Hacker News new | ask | show | jobs
by tytso 1562 days ago
Since you live in San Francisco, a number of companies (I know for sure Facebook and Google) have ways where you know somone who works at that company, and who can vouch for you, they can help you get control back to an account that has been lost or taken over by someone malicious. Maybe you know someone at those companies? The companies themselves generally don't advertise this, because it obviously doesn't scale, and they'd be concerned with people who try to strike up a "friendship" with an employee just so they can backdoor access to an account --- this is something that can be used as a security attack vector as well! (So it works best for, "I've known this person for the last X years, and last month they completely lost control over their account. I can say for sure they are who they say they are and not a conman or a state-sponsored intelligence agent." sort of thing.)

Other than that, what I try to tell everyone to use 2FA authentication, and not just SMS text messages or TOTP's, but FIDO Security Keys to protect your digital identity. Never reuse passwords and use a password manager, yadda, yadda, yadda.

1 comments

> and they'd be concerned with people who try to strike up a "friendship" with an employee just so they can backdoor access to an account

They should be concerned about this enough to change that policy even without it being generally known