Live data from Hacker News

Facebook Is Giving Advertisers Access To Your Shadow Contact Information

gizmodo.com

31–40 of 478 posts

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#31
post #28

When people suggested phone 2fa was a data collection scheme they were hushed and called tinfoils.

People still do that when you point out that using a phone number as a required identifier (WhatsApp, Signal, etc.) gives every 'free' service a near perfect unique identifier that's the same for all services used by that person. Ideal for cross-service collation.

Who wants a social security number when you've got someone's phone number?

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#32
post #4

The reason I never give fb my mobile is if you use a pseudonym account, it will suggest your profile as a friend to anyone who has your mobile in their phone contact list (eg ex-partners, stalkers, employers, drug dealers). Found that one out the hard way. I know Zuck wants me to preemptively upload my nudes, but still.

You can even do a search by mobile number, by typing a mobile number into the search without pressing enter.

Depending on the owner's security settings, Facebook will often suggest the profile of the person in the type-aheaded search results.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#33
post #25

The other really stupid thing, besides generally hurting the adoption of 2FA forever, is that they probably did it for hardly more than scraps, compared to their conventional add targeting capabilities. Maybe I am completely wrong about this, but I'm pretty convinced that almost all of the ad spending for that feature would have reached Facebook's coffers anyways had it not been available.

At Facebook's scale even the scraps can be worth millions.

And the sad truth is that the vast majority of people will not be deterred by, be aware of, or even understand the fact that Facebook is abusing their phone number in this way, so as far as Facebook is concerned it's a small bump in the long road to increased profitability.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#34
All my personal details on Facebook are (and have always been) false. My phone number is the number of a hotel in Monte Carlo. When Facebook nagged me to give them my mobile number for 2fa I ignored them. My friends thought I was crazy. I know it's not exactly gracious of me but feeling very self righteous right about now.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#35
post #21

Another personal observation. I have an Instagram account that I thought was fully incognito. I never connected it to any other social account, I used a separate email for authentication etc. Just days after the Instagram founders left Facebook I started receiving friend suggestion on my IG that were very very relevant. Those were people I knew in real life and mostly connected via Facebook but not only. I shouldn't…

Haven't you used the same web browser for both, Facebook and Instagram? They might just be sharing cookies.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#36
This should have been obvious for anyone who is paying attention.

When data collection and advertising companies such as Facebook (and Google) push a feature actually beneficial to users so aggressively – such as 2FA – during the sign-up process; you'd have to be naive to think it's for your benefit.

It's not 2007 any more... tech savvy users should know better than to trust such organisations with any scrap of additional personal information than absolutely necessary.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#37
post #6

Phone numbers were not a secure 2FA anyway, and I've been using the TOTP alternative since it's been available... but I don't really see a problem with them using whatever to show "more relevant ads", if you don't want ads just use an ad blocker.

Likewise, passwords fail to protect against a whole class of attacks. I don’t know why Facebook still uses them.
Post reply on HN