Live data from Hacker News

The Facebook phone numbers are now searchable in Have I Been Pwned

troyhunt.com

141–150 of 248 posts

Re: The Facebook phone numbers are now searchable in Have I Been Pwned

#141
post #132

I'm supposed to go to a random website and enter my phone number?

It's not at all a random website. haveibeenpwned is renowned. Your phone number is not uploaded to the server, instead your browser asks for a whole range of (hashed) phone numbers and checks locally if yours was one of them. The process is spelled out here: https://haveibeenpwned.com/Privacy

HIBP is indeed probably just fine, but I'm not sure how the phone number searching works. "There's no k-anonymity implementation for phone numbers at this point in time."

https://www.troyhunt.com/the-facebook-phone-numbers-are-now-...

Re: The Facebook phone numbers are now searchable in Have I Been Pwned

#142
post #54

Getting to the point where we’re going to need phone, email, and SMS to be deny all by default. Can’t reach me unless you’re information is already in my contacts.

It's a hard problem to crack. Some legitimate places need to be able to call you without you knowing them ahead of time. Say your sibling was mugged in Mexico and the local little police station let them borrow the landline to call the only number they still remember without having to check their contacts in their phone. Are you not going to pick up?

There are a lot of these little edge-cases. Journalists, lawyers representing class action suits, government id expiring, and so on.

Re: The Facebook phone numbers are now searchable in Have I Been Pwned

#144
post #46

A note for people with US numbers who aren't finding their info: > And finally, one last note on the data load process: At the time of publishing this blog post, all phone numbers beginning with international codes 4, 6, 8 and 8 have completed loading. The other codes are in progress and may take several hours more before they're searchable. US numbers begin with international code 1, and it seems that they aren't ye…

According to the edit at the bottom of the post, "1" is now complete.

Re: The Facebook phone numbers are now searchable in Have I Been Pwned

#145
post #31

Is it just me or... why do people even share their phone number with Facebook? What did you use it for? It wasn't mandatory or anything. Why the Pikachu faces?

Many companies present you with the opportunity to "Protect Your Account" with SMS, and for that protection they 'just' need your phone number.

Turns out the phone number is the best unique identifier and is the perfect key for joining up lots of disparate sources of data. It's the kind of thing that you could either sell directly or use as an index to determine things like your estimated income.

It wouldn't surprise me if Facebook has had multiple technical methods for devising/stealing and disingenuous "protect your account" campaigns for willingly turning over users phone numbers.

Re: The Facebook phone numbers are now searchable in Have I Been Pwned

#146
post #129

Earlier quoted context omitted.

What damages have you incurred?

Identity theft most likely, and the consequences arising from that.

What is the monetary amount, and do you have evidence of the theft?

Re: The Facebook phone numbers are now searchable in Have I Been Pwned

#147
post #97
post #45

Earlier quoted context omitted.

I do something similar when a site asks for my birthday, i used to pick a random date, but sonce its sometimes used to reset password or asks u to confirm i just use the first of january of the year i was born so i can make sure i remember what i put.

When birthdate is tied to an account, I pick a random one and store it alongside the username and password in KeePass. Same as the "security questions"; I make up and store nonsensical answers. E.g. "Q: What was your mother's maiden name?" "A: Blueberry pie."

I do the same thing but use KeePass’ password generator to create the answers. My mother’s maiden name will be something like “diejdJyt7ejHsud”

Re: The Facebook phone numbers are now searchable in Have I Been Pwned

#148
my Facebook account got hacked/stolen a few months ago (didn't notice since I hardly ever use it), and Facebook won't give me back access to it even after providing photo ID etc., citing coronavirus-related labor shortages or some such bullshit. but hey, at least now HIBP has the hacker's phone number instead of any of mine!

Re: The Facebook phone numbers are now searchable in Have I Been Pwned

#149
post #54

Getting to the point where we’re going to need phone, email, and SMS to be deny all by default. Can’t reach me unless you’re information is already in my contacts.

It's a hard problem to crack. Some legitimate places need to be able to call you without you knowing them ahead of time. Say your sibling was mugged in Mexico and the local little police station let them borrow the landline to call the only number they still remember without having to check their contacts in their phone. Are you not going to pick up? There are a lot of these little edge-cases. Journalists, lawyers re…

My iPhone is set to "Silence Unknown Callers." It's the perfect compromise. If a call is legitimate they'll leave a voicemail and I just call them back.

Re: The Facebook phone numbers are now searchable in Have I Been Pwned

#150

Found my number on there too even though I've deleted Facebook for at least 5 or 6 years now -_- Not sure when I gave them my number either, I hope it wasn't scraped from someone else's contact list... At least it makes sense why I received a bunch of spam calls over the weekend. Anyway it's probably good practice to recycle your number every few years, and not use it for 2FA to make switching numbers a lot easier. W…

"Anyway it's probably good practice to recycle your number every few years, and not use it for 2FA to make switching numbers a lot easier."

Ironically Twilio of all places forced SMS 2FA on all accounts earlier this year.

As in, one day you could no longer log into your twilio account without giving them a phone number. You are locked out until you do.

Ironic in a few ways ...

First, twilio numbers are not mobile numbers - they are voip numbers - and cannot be used for most 2FA authentication services because they cannot receive messages from short codes. So it's ironic that twilio forces you to use a non-twilio number for their 2FA.

Second, many twilio use-cases (like mine) involve building a twilio infrastructure to replace my existing phones/numbers ... and now that is broken from the bottom up because I have to use a mobile phone with a fixed provider just to use twilio.

The bottom line is: none of this is for me or my safety and security. Twilio has a spam problem and that spam problem is very hard to solve. Forced pairings of physical phones and SIM cards is just a desperate way to throw sand in those gears to slow it down a little bit.

Post reply on HN