Live data from Hacker News

Facebook does not plan to notify half-billion users affected by data leak

reuters.com

31–40 of 315 posts

Re: Facebook does not plan to notify half-billion users affected by data leak

#32
post #10

This huge leak has definitely killed the SMS text messaging service. Sender can be spoofed and spam/scam/phishing have reached an intolerable level. The fact that they can cross reference you and then produce a more personalized content is huge. Changing password is easy (ok less easy if you recycle it) but changing phone number is something that I am not even relaxed to do.

> Sender can be spoofed Is this worldwide or US? I for now trust the senderid and assume them to be valid if they are coming from bank etc. I also haven't heard of anyone spoofing SMS. Should I be more cautious?

Absolutely do not trust the SMS sender name or message content in any country. SMS can be spoofed so easily anyone can do it.

Re: Facebook does not plan to notify half-billion users affected by data leak

#33
post #4

It's from 2019 is the stupid excuse they have. The amount of laxity they have shown in this matter is appalling!!

If you change your DoB every year like I do, you'll be fine...

Assuming not sarcasm, how does that help? Do you do this for just Facebook or for multiple websites?

Re: Facebook does not plan to notify half-billion users affected by data leak

#34

Zuckerberg is probably right in this one. Whatever fines might come out in the EU around this will be nothing compared to the cost of loosing the customers they notify and the cost of notifying them.

Then we need to reform the law to impose bigger fines or other tools that dissuade FB not notifying the users

Re: Facebook does not plan to notify half-billion users affected by data leak

#35
post #10

This huge leak has definitely killed the SMS text messaging service. Sender can be spoofed and spam/scam/phishing have reached an intolerable level. The fact that they can cross reference you and then produce a more personalized content is huge. Changing password is easy (ok less easy if you recycle it) but changing phone number is something that I am not even relaxed to do.

Facebook didn't even change user Ids. You can look up those people accounts to find even more information. It is crazy they got away with it.

Re: Facebook does not plan to notify half-billion users affected by data leak

#36
post #23

Zuckerberg is probably right in this one. Whatever fines might come out in the EU around this will be nothing compared to the cost of loosing the customers they notify and the cost of notifying them.

> Whatever fines might come out in the EU around this will be nothing compared to the cost of loosing the customers they notify and the cost of notifying them. There is no mention of GDPR in the article, but in the worst case of not notifying _at all_, the GDPR fine should be $3.5B (4% of their global revenue). Is this quantity insignificant enough for them to ignore? (not rhetorical, i have no idea how much capital…

EU legal system will not allow a company to trade infringement for a fine.

If they had to do something, they will get a fine and they will be forced to do it anyway by the court.

If they don't comply with court orders they will be fined separately with an accumulating sum until they do.

Re: Facebook does not plan to notify half-billion users affected by data leak

#37
post #32

Earlier quoted context omitted.

> Sender can be spoofed Is this worldwide or US? I for now trust the senderid and assume them to be valid if they are coming from bank etc. I also haven't heard of anyone spoofing SMS. Should I be more cautious?

Absolutely do not trust the SMS sender name or message content in any country. SMS can be spoofed so easily anyone can do it.

I can confirm this happens in the UK.

Re: Facebook does not plan to notify half-billion users affected by data leak

#39

Earlier quoted context omitted.

> Sender can be spoofed Is this worldwide or US? I for now trust the senderid and assume them to be valid if they are coming from bank etc. I also haven't heard of anyone spoofing SMS. Should I be more cautious?

> Is this worldwide or US? Worldwide. SMS is just like e-mail, you can put anything you want in the sender field. You should absolutely not trust SMS.

Any idea on the extra security measures? In Turkey for example, when you change your SIM card the 2FA from the banks will stop working and you need to call your bank to re-activate it. That of course seems like a measure to prevent SIM cloning but maybe there are some security protections against spoofing. In many places SMS is a popular way to do payments and 2FA for high security applications.
Post reply on HN