Live data from Hacker News

Have I Been Facebooked?

haveibeenfacebooked.com

41–50 of 230 posts

Re: Have I Been Facebooked?

#41
anyone know of one of these sites where they don't send your phone number / email to the server? The /search endpoint phone_number param has your number.

They should instead hash your number client side and test the hash.

Re: Have I Been Facebooked?

#42
post #8

I'm looking forward to the sequel, "Have I Been 'Have I Been Facebooked'ed" when it turns out this is just a data harvesting operation. If you don't want your phone number leaked don't hand it over to a random website that pinky swears it won't keep it. It's maybe not a scam, but still...

exactly! They should be testing a hash of your phone number, not the number itself. Amateur hour here.

Re: Have I Been Facebooked?

#43
post #37

So, a few things. 1) no indication that there's any rate limiting here beyond a 2 second cooldown (thanks for that, grenoire), but I only tested it using burp intruder community edition, and I only tested it on a set of numbers guaranteed to return false. If anyone wants to test a range with a known-leaked number in it, up to you. 2) it's very possible that if there is rate limiting, it acts invisibly. But if there's…

Why would anyone scrape this site when they could just download the leaked dataset?

where?

Re: Have I Been Facebooked?

#44
post #19

Earlier quoted context omitted.

Because 12-13 years ago when a lot of people signed up, it wasn't clear that they were exceptionally evil. Pre-IPO, pre-ads, back when it was just status updates and photos, it didn't strike a lot of people (myself included) as a particularly bad idea. We hadn't seen the monster social media would become when it suddenly had to improve quarterly profits.

Ads began in 2007, over 13 years ago. I purchased my first FB ad in late summer 2007. Not sure if that’s also when it opened up.

I don't think the first few years of ads really made a big difference - Facebook couldn't really figure out how to make advertising terribly profitable while not driving people off.

Like most things, it took a few years to really take off. They IPO'd in 2012, and then really had to prove they could turn a profit (and increase it over time). I've honestly not been a heavy enough Facebook user to be able to pin the transition to a particular point in time (and it was almost certainly a long period of time, pushing for more and more), but the transition of the "Like" widget on random pages from an image icon to a data collection tool was probably a good indication of the transition.

In any case, by... oh, 2014 or so at the latest, they'd definitely started showing their true colors. Engagement Uber Alles. Because ads.

Re: Have I Been Facebooked?

#45
post #36

Earlier quoted context omitted.

A list of valid phone numbers is more valuable than a list of all possible phone numbers, for the same reason that a list of valid passwords is much more valuable than a list of all possible passwords. It saves miscreants a lot of time and effort.

I'm not sure how it works in other countries, but for the US the numbers are generated by area code, and they're constantly allocating new ones because the old ones have been used up[1]. This is with number recycling. Therefore if you randomly generate a phone number for an "old" area code you probably are going to get a valid number. [1] https://en.wikipedia.org/wiki/List_of_North_American_Numberi...

Hmm, so that suggests that getting a phone number with a "new" area code could be a way of reducing junk phone calls.

Re: Have I Been Facebooked?

#46
Can someone bcrypt all these phone numbers & emails and make that public? Share the salt and then everyone can just test their own phone number without sending it to some rando

Re: Have I Been Facebooked?

#47
post #5

Facebook should email those affected... surely they know who was compromised or not. Shouldn't have to use random sites for this. Why has there been no communication from them?

The leak doesn’t provide much. The backlash of sending an email will instantly be way worse than what was actually leaked. Far worse leaks happen routinely from big names. However Facebook’s negative reputation would sway so far against it, you’d think Facebook had doxxed every one. I don’t particularly like Facebook or any big corporation FYI.

The backlash of GDPR for not informing users may be far more severe.

Re: Have I Been Facebooked?

#48
post #18
post #8

I'm looking forward to the sequel, "Have I Been 'Have I Been Facebooked'ed" when it turns out this is just a data harvesting operation. If you don't want your phone number leaked don't hand it over to a random website that pinky swears it won't keep it. It's maybe not a scam, but still...

> If you don't want your phone number leaked don't hand it over to a random website that pinky swears it won't keep it. What's the worst they can do with it? Call me all hours of the day trying to sell me an extended factory warranty for my free Medicare brace that, by the way, has a Security Number that is under arrest by the Security Administration because it made fraudulent IRS payments with iTunes gift cards to l…

"The worst that can happen"...

