Live data from Hacker News

Facebook does not plan to notify half-billion users affected by data leak

reuters.com

131–140 of 315 posts

Re: Facebook does not plan to notify half-billion users affected by data leak

#131
post #66

Earlier quoted context omitted.

Because I would really like to know if I'm affected. According to "Have I Been Pwned" my phone number is not in the list, but about one or two weeks ago I noticed that my spam folder was unusually full, which led me to believe that something new must have happened. Shortly thereafter Facebook's leak hit the news. From my point of view it is their obligation to notify all the affected users. It's morally the right thi…

The leak did not include email addresses, so your email spam issue is unrelated.

According to haveibeenpwned.com

> whilst each record included phone, only 2.5 million contained an email address

Re: Facebook does not plan to notify half-billion users affected by data leak

#132
post #10

This huge leak has definitely killed the SMS text messaging service. Sender can be spoofed and spam/scam/phishing have reached an intolerable level. The fact that they can cross reference you and then produce a more personalized content is huge. Changing password is easy (ok less easy if you recycle it) but changing phone number is something that I am not even relaxed to do.

Can anyone on HN please explain why, why, WHY are we still using SMS/telephony which has exactly 0 encryption wh---I guess that's the reason?

It's insane. I've heard banks using SMS!!!! To send a code. We have TOTP for that! Or even perhaps a push notification or something better than bloody SMS.

I refuse to use the networking system altogether. No phones, no calls. Of course you do 'need' a number so I keep one handy, but I haven't read a text or made a phone call in a long while.

It needs to die. NOW. Outlaw SMS!

Re: Facebook does not plan to notify half-billion users affected by data leak

#133
Maybe its already been answered in the comments, but I cant seem to find it but isnt it required by law to notify the users ?

At least for GDPR there is a requirement :

> A controller is obliged to notify the DPC of any personal data breach that has occurred, unless they are able to demonstrate that the personal data breach is 'unlikely to result in a risk to the rights and freedoms of natural persons'.

Re: Facebook does not plan to notify half-billion users affected by data leak

#134

Earlier quoted context omitted.

The beach has phone numbers and emails- why wouldn't they be able to contact those users with that information?

Facebook can't use the breach itself to contact users, no. The data could have been tampered with, and besides, Facebook doesn't have permission to process the leaked data in that way.

A company that employs dozes of data scientists and has petabytes of data is now supposedly unable to compare and match two datasets? Come on, this is beyond ridiculous.

Re: Facebook does not plan to notify half-billion users affected by data leak

#135

Earlier quoted context omitted.

> Sender can be spoofed Is this worldwide or US? I for now trust the senderid and assume them to be valid if they are coming from bank etc. I also haven't heard of anyone spoofing SMS. Should I be more cautious?

> Is this worldwide or US? Worldwide. SMS is just like e-mail, you can put anything you want in the sender field. You should absolutely not trust SMS.

I'm pretty sure Italy requires a company to register to an official list before being able to put a personalized sender ID in your SMS communications. I'm not sure about the inner workings but seems far from "whatever you want".

I kinda assumed this was a widespread modus operandi, apparently it's not?

Re: Facebook does not plan to notify half-billion users affected by data leak

#136
post #87

For years companies have been steadily asking, mandating or even trickling users to give them their phone numbers under the excuse of security (while the real reasons were different), now what? How can they be trusted anymore? This also strikes a great point about the data sharing between Facebook and WhatsApp. Linking data between services augments the dangers and the consequences are not obvious to the end user. I…

>For years companies have been steadily asking, mandating or even trickling users to give them their phone numbers under the excuse of security (while the real reasons were different), now what? >How can they be trusted anymore? I don't know if they can. I had specific conversations about things life preferring TOTP to phone in internship and job interviews, but I struggled to land the prestigious roles others did, t…

What does the last sentence have to do with trust?

Re: Facebook does not plan to notify half-billion users affected by data leak

#138
post #115

Earlier quoted context omitted.

zuckerberg's infamous "dumb f**ks" quote comes to mind.

[flagged]

Given the number of times this quote has been dutifully typed in this thread, HN finally found its narwhal to bacon at data breach, it seems. It’s interesting to watch the competition between those flagging it off the site and those repeating it, apparently unaware it’s been flagged and removed already.

Re: Facebook does not plan to notify half-billion users affected by data leak

#139

Earlier quoted context omitted.

If Facebook has since deleted some of those accounts or associated phone numbers, they may no longer have a way to contact those users. The GDPR in Europe would require them to delete that data in a bunch of circumstances.

Because they might have deleted some of the accounts they no longer have an obligation to notify the rest that they haven't deleted?

While this may be true, this doesn’t have to be an all-or-nothing thing.

Re: Facebook does not plan to notify half-billion users affected by data leak

#140

Earlier quoted context omitted.

The beach has phone numbers and emails- why wouldn't they be able to contact those users with that information?

Facebook can't use the breach itself to contact users, no. The data could have been tampered with, and besides, Facebook doesn't have permission to process the leaked data in that way.

[deleted]
Post reply on HN