They should instead hash your number client side and test the hash.
Have I Been Facebooked?
41–50 of 230 posts
Re: Have I Been Facebooked?
#42I'm looking forward to the sequel, "Have I Been 'Have I Been Facebooked'ed" when it turns out this is just a data harvesting operation. If you don't want your phone number leaked don't hand it over to a random website that pinky swears it won't keep it. It's maybe not a scam, but still...
Re: Have I Been Facebooked?
#43So, a few things. 1) no indication that there's any rate limiting here beyond a 2 second cooldown (thanks for that, grenoire), but I only tested it using burp intruder community edition, and I only tested it on a set of numbers guaranteed to return false. If anyone wants to test a range with a known-leaked number in it, up to you. 2) it's very possible that if there is rate limiting, it acts invisibly. But if there's…
Why would anyone scrape this site when they could just download the leaked dataset?
Re: Have I Been Facebooked?
#44Earlier quoted context omitted.
Because 12-13 years ago when a lot of people signed up, it wasn't clear that they were exceptionally evil. Pre-IPO, pre-ads, back when it was just status updates and photos, it didn't strike a lot of people (myself included) as a particularly bad idea. We hadn't seen the monster social media would become when it suddenly had to improve quarterly profits.
Ads began in 2007, over 13 years ago. I purchased my first FB ad in late summer 2007. Not sure if that’s also when it opened up.
Like most things, it took a few years to really take off. They IPO'd in 2012, and then really had to prove they could turn a profit (and increase it over time). I've honestly not been a heavy enough Facebook user to be able to pin the transition to a particular point in time (and it was almost certainly a long period of time, pushing for more and more), but the transition of the "Like" widget on random pages from an image icon to a data collection tool was probably a good indication of the transition.
In any case, by... oh, 2014 or so at the latest, they'd definitely started showing their true colors. Engagement Uber Alles. Because ads.
Re: Have I Been Facebooked?
#45Earlier quoted context omitted.
A list of valid phone numbers is more valuable than a list of all possible phone numbers, for the same reason that a list of valid passwords is much more valuable than a list of all possible passwords. It saves miscreants a lot of time and effort.
I'm not sure how it works in other countries, but for the US the numbers are generated by area code, and they're constantly allocating new ones because the old ones have been used up[1]. This is with number recycling. Therefore if you randomly generate a phone number for an "old" area code you probably are going to get a valid number. [1] https://en.wikipedia.org/wiki/List_of_North_American_Numberi...
Re: Have I Been Facebooked?
#46Re: Have I Been Facebooked?
#47Facebook should email those affected... surely they know who was compromised or not. Shouldn't have to use random sites for this. Why has there been no communication from them?
The leak doesn’t provide much. The backlash of sending an email will instantly be way worse than what was actually leaked. Far worse leaks happen routinely from big names. However Facebook’s negative reputation would sway so far against it, you’d think Facebook had doxxed every one. I don’t particularly like Facebook or any big corporation FYI.
Re: Have I Been Facebooked?
#48I'm looking forward to the sequel, "Have I Been 'Have I Been Facebooked'ed" when it turns out this is just a data harvesting operation. If you don't want your phone number leaked don't hand it over to a random website that pinky swears it won't keep it. It's maybe not a scam, but still...
> If you don't want your phone number leaked don't hand it over to a random website that pinky swears it won't keep it. What's the worst they can do with it? Call me all hours of the day trying to sell me an extended factory warranty for my free Medicare brace that, by the way, has a Security Number that is under arrest by the Security Administration because it made fraudulent IRS payments with iTunes gift cards to l…
In a world where
your bank thinks that SMS is good enough for 2FA...
phone number plus other info is good enough for credit reporting agencies to send out your complete file...
Variations of this theme.
Also, this dump is once more confirmation that Facebook owns lots of data about its users, and doesn't care to protect that data, or to give its users the ability to control personal information. Why should they care? They suffer no consequences for this lack.
Re: Have I Been Facebooked?
#49Earlier quoted context omitted.
Because 12-13 years ago when a lot of people signed up, it wasn't clear that they were exceptionally evil. Pre-IPO, pre-ads, back when it was just status updates and photos, it didn't strike a lot of people (myself included) as a particularly bad idea. We hadn't seen the monster social media would become when it suddenly had to improve quarterly profits.
ELI5 why facebook is exceptionally evil. (Of course I'm inviting downvotes, but please give me a comment too; ideally a reason that isn't also applicable to 'internet as a whole').
Facebook, long ago, stopped being about connecting people (except that claiming this gets more people to join), and more about "keeping people on Facebook as long as they possibly could" - because that means more ad impressions, which means more money for Facebook.
They rely on every quirk in human psychology to keep people addicted ("engaged") and scrolling as long as possible. Intermittent reward, randomized ordering (the refresh throbber followed by "new" content), and driving people into toxic emotions and rabbit holes. Anger, outrage, and conspiracy rabbitholes are /great/ for keeping people on the site. They're terrible for the people involved (one could offer the handwaving parallel of a grocery store offering free heroin if you buy stuff there to keep people shopping), but profitable for Facebook.
They believe the entire internet is theirs to scrape user activity from (the "like" buttons were turned into data collection elements long ago, against the original promises made about them), so they can offer better-targeted advertisements to anyone who has a valid credit card. Foreign actor, scammer, seller-of-medical-nonsense, it's all fine - as long as they pay up properly.
And in a wide variety of cases of Facebook being fingered as directly responsible for enabling reprehensible behavior like genocides, their responses are consistently, "We are so, so sorry that you caught us doing that, and we promise to try harder not to get caught in the future." Genocide is extremely engaging, and as long as they can sell ads to people othering their neighbors and calling for violence against them, well, what's wrong?
The guiding principle of Facebook has been clearly demonstrated to be, "What's Good for Zuck is Good for Zuck!" Anything else is secondary (and mostly a concern in that if you don't do anything, people might get around to cancelling their accounts or no longer using Facebook).
I can, and do, apply these criticisms to a number of other properties on the internet, but the social media companies (companies who take user-generated content, repackage it, and algorithmically deliver it in optimally engaging order to other people, interleaved with ads) are the parts of the internet that are demonstrably ruining just about everything that people care about.
Re: Have I Been Facebooked?
#50Earlier quoted context omitted.
> If you don't want your phone number leaked don't hand it over to a random website that pinky swears it won't keep it. What's the worst they can do with it? Call me all hours of the day trying to sell me an extended factory warranty for my free Medicare brace that, by the way, has a Security Number that is under arrest by the Security Administration because it made fraudulent IRS payments with iTunes gift cards to l…
"The worst that can happen"... In a world where your bank thinks that SMS is good enough for 2FA... phone number plus other info is good enough for credit reporting agencies to send out your complete file... Variations of this theme. Also, this dump is once more confirmation that Facebook owns lots of data about its users, and doesn't care to protect that data, or to give its users the ability to control personal inf…
And, certainly, Facebook suffers no consequences. A while back, some people noticed that if a company was in the news for a catastrophic data breech, their stock tended to climb immediately afterwards. No such thing as bad press coverage, at least in the age of the trading algorithms!