Facebook SMS spam sullies the name of 2FA  - facebook lock - Facebook SMS spam risks spoiling adoption of 2FA

It’s hard enough to get people to use two-factor authentication () without a problem like Gizmodo reports of sending unwanted texts to users’ phones:

“I’ve been getting these - messages since last summer, when I set up a new Facebook account and turned on two-factor authentication…

At first, I only got one or two texts from Facebook per month. But as my profile stagnated, I got more and more messages. In January, Facebook texted me six times—mostly with updates about what my ex was posting. This month, I’ve already gotten four texts from Facebook. One is about a post from a former intern; I don’t recognize the name of one of the other “friends” Facebook messaged me about.”

If you’re similarly stalked by spammy Facebook text messages, there’s fortunately a way to opt out. Go to Settings, choose Notifications, and ensure that notifications via text are disabled.

Facebook notification settings  - fb txt 600 - Facebook SMS spam risks spoiling adoption of 2FA

Facebook security chief Alex Stamos has said that the unwanted text messages were not sent intentionally – but were the result of a bug:

“It was not our intention to send non-security-related SMS notifications to these numbers, and I am sorry for any inconvenience these messages might have caused. We are working to ensure that people who sign up for two-factor authentication won’t receive non-security-related notifications from us unless they specifically choose to receive them, and the same will be true for those who signed up in the past. We expect to have the fixes in place in the coming days. To reiterate, this was not an intentional decision; this was a bug.”

But don’t forget that there are strong arguments for choosing a form of authentication that doesn’t involve you giving your mobile number to Facebook in the first place. After all, that’s data that Facebook will use to try to match you up with potential Facebook friends who shared their contact lists with the social network.

Using a U2F security key or code generator for Facebook two factor-authentication is probably a better way to go.

It’s good that Facebook is fixing the issue, but what a shame that this latest faux pas will have damaged the reputation of two-factor authentication when it is so clearly needed.

Read more about two-step verification:

- aa9ea0686c5d1aa9086d4b12c3aa05f2 s 80 d mm r g - Facebook SMS spam risks spoiling adoption of 2FA

About the author, Graham Cluley

Graham Cluley is a veteran of the anti-virus industry having worked for a number of security companies since the early 1990s when he wrote the first ever version of Dr Solomon’s Anti-Virus Toolkit for Windows. Now an independent security analyst, he regularly makes media appearances and gives presentations on the topic of computer security and online privacy.

Follow him on Twitter at @gcluley, Google Plus, Facebook, or drop him an email.

Follow @gcluley

Source link


Please enter your comment!
Please enter your name here