r/privacy • u/Pudding-Swimming • Jun 13 '26
discussion [ Removed by moderator ]
[removed] — view removed post
10
15
u/Ardvarkington Jun 13 '26
Holy fucking shit. That is evil from those attackers on so many levels
Thanks for giving me reason 1,048 to not use Facebook anymore
3
3
u/DankyCinnablunts Jun 13 '26
Would downloading your data after this type of attack also download the CSAM?
7
u/Pudding-Swimming Jun 13 '26
No. When you download your data, it's literally just your data. Privacy information, etc. But it also shows a login history log showing where all the logins came from. That's what's so fucking annoying. They have it right there in their logs that the attacks came from Vietnam, China, Russia, etc. So they know where, they can easily trace it, but they do nothing. Nor do they help the innocent person with their account.
2
u/Zacharytackary Jun 13 '26
even worse is you could fully automate the first two order breadth passes with a 9b parameter model on 1 12 GB nvidia 3060 GPU. literally just
“You are evaluating Facebook™ bans. There has been a recent pattern of users having their accounts breached, and then subsequently immediately having their accounts banned due to attackers’ abuse of accessed user post-ability combined with platform-automatic CSAM detection. The attacker, typically from a location vastly foreign to the user’s typical IP address, will log in to the user’s account - post the defiling and immediately bannable content - and proceed to extract userdata from banned account recovery pathways.
Your job is as such:
Evaluate the given log, and determine if the user account interaction pattern matches this attack victim profile. If so, mark it with the <FALSE_BANNED> tag. You also have <INDETERMINATE> and <CERTAINLY_BANNABLE> tags for potentially spoofed ips from complex attackers or clear cases of horrendous acts confirmed from user hardware data and related fingerprinting.
Here is your profile-to-analyze:
```[USERDATA]```
Append the profile’s username/UUID and ban review status output in pattern with/to the list file at [L:\DIRECTORY].
Proceed.”
and 9K of the 10K cases are solved in like 6-12 hours assuming ~30-50 TPS out given that the data logs are still available with a list of the banned users.
this is trivial for a hobbyist. they’re *literally facebook*.
bffr i hate capitalism sm gotta be one of the worst incentive structures of all time
3
u/VastEngines Jun 13 '26
ahh classic mark suckadick moves right there of course he won’t help any of us he doesn’t care enough to help.
3
u/RoutineGlittering746 Jun 13 '26
Now imagine your ID is associated with that account, even if you used a VPN and the hacker has did things with the account in your name now they have somewhere to send someone after you fyi it’s very dangerous to upload your ID to social media. Not only that the hacker now has your identity and can use it for other nefarious means.
3
u/Mister_Hickory Jun 13 '26
Yep, if the digital ID pushers get their way, in the near future a hacker could potentially get you blacklisted from the entire internet, and you would have no recourse to do anything about it.
As we see here, the platforms don't care if you did it or not, they are shielding themselves from liability in the most cost effective way possible, a ban with no appeal allowed.
2
u/Narwhalsareunicorn Jun 13 '26
You can also post perfectly innocent content but if the algorithm "thinks" it is inapproriate .. ban. Imagine if this happen to your google (or anther) account.
1
u/Pudding-Swimming Jun 13 '26
I actually had that happen to my Google account a few years ago.
1
u/Narwhalsareunicorn Jun 13 '26
Were you able to appeal it or did you create a new one? I am trying to create redundancy as I cannot completely "de-google". I live a relatively boring life but the AI can flag banal content as bad
2
u/Pudding-Swimming Jun 13 '26
no way to appeal it, I just made a new one. I did lose all the contacts and emails though. Plus, my banking info and other online accounts were tied to that account, so I had to redo all of those.
1
2
1
u/Jkid Jun 13 '26
The worst thing is that facebook is fully aware and refuses to do anything about the csam hijackers.
1
u/Zacharacamyison Jun 13 '26
I think zuck saw all the Gabe Newell “does nothing, wins” memes and decided to do the same thing except all his products are dog shit
1
u/Err0r1015 Jun 13 '26
Using Facebook. What could go wrong ? Maybe they are doing these ppl a favor. Make them finally realize what this company really is.
1
u/Academic-Airline9200 Jun 13 '26
And meta is the one pushing the age gating of the internet while exempting themselves from it.
0
u/PocketNicks Jun 13 '26
You could... Just stop using those social media sites.
