Live data from Hacker News

Facebook does not plan to notify half-billion users affected by data leak

reuters.com

81–90 of 315 posts

Re: Facebook does not plan to notify half-billion users affected by data leak

#81

Earlier quoted context omitted.

> Is this worldwide or US? Worldwide. SMS is just like e-mail, you can put anything you want in the sender field. You should absolutely not trust SMS.

Are there Android apps for that?

I'm absolutely no expert on this, but I think your provider would usually filter this spoofing attempt out, just like with IP spoofing. But if you're in the right spot in the network (e.g. your provider doesn't check for spoofing or you're your own "provider") you can do whatever you want.

Another problem with Android could be that the operating system might not have enough control over the SIM-Card/Modem to spoof phone numbers.

I have heard about people using some services to send/call from spoofed numbers though

Re: Facebook does not plan to notify half-billion users affected by data leak

#82
post #39

Earlier quoted context omitted.

> Is this worldwide or US? Worldwide. SMS is just like e-mail, you can put anything you want in the sender field. You should absolutely not trust SMS.

Any idea on the extra security measures? In Turkey for example, when you change your SIM card the 2FA from the banks will stop working and you need to call your bank to re-activate it. That of course seems like a measure to prevent SIM cloning but maybe there are some security protections against spoofing. In many places SMS is a popular way to do payments and 2FA for high security applications.

Carriers can indeed expose APIs for banks and other third-parties to check if a SIM has recently been reissued, but that's a separate problem from spoofing.

Re: Facebook does not plan to notify half-billion users affected by data leak

#83
post #39

Earlier quoted context omitted.

Any idea on the extra security measures? In Turkey for example, when you change your SIM card the 2FA from the banks will stop working and you need to call your bank to re-activate it. That of course seems like a measure to prevent SIM cloning but maybe there are some security protections against spoofing. In many places SMS is a popular way to do payments and 2FA for high security applications.

Where does SMS get used to do payments? (...and how?) SMS for 2FA is known to be a very bad idea, and some security experts have been shouting about the need to stop doing that for a while. I also can't see any country managing to implement more restrictions on SMS without either breaking a lot of "legitimate" sources of SMS or being ineffective outside of a very narrow window (e.g. only blocking forged SMS for numbe…

"Where?!" Everywhere. It's being phased out in many places, but as a rule of thumb, mostly everywhere still.

"known to be very bad ... been shouting ..." Right, yeah, to put it in some perspective remember that you're talking second factor here. This is not your login, this is a secondary confirmation and you still need some serious motivation to bypass it. It's definitely doable, I work in security and I know what kind of attacks you're thinking of, but it's not the opportunistic kind of thing that a common thief will do without technical research and planning it out. If you know how to do it, you can probably find better jobs than this. It also doesn't scale well because you can only use it on people whose bank login you've already cracked in the first place.

Re: Facebook does not plan to notify half-billion users affected by data leak

#84
post #10

This huge leak has definitely killed the SMS text messaging service. Sender can be spoofed and spam/scam/phishing have reached an intolerable level. The fact that they can cross reference you and then produce a more personalized content is huge. Changing password is easy (ok less easy if you recycle it) but changing phone number is something that I am not even relaxed to do.

Could someone elaborate on what the worst-case exploit would be for those number that got leaked? How would a scenario look like? Asking for a friend whose number got exposed...

What some spammers do in my country for example, is call old people and pretend their (grand/)children were involved in an accident and ask for money for quick interventions (the hospital is out of funds, bla bla). It's sometimes hit or miss cause the person might be next to them, or they just talked, or sometimes they can't figure out if you have a daughter or a son etc.

With a correlated leak like this, it's super easy for me to find your profile, see who you are, what you look like, even from just your profile picture I could potentially see you have a daughter yourself, so I can target your mother that something happened to her granddaughter and you, which would make her pay up even faster possibly.

Re: Facebook does not plan to notify half-billion users affected by data leak

#85
post #7

Earlier quoted context omitted.

Are you seriously claiming it's too hard? They could send out emails, Facebook messages or show some banner in the profile page. This is Facebook ffs, they almost have a monopoly on communication.

> too hard to notify users Legally seen. The way privacy protection laws are, especially in Germany, is kinda stupid. On one side they often doesn't protect you in practice, on the other side they effectively hinder and sometimes prevent reasonable usage. Just a view examples: - A local government couldn't properly inform elder people that they now can get Vaccinated for free because the interplay of various privacy…

> Legally seen.

Its funny, one would expect them to include that as part of their terms of service or the list of things they officially use your private data for. But no, apparently the lawyers they hired fucked up while writing these in a way that favours Facebook. Its almost as if they weren't plain incompetent and instead paid to mess this up, just like Apples lawyers fucked up adapting the warranty terms for the EU market, etc. .

Hit them with a few billion dollars for having a brain dead moron in charge of user privacy, each day until that oversight is fixed.

Re: Facebook does not plan to notify half-billion users affected by data leak

#86
post #10

This huge leak has definitely killed the SMS text messaging service. Sender can be spoofed and spam/scam/phishing have reached an intolerable level. The fact that they can cross reference you and then produce a more personalized content is huge. Changing password is easy (ok less easy if you recycle it) but changing phone number is something that I am not even relaxed to do.

Could someone elaborate on what the worst-case exploit would be for those number that got leaked? How would a scenario look like? Asking for a friend whose number got exposed...

It's still going to be a scam message, but they can use your Facebook ID to see everything public on your profile now, as well as the other fields in the leak like full name, location, bio, birthday. So whatever the most convincing scam message somebody can come up with is combining all of that data. Off the top of my head, "happy birthday here's a gift from us" messages from companies leading to phishing pages and personalised fake register to vote pages relating to upcoming elections in your area.

It's not really new data, it's just scam SMS I've received in the past has never shown any sign of knowing anything other than my phone number. Now you can buy phone numbers and pull personalisation data unrestricted from your copy of Facebook's database for each of them. I'm sure sophisticated scammers already were, but now everyone will.

Re: Facebook does not plan to notify half-billion users affected by data leak

#87
For years companies have been steadily asking, mandating or even trickling users to give them their phone numbers under the excuse of security (while the real reasons were different), now what?

How can they be trusted anymore?

This also strikes a great point about the data sharing between Facebook and WhatsApp. Linking data between services augments the dangers and the consequences are not obvious to the end user.

I think Facebook should offer their users the option to remove their phone numbers with a real deletion.

Re: Facebook does not plan to notify half-billion users affected by data leak

#88
So if I decide to fish the world with this database, am i really doing something wrong? Cause you would think if somebody steal from you at Wallmart and the cashier sees it. They would try to notify you. If everybody think it's ok, when does it start to be:" I just found this wallet full of cash and i'm not notifying the authority?"

Re: Facebook does not plan to notify half-billion users affected by data leak

#90
post #10

This huge leak has definitely killed the SMS text messaging service. Sender can be spoofed and spam/scam/phishing have reached an intolerable level. The fact that they can cross reference you and then produce a more personalized content is huge. Changing password is easy (ok less easy if you recycle it) but changing phone number is something that I am not even relaxed to do.

Could someone elaborate on what the worst-case exploit would be for those number that got leaked? How would a scenario look like? Asking for a friend whose number got exposed...

If your phone is your 2fa, someone uses this data to target you for a sim-swap to take over your phone, and then uses it to take over high value accounts.
Post reply on HN