Meta says it applies the principles of asymmetric design to build systems with the assumption that attackers will try to exploit them, rather than ignoring the reality of these risks and being caught off guard.

When you build a system, you roll it out slowly and watch for how it gets exploited, and then you rapidly build systems to protect it. It's important to be careful about being purely reactive. We have built a system that relies on a combination of strategic foresight, tabletop exercises, red teaming, blue teaming, purple teaming, and put people together to take a new product that we are considering.

Meta plans to use some of the same signal analysis methodology to give more nuanced warnings to users for Facebook Messenger andInstagram when they may be at risk of being phishers or fake accounts.

Meta says it is hard to bring all of these components together without accidentally blocking legitimate content or locking people out. Helping more users get back into their accounts is good for retention and good for business.

Gleicher says that it's not a compromise targeted at Meta assets when bad actors compromise email. We have a lot of users and we have a lot of responsibility.

Strong unique passwords, using a password manager to keep track of them all, and enabling two-factor authentication are the best protections for your online accounts.