Live data from Hacker News

533M Facebook users' phone numbers and personal data have been leaked online

businessinsider.com

471–480 of 524 posts

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#471
post #331

Earlier quoted context omitted.

As a counterpoint I can think of dozens of personal acquaintances who are happily non-users and never interact with Facebook properties (retirees not into tech, busy executives, to cool for Facebook hipsters). If your country or social circle doesn't use WhatsApp, Facebook itself is already dying and Instagram is getting their lunch eaten by Tiktok.

FBs revenue growth doesn't agree with this perspective: https://twitter.com/JonErlichman/status/1354536238104064005

That is a very good point. But usually changes in revenue trail changes in adoption and/or engagement. Both when growing, and when slowing down.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#472
post #353
post #326

Earlier quoted context omitted.

I've always thought the most scary thing about this practice is that your (unique) phone number is a powerful "foreign key" which could potentially join data from many other leaked databases, forming an even larger dataset on you. There are plently of other places we give our phone numbers to, which might not have anywhere near the protections that Facebook say they provide.

Absolutely, and e-mail or Paypal account name too. Neither of them are trivial to change. If you try to create a new account for each thing at a generic mail provider such as Gmail, your accounts will be shut down by automatic abuse filters. If you roll your own domain, then, well... the domain becomes the foreign key.

The solution to this is unlimited true email aliases as e.g. StartMail [1] and Fastmail [2] provide. I wish this was more common place for email provider. Besides the front up cost of developing / setting up the solution, email aliases have the marginal cost of one small database row per alias. And it would be such a boon for privacy.

[1] https://support.startmail.com/hc/en-us/articles/360007297457...

[2] https://www.fastmail.help/hc/en-us/articles/360060591073

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#473
post #459

Earlier quoted context omitted.

I stand by your SSN only for social security point. But the rest sounds plain wrong to me. Your phone might get stolen, your name might change due to marriage, your address might change because you moved/got evicted. What now?

Your phone gets stolen so you use your bank card and password to set a new phone number on your account. Your bank card gets stolen so you use your phone and password to get a new bank card. If someone steals your phone and password and bank card and ability to receive mail at your home address all at once then you're pretty screwed, but you're pretty screwed then regardless, right? That's the level of screwed where…

For sufficient amounts or suspicious operations, banks should be in charge of authentification, ie showing up in-person for bank transfers such as a car, showing up and supplying fingerprints if the bank transfer buys a house...

And in fact, for poor people, anything that might engage their entire savings might also benefit from a more advanced identity verification.

For example my stock exchange account just takes a password. It’s a scandal.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#474

Earlier quoted context omitted.

What a pathetic response. Does it mean users changed where they live? Change their names? Deleted and started a new account so the ID is different?

> Deleted. "You keep using that word. I do not think it means what you think it means." I "deleted my account" in the run-up to the 2016 election, because I could see how social media was being manipulated, and what it is doing to society. And I mean I _deleted_ it. I took the extra steps of researching how to REALLY delete it; not just suspend it. A couple years later, I needed to get a new account to help admin a p…

I think this is because is very expensive to delete and also to develop true delete process. I think that is not acceptable and cost shouldn't be an excuse for keeping content forever. Even if you manage to get deleted from the live servers, chances are your content is still going to live in backups and will never be deleted. Some backup systems are write-once and could only be deleted by physically destroying the medium. I wish this was properly addressed in legislation.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#475

Earlier quoted context omitted.

You don't know that. While the publicly available data leaks are indeed rare, you cannot know if they don't use the data for trading or other purposes for their personal gain without disclosing it to the public.

Sure, but if you have no evidence of it happening you have a fairly weak argument.

People do have access to privileged information and that will influence their decisions on both conscious and unconscious levels. It's not possible to detach yourself from work completely and asses your thinking whether it is influenced by something you saw or not on an objective level. It will also be difficult to prove. For example if an employee hobby is trading, how do you prove that the trades they made are based on their own independent research or based on what they saw? If they saw something that could make them money, they could easily create a trail of evidence that they researched the matter on their own - it will be difficult to prove that it originated from looking up the privileged information and unless someone is going to be making millions, it's frankly not economical to commit resources to. It is also in the interest of the company that such incidents don't see the light of day.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#476

The root of the problem is not the privacy policy or the system security. The root of the problem is the collection itself. All large businesses, health care providers, and governments maintain databases. Every one of them will eventually be leaked. All it takes is a corruptible trusted insider.

I mean, yes, but.. what's the solution? Never collect data? In at least some of those cases (and arguably all), that data does need to be collected and stored. What is the government going to do, not maintain birth registries, tax registries, land owner registries etc? What is a big business like a bank going to do, not collect customer data like your name and address?

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#477

I mean, at this point I think everyone should just accept that at the very least their name, age, address(es), email(s), phone number(s) and screen name(s) have been fully leaked if you have ever had any kind of online presence. Not saying that's right or good, but at this point it's just a fact. So if that's the case, I think we should move beyond really even trying to think of this info as private or a marker of id…

Like really? Don't you have to walk to a bank or show some ID? I live in the EU and I do operate under the assumption that banks take reasonable measures to ensure an account is linked to a legal identity.

[deleted]

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#478

Earlier quoted context omitted.

In which case it surely wouldn't match with credit report databases?

It turns out that signing up for a new bank account is something that people commonly do at the same time as they're moving to a new place and change their address and phone number.

So you're saying there's effectively no checks for ID for opening a bank account in the US?
Post reply on HN