Live data from Hacker News

The Facebook phone numbers are now searchable in Have I Been Pwned

troyhunt.com

91–100 of 248 posts

Re: The Facebook phone numbers are now searchable in Have I Been Pwned

#92
post #54

Getting to the point where we’re going to need phone, email, and SMS to be deny all by default. Can’t reach me unless you’re information is already in my contacts.

My phone number (and some other details) were part of Nano Ledger's database that got stolen last year. So, some entrepreneurial scammer started calling me on a daily basis a few months ago. Really annoying. I'm well aware my phone number and email addresses are pretty much public information at this point. I actually put that on my web site even. But stuff like this makes me even less likely to answer unknown numbers. Hilariously, the scammer actually called me while I was giving a security briefing to our company about enabling 2FA. I put him on speaker and we had a good laugh while the guy insisted in broken English laced with expletives that he "had my money".

A few months ago some criminals social engineered themselves past my bank's security as well. The first I learned about this was a funny conversation (by phone!) from an actual Deutsche Bank employee asking me if I recently changed my address and phone number and whether I opened ten new accounts. "eh no?!..." Basically their fraud detection system kicked in before these people did any damage. I made a point of not doing anything else than confirming information they already knew (like my old address, email address) and asked for an on site meeting to discuss things in more detail. I realized instantly I had no way of verifying anything I was being told on the phone and might very well be talking to a scammer. As it turns out this was for real and the person actually managed to find my "old phone number" in some archive. Otherwise all my contact information had already been changed by the scammers. Thankfully I answered that call. Apparently, this happened to several people.

Basically, what happened was some persons just called the bank's help desk, asked them to reset my online banking access codes, and then somehow intercepted the pin codes (thanks Deutsche Post) before they reached me. The theory is that somehow the security of the distribution system was compromised. As far as I an tell, nobody broke into my building or mailbox. Then started they using them to change my address, etc. They got caught only when they created sub accounts and started transferring money.

Re: The Facebook phone numbers are now searchable in Have I Been Pwned

#93
post #54

Getting to the point where we’re going to need phone, email, and SMS to be deny all by default. Can’t reach me unless you’re information is already in my contacts.

Possibly, but we can't do that either. What we need is some balance of both worlds. OOH, we do actually need to be contactable. OTOH, being too contactable means spam. I doubt there's a perfect balance, but either extreme come with too many problems. Email has decent spam filtering, and I think that kind of cat-mouse system will persist. That said, there's "room" for more whitelisting.

The “Hey” email service toes the line well for me. I’d prefer all of my communications were based on a similar idea.

Re: The Facebook phone numbers are now searchable in Have I Been Pwned

#94
post #72

Found my number on there too even though I've deleted Facebook for at least 5 or 6 years now -_- Not sure when I gave them my number either, I hope it wasn't scraped from someone else's contact list... At least it makes sense why I received a bunch of spam calls over the weekend. Anyway it's probably good practice to recycle your number every few years, and not use it for 2FA to make switching numbers a lot easier. W…

I can’t imagine telling everyone I know that I’m changing my number every couple years, and I’m not even calling/messaging a lot of people nowadays. I have a family member who did something similar(not on purpose) and I still have 3 of her numbers and still get confused which is the working one.

I know exactly what you mean, there's only so many times you can append "New" on the end of a contact name!

A good chunk of people will probably communicate mostly on platforms like WhatsApp/Telegram/Discord/whatever that don't need numbers at all or facilitate switching of numbers without your contacts having to do anything. I don't think that will constitute anywhere near the majority of people across the world though, switching numbers will definitely be a pain for most.

Re: The Facebook phone numbers are now searchable in Have I Been Pwned

#96
post #45

Earlier quoted context omitted.

I do something similar when a site asks for my birthday, i used to pick a random date, but sonce its sometimes used to reset password or asks u to confirm i just use the first of january of the year i was born so i can make sure i remember what i put.

Doesn't that kinda negate the goal of using a fake birth date? After all, they don't really care whether you give your real birth date, it's enough that it is the same on that other website they get your personal information from to correlate.

I don’t care if someone leaks my fake DOB in a Dropbox hack and then tries to reset my Netflix password.

Websites that use my real DOB are usually linked to my identity, so I’m much more concerned with protecting them from, eg social engineering attacks [0].

[0]: https://gizmodo.com/how-i-lost-my-50-000-twitter-username-15...

Re: The Facebook phone numbers are now searchable in Have I Been Pwned

#97
post #45

Note to anyone that cares: Make your data as stale as possible: you can't change your address easily, sure. But you can recycle phone numbers (once a year, minimum). Change your credit/debit cards yearly (say to your bank you 'lost' it). When ordering online, always, always, always use a fake number, it's not required. Always use a fake name where possible. Sure, you need to provide that as a 'billing' address, but i…

I do something similar when a site asks for my birthday, i used to pick a random date, but sonce its sometimes used to reset password or asks u to confirm i just use the first of january of the year i was born so i can make sure i remember what i put.

When birthdate is tied to an account, I pick a random one and store it alongside the username and password in KeePass. Same as the "security questions"; I make up and store nonsensical answers. E.g. "Q: What was your mother's maiden name?" "A: Blueberry pie."

Re: The Facebook phone numbers are now searchable in Have I Been Pwned

#98
Hm, I already know phone number is leaked, but searching for it (XXXxxxXXXX) doesn’t work.

Once I prepended Canada’s country code: (1XXXxxxXXXX) it worked.

Maybe this can be fixed with some simple communication? Ie “No result —- ensure you enter your full phone number including country code”

Re: The Facebook phone numbers are now searchable in Have I Been Pwned

#99

After my wife's suicide (See the documentary Pain Warriors) I took over Karen's FB account as my own, and I changed the name on the account. Long before this breach I have been getting SMS Spam addressing me as Karen, on a number that did not exist when she was alive. FB data can be the only possible source of that spam. The spam is always trying to sell male enhancement products to 'Karen'. Anyone know how to stop t…

Very sorry for your loss and thank you for sharing.

Re: The Facebook phone numbers are now searchable in Have I Been Pwned

#100
post #96

Earlier quoted context omitted.

Doesn't that kinda negate the goal of using a fake birth date? After all, they don't really care whether you give your real birth date, it's enough that it is the same on that other website they get your personal information from to correlate.

I don’t care if someone leaks my fake DOB in a Dropbox hack and then tries to reset my Netflix password. Websites that use my real DOB are usually linked to my identity, so I’m much more concerned with protecting them from, eg social engineering attacks [0]. [0]: https://gizmodo.com/how-i-lost-my-50-000-twitter-username-15...

Yes this is my thought as well.
Post reply on HN