Facebook's Delegated Recovery Method Tries to Improve Upon Two-Factor Authentication

Advertisement
By Shekhar Thakran | Updated: 31 January 2017 12:36 IST
Highlights
  • Facebook has open sourced the feature for wider application
  • The tokens generated as part of this method are encrypted
  • The new feature is also eligible for company's bug bounty programs

Facebook has announced a new recovery tool, called Delegated Recovery, which aims to help users in improving their account security. The social media networking site has released the new feature in collaboration with GitHub in a limited manner in order to get customer feedback but has shared the protocol behind this feature so that more services can adopt the recovery design going ahead. Notably, the company last week added a NFC-based two-factor authentication, alongside support for physical security keys.

The Delegated Recovery method is being demonstrated on GitHub, and makes use of encrypted tokens that are stored in users' Facebook accounts. These allow users to get back into their GitHub account in case they lose access. As these tokens are encrypted, Facebook says that it cannot read users' personal information. The tool is said to be an additional authentication method that can supplement two-factor authentication.

Facebook Launches NFC-Based Two Factor Authentication Process for Added Security

Advertisement

"If you ever need to recover your GitHub account, you can re-authenticate to Facebook and we will send the token back to GitHub with a time-stamped counter-signature. Facebook doesn't share your personal data with GitHub, either; they only need Facebook's assertion that the person recovering is the same who saved the token, which can be done without revealing who you are," Facebook said in a note on its website.

Advertisement

The social networking firm says that going ahead, it wants to give users' the option of recovering access to their Facebook account using other accounts such as GitHub. The company wants to essentially improve upon the traditional password recovery tools such as security questions, which it says are inconvenient as well as risky.

"Recovery emails and SMS messages are common alternatives, and while they can get the job done, both are showing their age: neither offers the end-to-end security guarantees we expect from modern protocols," it added.

Advertisement

"GitHub maintains direct control of how it authenticates its users, how it assesses password strength and other risk signals, and how it deploys a diverse set of two-factor authentication methods.

So what do you do if you lose access to the phone number or security keys you use at GitHub? An email address alone can't provide the same level of two-factor authentication to recover access, so starting Tuesday, you'll be able to use your Facebook account to provide additional authentication as part of the recovery process at GitHub," the company elaborated on the motive behind the method.

Advertisement

The new feature has also been associated with Facebook's bug bounty programs to allow researchers to find out the existing flaws and vulnerabilities in the new recovery method. Considering that tokens for all supported websites will be stored in your Facebook account, it is likely to become a hub of users' online account information.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. OTT Releases of the Week: Dude, Nishaanchi, Jolly LLB 3, and More
  2. Moto G100s Could Launch With This Chipset, RAM
  3. Oppo Reno 15 Series India Launch Timeline, Price, Key Features Leaked
  4. Vivo X300 Series Teased on Amazon Ahead of Launch in India
  5. OnePlus 15 Launching Today: Everything You Need to Know
  6. Vivo V70 Reportedly Spotted on Geekbench With Snapdragon 7 Gen 4 SoC
  7. Valve Unveils Steam Machine PC/ Console Hybrid: Everything You Need to Know
  8. OnePlus 15: Everything We Know Ahead of Tomorrow's India Launch
  9. PhonePe Partners With OpenAI to Integrate ChatGPT Within the UPI App
  10. Realme GT 8 Pro Camera Details Confirmed Ahead of Nov 20 India Launch
  1. Microsoft 365 Personal With Copilot Is Now Free for Students for One Year
  2. Jonathan Bailey’s Wicked is Now Streaming Online: Know Where to Watch This Film
  3. Marutham OTT Release Date: When and Where to Watch Vidaarth’s Emotional Drama Online?
  4. Oppo Reno 15 Series India Launch Timeline, Price Leaked; May Pack Different Chipset Than China Variant
  5. Meta’s Chief AI Scientist Yann LeCun Reportedly Planning Exit to Become a Startup Founder
  6. Vivo V70 Reportedly Spotted on Geekbench With Snapdragon 7 Gen 4 SoC
  7. Dímelo Bajito (Tell Me Softly) OTT Release Date: When and Where to Watch it Online?
  8. One Man: Multiple Dangers is Now Streaming on Lionsgate Play
  9. Bitcoin Trades Near $103,600 as Market Awaits Clearer Macro Direction
  10. Delhi Crime Season 3 Now Streaming on Netflix: Everything You Need To Know About Plot, Cast, and More
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.