In a world where

your bank thinks that SMS is good enough for 2FA...

phone number plus other info is good enough for credit reporting agencies to send out your complete file...

Variations of this theme.

Also, this dump is once more confirmation that Facebook owns lots of data about its users, and doesn't care to protect that data, or to give its users the ability to control personal information. Why should they care? They suffer no consequences for this lack.

Re: Have I Been Facebooked?

#49
post #34
post #19

Earlier quoted context omitted.

Because 12-13 years ago when a lot of people signed up, it wasn't clear that they were exceptionally evil. Pre-IPO, pre-ads, back when it was just status updates and photos, it didn't strike a lot of people (myself included) as a particularly bad idea. We hadn't seen the monster social media would become when it suddenly had to improve quarterly profits.

ELI5 why facebook is exceptionally evil. (Of course I'm inviting downvotes, but please give me a comment too; ideally a reason that isn't also applicable to 'internet as a whole').

They're not much more evil than any other publicly traded, advertising supported content repackager (so the bulk of "social" media these days), but they're far worse than a lot of other places on the internet because of their power as the "default location" for a lot of people to go when bored.

Facebook, long ago, stopped being about connecting people (except that claiming this gets more people to join), and more about "keeping people on Facebook as long as they possibly could" - because that means more ad impressions, which means more money for Facebook.

They rely on every quirk in human psychology to keep people addicted ("engaged") and scrolling as long as possible. Intermittent reward, randomized ordering (the refresh throbber followed by "new" content), and driving people into toxic emotions and rabbit holes. Anger, outrage, and conspiracy rabbitholes are /great/ for keeping people on the site. They're terrible for the people involved (one could offer the handwaving parallel of a grocery store offering free heroin if you buy stuff there to keep people shopping), but profitable for Facebook.

They believe the entire internet is theirs to scrape user activity from (the "like" buttons were turned into data collection elements long ago, against the original promises made about them), so they can offer better-targeted advertisements to anyone who has a valid credit card. Foreign actor, scammer, seller-of-medical-nonsense, it's all fine - as long as they pay up properly.

And in a wide variety of cases of Facebook being fingered as directly responsible for enabling reprehensible behavior like genocides, their responses are consistently, "We are so, so sorry that you caught us doing that, and we promise to try harder not to get caught in the future." Genocide is extremely engaging, and as long as they can sell ads to people othering their neighbors and calling for violence against them, well, what's wrong?

The guiding principle of Facebook has been clearly demonstrated to be, "What's Good for Zuck is Good for Zuck!" Anything else is secondary (and mostly a concern in that if you don't do anything, people might get around to cancelling their accounts or no longer using Facebook).

I can, and do, apply these criticisms to a number of other properties on the internet, but the social media companies (companies who take user-generated content, repackage it, and algorithmically deliver it in optimally engaging order to other people, interleaved with ads) are the parts of the internet that are demonstrably ruining just about everything that people care about.

Re: Have I Been Facebooked?

#50
post #48
post #18

Earlier quoted context omitted.

> If you don't want your phone number leaked don't hand it over to a random website that pinky swears it won't keep it. What's the worst they can do with it? Call me all hours of the day trying to sell me an extended factory warranty for my free Medicare brace that, by the way, has a Security Number that is under arrest by the Security Administration because it made fraudulent IRS payments with iTunes gift cards to l…

"The worst that can happen"... In a world where your bank thinks that SMS is good enough for 2FA... phone number plus other info is good enough for credit reporting agencies to send out your complete file... Variations of this theme. Also, this dump is once more confirmation that Facebook owns lots of data about its users, and doesn't care to protect that data, or to give its users the ability to control personal inf…

I've had my phone number for... oh, 18-19 years. I assume it's utterly trivial for anyone who cares to find it, if they care to. I know it is, because I've had the occasional random call from people who wanted to give me a call for one reason or another.

And, certainly, Facebook suffers no consequences. A while back, some people noticed that if a company was in the news for a catastrophic data breech, their stock tended to climb immediately afterwards. No such thing as bad press coverage, at least in the age of the trading algorithms!

Post reply on HN