Facebook Introduces OTP (One-time Password) Functionality

The New Acunetix V12 Engine


Nice to see an innovation on the security front for once rather than endless ‘feature’ updates and announcements of ‘the next big thing’. Facebook has had its fair share of security woes so it’s nice to see they are doing something which I think may be genuinely useful for it’s burgeoning user base.

A lot of banks use a similar system labeled as a TAC (Transaction Authorisation Code) or similar when you want to carry out a transaction which involves moving money out from your account (bill payment, fund transfers etc).

Facebook began rolling out new service on Tuesday that allows people using public computers to log into the site without having to enter their regular password.

Instead, users can login with a one-time password that, upon request, Facebook zaps to their mobile phones. The temporary access code is good for 20 minutes only. The new feature is designed to prevent account compromises that result when credentials are entered into machines that have been compromised by keyloggers and similar types of malware.

“We’re launching one-time passwords to make it safer to use public computers in places like hotels, cafes or airports,” Jake Brill, a Facebook product manager, blogged here. “If you have any concerns about security of the computer you’re using while accessing Facebook, we can text you a one-time password to use instead of your regular password.”

I think it’s a useful thing for Facebook users on the move who may not want to use their proper password on a public computer in an airport or cybercafe for example as they may be infected with malware.

Of course the pessimists and conspiracy theorists will say Facebook is just running a ruse to gather more mobile phone numbers from their user base to leverage more data and improve their ability to suggest connections.


To use the service, users must first configure their accounts to work with a designated mobile phone number. When they text “otp” to 32665, they should immediately receive a password that’s good for the next 20 minutes. The feature is available to select Facebook users for now. Over the next few weeks, it will gradually become available to everyone.

Brill unveiled two other features that are also intended to give users more control over their accounts. One allows users to remotely sign out of accounts. It’s useful in cases when someone forgets to log off of a computer and only later realizes he’s still logged in. In the past, the person had to access the computer to be logged off, but the new service allows this to happen remotely. Users can check to see if they’re still logged in from their Facebook account settings page.

A third service will regularly prompt users to update their security information, Brill said. Facebook uses the information to verify users in the event a password is lost or compromised.

I’m not sure what country this service is rolling out in, but I’d guess it’s probably US-centric and will stay that way for some time. They should use an international number as it’s most likely you’d want to login from a publication location when traveling.

No doubt they’ll address some issues as for now the service is a testing phase and only available to certain users.

The other new security related features are remote log-out, which Gmail from Google has had forever – if you didn’t know about the feature just scroll to the very bottom of the Gmail window and you’ll see something like this:

Source: The Register

Posted in: Countermeasures, Cryptography, Privacy, Web Hacking

, , , , ,


Latest Posts:


How To Recover When Your Website Got Hacked How To Recover When Your Website Got Hacked
The array of easily available Hacking Tools out there now is astounding, combined with self-propagating malware, people often come to me when their website got hacked and they don't know what to do, or even where to start.
HTTrack - Website Downloader Copier & Site Ripper Download HTTrack – Website Downloader Copier & Site Ripper Download
HTTrack is a free and easy-to-use offline browser utility which acts as a website downloader and a site ripper for copying websites and downloading them for offline viewing.
sshLooter - Script To Steal SSH Passwords sshLooter – Script To Steal SSH Passwords
sshLooter is a Python script using a PAM module to steal SSH passwords by logging the password and notifying the admin of the script via Telegram when a user logs in.
Intercepter-NG - Android App For Hacking Intercepter-NG – Android App For Hacking
Intercepter-NG is a multi functional network toolkit including an Android app for hacking, the main purpose is to recover interesting data from the network stream and perform different kinds of MiTM attacks.
dcipher - Online Hash Cracking Using Rainbow & Lookup Tables dcipher – Online Hash Cracking Using Rainbow & Lookup Tables
dcipher is a JavaScript-based online hash cracking tool to decipher hashes using online rainbow & lookup table attack services.
HTTP Security Considerations - An Introduction To HTTP Basics HTTP Security Considerations – An Introduction To HTTP Basics
HTTP is ubiquitous now with pretty much everything being powered by an API, a web application or some kind of cloud-based HTTP driven infrastructure. With that HTTP Security becomes paramount and to secure HTTP you have to understand it.


One Response to Facebook Introduces OTP (One-time Password) Functionality

  1. Bogwitch October 14, 2010 at 12:21 pm #

    Please forgive my cynicism. Isn’t this just another way for Facebook to ensure they have your mobile telephone number?

    Facebook points to 127.0.0.1 in my HOSTS file….