Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Worth noting. Some users have found they are unable to delete their Facebook account because, when they are asked to enter their password on the final screen, FB says the password is incorrect.

Seems FB has a bug where you must enter your password in all lower case on the final screen.

Imagine, big company like FB, having still not caught that bug....



Actually, that's intended behavior.

https://security.stackexchange.com/a/68014/47800


They can accomplish that feature using 3 separate hashes for various common mistakes, and it will still accept the normal case, but what GP is describing is that only a lowercase version of the password will work for account deletion.


It's most likely that they're using lower(password) everywhere, except someone forgot to use that on the account deletion page and no one noticed.


How convenient that they forgot to use it on the one action they never want you to perform


That's fascinating. Couldn't they just detect the caps lock being on and warn the user instead?


That certainly makes more sense for desktop users. But remember the UX dark pattern for mobile touch screen devices: default is to capitalize the first letter of every sentence. On particularly old devices even in password fields have this.

No caps-lock key on many of those keyboards. And, no warning that the shift key has been single-key or perma-pressed.


Reminds me of when I try to unsubscribe to a random newsletter. If it seems tedious to do so, even in the slightest, I don’t even bother googling or looking through the source’s website and ultimately move on. Wonder if this is what fb is trying to do.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: