Live data from Hacker News

533M Facebook users' phone numbers and personal data have been leaked online

businessinsider.com

221–230 of 524 posts

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#221

Earlier quoted context omitted.

> I don’t have FB or or WhatsApp but my Insta account (using a separate email address and no personal details) keeps recommending my therapist to me. So what? What's the harm? People sure like to write emotionally charged posts arguing for privacy, but they're always suspiciously low on details on what bad things (actually) happened. Even in this case with phone numbers and other data leaked, so what? What harm do da…

Post your personal phone number right here and I will show you what harm it can cause.

Also @badjeans should give you all passwords for all email accounts, and all encryption keys.

Because you know, what does it matter, right?

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#222

Earlier quoted context omitted.

I have WhatsApp and you can deny access to your phonebook. Everything works just fine

Others can still allow access to their phone book and the information stored in them about you will be transmitted and saved at Facebook, won't it? Is there a way to disable that?

Exactly this. I recently started a twitter for my academic career. Didn't share my contacts or anything (I only follow academic twitter too). I get tons of suggestions of people I know and several have followed me. The information is from their contact list because twitter knows my number and connected us. There's a clear benefit to this, but there's also privacy concerns too. The lack of control over this is what is concerning.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#223
post #211

Earlier quoted context omitted.

haha, that's a good point, but in this case I think it's more trivial than that: she probably shared her contact book with FB or Insta (still, not her fault imho). But, at the same time I've worked with FB SDK which was just one big shit show. It's hard even to describe it without turning a comment into an essay, so I'll pick the two I found somewhat amusing: sending data to FB before the developer could pass user co…

It’s almost certainly just the phone number. Recently Instagram told me that a former business partner of mine had joined and I was surprised to learn that his account was an hair braiding service in Atlanta for women with African lineage (we’re both Canadian men with European ancestors). We figured out that years ago we had taken a business trip there and picked up temporary SIM cards back when Canadian cell phone p…

Yeah, my first thought reading the parent comment was two words: "Occam's razor". But, I still find it amusing that companies like FB want to project the image of "informed consent" whereas we have a bunch of developers here trying to figure out what the hell happened and coming up with plausible solutions.

What's interesting thought (and I know that from my professional experience in ad tech) is that the "cookiegeddon" did push companies towards non-deterministic, more fuzzy ways of cross-device targeting (and we're talking about people who already think that fingerprinting is ethical).

The upside is that metrics are mostly bullshit anyway.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#224
post #2

This does not look like scraping. A prima fascie database leak, and an invalidation of Facebook's claims of them not using your phone number past the validation, as well as them claiming using encryption at rest.

I've had a play with the data for a few people whose phone numbers I actually know, and they all seem old enough users that they just have the number on the account anyway. I could be wrong but I haven't found anyone my age who's number I can confirm.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#225
Last night I was browsing Facebook, and all of a sudden, it said there's been suspicious activity and I've been locked out of my account. To unlock it, I had to review the email address and phone number I associated with my account (in case the hijacker added their own contact info), but all it had were my info that I added in 2011 (before I knew what a piece of shit Zuck was). Then it asked me to change my super-complicated password because it said the password is no longer secure.

So, can I assume this leak is related to this strange event?

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#226

I don’t have FB or or WhatsApp but my Insta account (using a separate email address and no personal details) keeps recommending my therapist to me. How are we still ok with this shit? The sooner we get rid of the cancer that FB is, the better. I didn’t share my contact book with FB apps either. It was probably her—a person in her 70s, not necessarily experienced with tech. The main reason this company exists, or that…

You do know how this happened right? Wifi SSIDs with similar strengths reveal if people are in the same area, then just correlate timestamps and viola! I wouldn't throw the elder person under the bus on this one, the tactics are sophisticated, and honestly, just a precursor to what will happen with AR. To give a bit more of how it's implemented (at least how I would propose it in iOS), Insta/FB/Whats queries availabl…

> You do know how this happened right? Wifi SSIDs with similar strengths reveal if people are in the same area, then just correlate timestamps and viola!

I mean yeah, they _could_ do that, but thats a pain in the arse to do. Its far easier to do it on contact lists, interests and implied location from business page follows.

I don't think iOS allows you to track SSIDs, which explains the lack of wifi scanning utilities in the app store.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#227

Earlier quoted context omitted.

You do know how this happened right? Wifi SSIDs with similar strengths reveal if people are in the same area, then just correlate timestamps and viola! I wouldn't throw the elder person under the bus on this one, the tactics are sophisticated, and honestly, just a precursor to what will happen with AR. To give a bit more of how it's implemented (at least how I would propose it in iOS), Insta/FB/Whats queries availabl…

haha, that's a good point, but in this case I think it's more trivial than that: she probably shared her contact book with FB or Insta (still, not her fault imho). But, at the same time I've worked with FB SDK which was just one big shit show. It's hard even to describe it without turning a comment into an essay, so I'll pick the two I found somewhat amusing: sending data to FB before the developer could pass user co…

is it even legal for a therapist to share their clients contact details with a third party?

certainly I would expect that a person who works as a therapist would be aware that the concept of client confidentiality exists and that they should not share their clients details

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#228

Last night I was browsing Facebook, and all of a sudden, it said there's been suspicious activity and I've been locked out of my account. To unlock it, I had to review the email address and phone number I associated with my account (in case the hijacker added their own contact info), but all it had were my info that I added in 2011 (before I knew what a piece of shit Zuck was). Then it asked me to change my super-com…

Highly unlikely to be related. It's not a password leak. It's also not really a leak, someone scraped some public profile info and then used the phone number lookup feature to match up the two.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#229

Earlier quoted context omitted.

Put a monetary cost of holding user data, and a steep monetary cost on losing user data. Ex, pay x amount per month in perpetuity for each piece of information about a user your keep. And have to pay the "net present value" of those payments if you lose the data. Having to pay for hoarding user personal data changes the incentives from gobble up as much as possible, to instead only pay for a users data that is worth…

Sounds interesting. Shall we call it "GDPR"?

Honestly the EU need to finans a organisation to deal with GDPR violation, hell it could finans it self. The GDPR is the single best piece of legislation ever written, in term of privacy, but enforcement is lacking.
Post reply on HN