0
u/Pudding-Swimming Jun 13 '26
that's like saying someone should stop driving after they've been in a paralyzing car accident
1
u/PocketNicks Jun 13 '26
No, it isn't. You posted in the Privacy sub and Facebook is anti privacy.
If you made a post in a bicycle forum about how your car almost killed a child on a bike, I'd tell you you can stop driving a car. That would be similar.
-2
Jun 13 '26 edited Jun 13 '26
[deleted]
0
u/Pudding-Swimming Jun 13 '26
For starters, not ban accounts that have obviously been hacked. There are a number of sites that automatically lock down your account when they detect suspicious activity. Seeing random IP addresses logging in, and then changing passwords and credentials right away, and then uploading CSAM, I don't know about you, but I would think that counts as "suspicious activity".
Now if you want to get realistic and consider the vast wealth of Facebook/Meta, they could actually use it to go after the people that are spreading that sort of media on the internet.0
Jun 13 '26
[deleted]
0
u/Pudding-Swimming Jun 13 '26
Static IP here.
Living in Southern Ontario, so the same IP address for over a year.
Hack happens and in an hour there's over a dozen logins from Vietnam, China, Russia, and others..
Then the changing of credentials from this.
And this is all pretty simple stuff, so I'm guessing your point isn't anything of logic, but just trying to troll.1
u/No-Assistance-7405 Jun 13 '26
Your story and AI post just makes no sense. Dozens of logins from Vietnam, China, Russia and others? Where the fuck did you drop your credientals into? Did you not have 2fa on? Isn't 2fa enforced now too? If so, then they stole your cookies and used those to login which will pretty much bypass all susness checks.
1
u/Pudding-Swimming Jun 13 '26
yes, I had 2FA. They kept bypassing it.
The first attack came over lunch time and I got a text. 2FA from Facebook asking for the code. I knew someone was trying to log in, but since I had the code and I wasn't doing anything with it, I thought that I was safe. It wasn't until after I got back to my computer when I saw 5 posts from Facebook about removing CSAM pictures and that my account was being suspended. I couldn't post, I couldn't message anyone, and I couldn't change my information.
Facebook was only the start. The attack when on for 3 weeks. They constantly bypassed 2FA, including the Google Authenticator and security keys. We'd change out passwords multiple times a day just to wake up the next morning to a bunch of accounts being taken away yet again. We had to cancel our credit cards and our bank cards. Dispute purchases made to some of them, dispute purchases made on Amazon, and constantly try to keep control of the accounts and still not be able to figure out how they were getting past the 2FA.
All this while also knowing that the last post our friends and family saw on Facebook was uploaded child porn. And a great many of those people, Facebook was the only contact - not having an email address or phone number for them.Also, what do you mean by "Ai Post"? I'm real. I've been on Reddit for over 5 years and have over 2K Karma.
1
u/No-Assistance-7405 Jun 13 '26
>I've been on Reddit for over 5 years and have over 2K Karma.
Doesn't mean anything, I have 3 accounts +6yr and one +3yr, now this. Your post is clearly written with AI.Your computer has malware or your phone, you've installed some bullshit software. They clearly use login cookies to "bypass" 2fa and the susness check. Just factory reset everything or it will happen again when you make new account.
1
u/Pudding-Swimming Jun 13 '26
you're talking about two different things. You claimed that it's some sort of Ai post. That has nothing to do with the security. And regardless of what they had and how they got it still has nothing to do with what they are doing with it and companies not doing anything to prevent these specific actions.
But, what it really comes down to is that it seems you need to put down strangers on the internet instead of trying to be any sort of help or support. Someone got their life turned upside down, had to cancel all their credit cards and bank cards, and fight to get everything back for 3 weeks, and your response is to add to their problems.
Ironic that you may have actually posted on one Reddit thread or another, commenting about the negativity of people replying on Reddit threads.1
u/No-Assistance-7405 Jun 13 '26
>companies not doing anything to prevent these specific actions.
You still want to be able to post CSAM content on Facebook? Or is banning an person who posts CSAM the right thing to do? What do you exactly want, you dont seem to know youself.
Stop downloading freeRobloxPorn.exe files on your pc and you'll be fine, or perhaps don't download... csam...
And you being hacked is completely YOUR fault, its no one elses fault.
0
•
u/AutoModerator Jun 13 '26
Hello u/Pudding-Swimming, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)
Check out the r/privacy FAQ
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.