Facebook's Delegated Recovery Method Tries to Improve Upon Two-Factor Authentication

Advertisement
By Shekhar Thakran | Updated: 31 January 2017 12:36 IST
Highlights
  • Facebook has open sourced the feature for wider application
  • The tokens generated as part of this method are encrypted
  • The new feature is also eligible for company's bug bounty programs

Facebook has announced a new recovery tool, called Delegated Recovery, which aims to help users in improving their account security. The social media networking site has released the new feature in collaboration with GitHub in a limited manner in order to get customer feedback but has shared the protocol behind this feature so that more services can adopt the recovery design going ahead. Notably, the company last week added a NFC-based two-factor authentication, alongside support for physical security keys.

The Delegated Recovery method is being demonstrated on GitHub, and makes use of encrypted tokens that are stored in users' Facebook accounts. These allow users to get back into their GitHub account in case they lose access. As these tokens are encrypted, Facebook says that it cannot read users' personal information. The tool is said to be an additional authentication method that can supplement two-factor authentication.

Advertisement

Facebook Launches NFC-Based Two Factor Authentication Process for Added Security

"If you ever need to recover your GitHub account, you can re-authenticate to Facebook and we will send the token back to GitHub with a time-stamped counter-signature. Facebook doesn't share your personal data with GitHub, either; they only need Facebook's assertion that the person recovering is the same who saved the token, which can be done without revealing who you are," Facebook said in a note on its website.

Advertisement

The social networking firm says that going ahead, it wants to give users' the option of recovering access to their Facebook account using other accounts such as GitHub. The company wants to essentially improve upon the traditional password recovery tools such as security questions, which it says are inconvenient as well as risky.

"Recovery emails and SMS messages are common alternatives, and while they can get the job done, both are showing their age: neither offers the end-to-end security guarantees we expect from modern protocols," it added.

Advertisement

"GitHub maintains direct control of how it authenticates its users, how it assesses password strength and other risk signals, and how it deploys a diverse set of two-factor authentication methods.

So what do you do if you lose access to the phone number or security keys you use at GitHub? An email address alone can't provide the same level of two-factor authentication to recover access, so starting Tuesday, you'll be able to use your Facebook account to provide additional authentication as part of the recovery process at GitHub," the company elaborated on the motive behind the method.

Advertisement

The new feature has also been associated with Facebook's bug bounty programs to allow researchers to find out the existing flaws and vulnerabilities in the new recovery method. Considering that tokens for all supported websites will be stored in your Facebook account, it is likely to become a hub of users' online account information.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Portronics Launches Vayu Nano Tyre Inflator in India at This Price
  2. Mysterious Stacked Rocks Spotted by NASA Perseverance Rover on Mars
  3. New OTT Releases This Week: Dhurandhar: Raw and Uncut, Desi Bling, System, and More
  4. Google Said to Sell Over 2 Million Android XR Smart Glasses in 2026
  5. Realme 16T Launched in India With 50-Megapixel Main Camera, 8,000mAh Battery
  6. Samsung's One UI 8.5 Update Rolls Out to These Galaxy Phones, Tablets
  7. Realme 16T 5G Review: The Pro Looks at an Affordable Price
  8. Honor Magic 9 Series Could Launch in China With These Notable Upgrades
  1. Bhojpuri Bawaal OTT Release Date Reportedly Revealed Online: Know Everything About This Upcoming Reality Series
  2. Mysterious Stacked Rocks Spotted by NASA Perseverance Rover on Mars
  3. Meta Launches Forum App as a Reddit-Like Platform for Discussions With AI-Powered Assistant for Admins
  4. Xiaomi 17T Series Teased to Arrive in Two Display Variants; Colour Options Revealed Ahead of Debut
  5. Honor Magic 9 Series Could Feature 8,000mAh Batteries; Tipster Leaks Camera, Display Upgrades
  6. Google Might Sell Over 2 Million Android XR-Powered Smart Glasses This Year: Report
  7. Google's Pixel Glow Feature for the Google Pixel 11 May Have Accidentally Leaked During Google I/O 2026
  8. iQOO 16 Global and Indian Debut Seemingly Confirmed as Handset Gets Listed on IMEI Database: Report
  9. Motorola Edge 70 Pro+ Camera Details Confirmed, WIll Arrive in Three Colourways
  10. Oppo Reno 16 Bags BIS, TUV SUD and TDRA Certifications That Hint at Imminent Global Debut
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.