The Register® — Biting the hand that feeds IT

Feeds

Facebook user locked out of account even with ID

Your name's not down, you're not coming back in

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

A Facebook user shut out of the service due to a glitch last Tuesday was locked out for a further two days even after she proved her identity.

The case of Christine C, a US-based marketing executive who asked us to withhold details of the organisation she worked for, raises wider questions about Facebook's handling of the problem.

The issue was triggered when the social network's system for detecting fake accounts went awry. The bug resulted in a sizeable but unconfirmed numbers of (seemingly all female) Facebook users being locked out of their accounts.

Exiled users were told that they were using an "inauthentic" name, and asked to send in an image from a government-issued ID card1 in order to unfreeze their account.

Christine duly submitted her picture, but was given the cold shoulder and informed that the account had been permanently suspended, via the following terse communique in a email entailed Disabled Account Appeal-ID Request and sent in the early hours of Wednesday morning.

Hi,

Fake accounts are a violation of our Statement of Rights and Responsibilities. Facebook requires users to provide their real first and last names. Impersonating anyone or anything is prohibited, as is maintaining multiple profiles on the site. Unfortunately, we will not be able to reactivate this account for any reason. This decision is final.

Thanks for your understanding,

The Facebook Team

Christine was understandably nonplussed by this response and got in touch with us after reading our article on the mix-up. "My Facebook account is legit and I only have one, so I am not managing multiple identities," she told El Reg. Christine uses the account for work reasons, using it to manage two groups, and the permanent exile of her account would have meant handing over the reins for this to a colleague.

After periodically checking whether her account had been reinstated, Christine was confronted by a different message2 suggesting she may have been the victim of a phishing attack.

Suspicious activity has been detected on your Facebook account and it has been temporarily suspended as a security precaution. It is likely that your account was compromised as a result of entering your password on a website designed to look like Facebook. This type of attack is known as phishing.

Christine told the Reg that her account was reinstated shortly after we first exchanged emails with her last week, with apologies from Facebook for the cock-up.

We apologize for the inconvenience you have experienced. Your account was disabled in error. Your account has been reactivated and you will now be able to log in.

We are yet to hear back from Facebook.

It's unclear if Christine's account was reinstated due to our intervention or as part of the wider reactivation process, which seems likely. Quite why Facebook didn't rescind account disactivations as soon as it was sure its control systems had gone awry remains unclear.

Its requests for the upload of confidential ID documents also seems like overkill; all the more so if the case of Christine is more than just an isolated case of someone getting locked out of the social network even after meeting its demands.

The experience has left Christine with a negative view of the social network.

"Facebook doesn't seem to be very good for security and I'd be reluctant to sign for any other services it offers," she said. ®

Bootnote

1Security firms, such as Sophos, have expressed reservations about uploading images of sensitive government-issued ID documents to Facebook. "Even if other data is obscured, there's still a risk [from] electronic copies of these sensitive identification documents lurking on users' hard drives for months if not years after this incident is long forgotten," it said.

2Cybercrooks unsurprisingly took advantage of the confusion caused by the suspension of multiple legitimate accounts to launch a campaign designed to trick users into open a booby-trapped message that posed as an email from Facebook support. The Asprox spam campaign was designed to spread a Trojan, as explained in a blog post by M86 Security here.

Agentless Backup is Not a Myth

WTF...

... would anyone with more than one brain cell use Facebook 'for work reasons' or anything other than idle chit chat about the latest soap episodes. FFS.....

6
0

Gov-issued ID's

1)Scan your passport

2)Submit it to an internet service known for its security

3)Find out in the news, that you've just participated in Mossad operation somewhere in Dubai

4)??????

5)PROFIT!!!!!!

AC, obviously.

5
0

How lucky can you get

"Christine duly submitted her picture, but was given the cold shoulder and informed that the account had been permanently suspended,"

All those people that have tried to close their accounts and failed must be insanely jealous.

5
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving