info to spammers or anything (simply because it's not worth the effort, the money's way too small for a company of their size). Third-party spammers, on the other hand, will get your personal info from anywhere and everywhere. For you to make a credible claim that Meta is using your 2FA contact info for marketing, you've really got to be sure that it's 1) actually Meta contacting you and 2) that they got your phone number specifically from 2FA and not just from looking it up publicly the way salespeople do.
- codyZ 4y agoIndeed it is. I too thought that perhaps it was a scam. But the call was followed up by an email from business.fb.com and per their Help Center, it is indeed from Meta https://www.facebook.com/business/help/372703956148310 https://www.facebook.com/business/help/372703956148310
- BenjiWiebe 4y agoNote that the from address doesn't necessarily indicate where the email actually came from.
- ohmanjjj 4y agoGotta pump up the numbers before market close and earnings
- deleted 4y ago[deleted]
- MarinaTownson 4y ago