Live data from Hacker News

Facebook Is Giving Advertisers Access To Your Shadow Contact Information

gizmodo.com

201–210 of 478 posts

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#201
post #193

Earlier quoted context omitted.

You can do it with Gmail to some extent already. E.g. instead of using myemail@gmail.com I would use myemail+facebook@gmail.com. Gmail ignores anything after the plus. As someone mentioned, marketing companies usually share just the hash of email. The trick is not too popular and I didn't experience a company handling it yet.

The "trick" is both popular and commonly made to be moot by programmers. Source: I know programmers at multiple companies that have written production code to strip the +suffix from the username portion of gmail addresses.

If someone does that with one of my (custom domain) addresses, it won’t work, here’s what I implemented: https://zackorndorff.com/2015/03/10/disposable-email-address...

(To save you a click, they look like aa_COMPANY+SHORTHASH@mydomain.com, with shorthash being based on COMPANY and a secret)

Downside is the address ends up absurdly long, and I’ve had to manually create some aliases for companies that won’t accept the plus.

I don’t recommend this setup, it’s kind of a pain to maintain, but I wish one of the mainstream providers would implement something similar.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#202

It's also entirely what I expected, hence why I haven't given Facebook my number. Not sure why anyone is surprised by this to be honest.

The second one person with your phone number as a contact downloads the Facebook malware app, they have given Facebook your phone number.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#203

Earlier quoted context omitted.

> And I think Apple made it "easier to use SMS 2FA" in iOS 12 for the same reason. Wait. You think Apple is selling your phone number to advertisers?

That person is confusing different things. Apple is making it easier to use SMS 2FA in iOS 12 (automated copy paste) However Apple itself doesn’t use SMS for 2FA. As for Apple they had your phone number since the launch of the iPhone (!). Never needed 2FA to know it. And no, Apple isn’t selling your phone number.

>Apple isn’t selling your phone number.

Until they have bad iphone sales.

Given Apple's less than stellar track record toward developers, employees, and customers, Apple will do things for Apple.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#204

All my personal details on Facebook are (and have always been) false. My phone number is the number of a hotel in Monte Carlo. When Facebook nagged me to give them my mobile number for 2fa I ignored them. My friends thought I was crazy. I know it's not exactly gracious of me but feeling very self righteous right about now.

Your friends also gave Facebook your actual phone number too....

Facebook app abuses your phones internal Contacts API.

Effectively, you are linked and your main Facebook account is known to be a pseudonym already

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#206

Earlier quoted context omitted.

When I was in another country on a business trip I bought a temporary local SIM, originally valid for two weeks but I've kept it active as I travel there often. I used that foreign number to create my Instagram account and I've gotten the benefit of only being shown suggested accounts from locals from that country (zero people I know). Same goes for ads as well. Currently I keep it on roaming and actually use it to v…

Just as a warning to anyone who might try this, it won't work. (At least not without a massive amount of opsec effort expended on your side.) I'll give you an example of why it might not work. Since your phone has roaming, you happen to have it with you at work, or at a party, or at the library, or anywhere really. If even a single acquaintance of yours is "nearby", the information is leaked. If acquaintances seem to…

While one would think that this is only important for things you're doing that you don't want the government to know about (see [1] page 52 for details on how not to mess this up -- basically don't have them turned on together, don't turn one off and turn the other on in the same place, or log in to the same sites or store the same numbers on both phones), it's also important for Facebook and other private tracking. If you have Facebook on your burner phone and your friends have Facebook on their phones with location enabled, it's over [2].

[1] https://www.defcon.org/images/defcon-22/dc-22-presentations/...

[2] https://splinternews.com/facebook-is-using-your-phones-locat...

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#208
post #97

Earlier quoted context omitted.

Small question: how do you prove it, adequately for a court of law? I imagine that to prove it, you'd have to make several accounts, with several phone numbers, and somehow demonstrate to a judge that the information leaks through. Not an easy task.

It's "easy". 1. Ask for the judges phone number 2. Register new account with judges phone number (clean browser, no friends added or pages liked) 3. See friend recommendations from the judge in this new FB profile.

wouldn't be surprised if FB kept a list of regulators and judges whose information is treated differently from the rest of us.

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#209
post #90

Earlier quoted context omitted.

Most internet service companies, including Facebook and Google, don't give you the option of paying for privacy even if you wanted to.

I happily pay for YouTube Premium, just to avoid ads. I wish I could do the same with Facebook

Do you still get tracked and your data collected if you pay?

Re: Facebook Is Giving Advertisers Access To Your Shadow Contact Information

#210
post #183

Earlier quoted context omitted.

What are some crazy things you've seen?

Not related to private data but I've seen a bank shadow fund a project to get the mortgage review packages of a competitor to run through their models and test them out, also giving this one bank all the data on the mortgage packages and the scores. A really big bank did this to two others BIG lenders (one lender directly related to the federal government). We were instructed to turn a blind eye and the business mode…

> My personal opinion is ALL your data is being sold. Every single bit that can be collected will be sold with no protections, regulations.

I don't understand -- especially in this crowd -- how this is even a question, at this point, nor why anything related to this fact even warrants discussion any more, given the knowable ubiquity of the practice. I guess the only thing left is figuring out a novel way to capitalize on it, like the Gold Rush.

Post reply on HN