Live data from Hacker News

Facebook does not plan to notify half-billion users affected by data leak

reuters.com

151–160 of 315 posts

Re: Facebook does not plan to notify half-billion users affected by data leak

#151
post #83

Earlier quoted context omitted.

"Where?!" Everywhere. It's being phased out in many places, but as a rule of thumb, mostly everywhere still. "known to be very bad ... been shouting ..." Right, yeah, to put it in some perspective remember that you're talking second factor here. This is not your login, this is a secondary confirmation and you still need some serious motivation to bypass it. It's definitely doable, I work in security and I know what k…

I'd never seen or heard of it being used for payments before, which is why I asked - I'd heard of phone numbers being used as account names (effectively) in some payment systems, but being involved in the workflow of making payments is entirely novel to me. I'm aware it's not your login, but it feels the same as asking someone for publicly searchable information to "verify your identity" - an additional "security" st…

What better options are there that have approximately the same ease of use?

SMS works with every conceivable phone, even most landlines if need be, users don't have to install a separate authenticator app, which may require a Google/iCloud password (now where did I put that post-it note?), that takes up space that may be scarce on low-end phones and that may not even be compatible with very old phones, leaving affected people in a really unsatisfactory spot.

Then they need to set up codes for every login, figure out how to switch back and forth between apps and how to copy codes, which is not very discoverable at least in Google Authenticator – most people seem to memorize and type instead, cumbersome.

Hardware tokens are even worse, people misplace those a lot and unless you are a bank with a mature process for issuing these, setup is probably even more of a hassle.

All of this may be big deal if you (also) target less technical people and want them to use your product when they have the option not to.

With SMS, all the user needs is a phone number. Pretty much everyone is familiar with that, most will readily share it, too. iOS will even extract codes and show them on top of the keyboard, just wait a second or two and tap the code, done. It's about as painless and frictionless as it can reasonably be, with apparently relatively inconsequential security drawbacks – given it's supposedly trivial to fake SMS, there don't seem to be a lot of people doing so at scale. Maybe a breach like this one will finally change that? Remains to be seen.

For now I can totally see why one might stick with SMS as a second factor.

Re: Facebook does not plan to notify half-billion users affected by data leak

#152

"The Facebook spokesman said the social media company *was not confident it had full visibility on which users would need to be notified*." @Facebook here you go: https://haveibeenpwned.com

If Facebook has since deleted some of those accounts or associated phone numbers, they may no longer have a way to contact those users. The GDPR in Europe would require them to delete that data in a bunch of circumstances.

Have another up of coffee, the data is in the leak.

Re: Facebook does not plan to notify half-billion users affected by data leak

#153
post #93

Earlier quoted context omitted.

Never trust caller ID or senderid on phone calls or SMS. The reason is that phone companies interoperate grudgingly and do the minimum required to pass calls and messages between each other, and also most phone companies are 100+ year old companies who have just layered modern tech on top of their old stuff. They handle a massive unending stream of calls/messages and they can't possibly validate each one (even if the…

>they can't possibly validate each one // Why not? They don't pass on all metadata, that's part of the problem. If a call originates in $foreign_country, the sender gets to spoof it as a local call (sometimes they even use your own phone number). Are you really telling me there's no way to tell the difference between an off-shore call and a local one. It seems if this were true that billing is impossible, yet somehow…

There are valid use cases for spoofing caller ID.

It’s been a long time since I dabbled with Asterisk (IP PBX), IIRC, by default the call forwarding/redirection function uses metadata from the original incoming call. Let’s say, you’ve programmed your PBX that after 30 seconds of incoming call ringing, you want to redirect/forward the call (that is to make a new leg, and then connect them together) to your mobile phone number. I’m pretty sure, on your mobile phone you’d want to see the original caller’s number for incoming call, not the PBX’s phone number.

Re: Facebook does not plan to notify half-billion users affected by data leak

#154

Earlier quoted context omitted.

A company that employs dozes of data scientists and has petabytes of data is now supposedly unable to compare and match two datasets? Come on, this is beyond ridiculous.

Clearly they technically can. It's that the GDPR doesn't allow it. Think about it... If you asked a company to delete your data, are you giving them permission to go refind that data on the dark web, cross reference it with records they should have deleted, and use it to send you email? Clearly not.

I doubt Facebook gives a shit about the GDPR

Re: Facebook does not plan to notify half-billion users affected by data leak

#155
post #87

For years companies have been steadily asking, mandating or even trickling users to give them their phone numbers under the excuse of security (while the real reasons were different), now what? How can they be trusted anymore? This also strikes a great point about the data sharing between Facebook and WhatsApp. Linking data between services augments the dangers and the consequences are not obvious to the end user. I…

> I think Facebook should offer their users the option to remove their phone numbers with a real deletion.

Man sometimes I think people forget phone books existed for a long time.

Re: Facebook does not plan to notify half-billion users affected by data leak

#157

"The Facebook spokesman said the social media company *was not confident it had full visibility on which users would need to be notified*." @Facebook here you go: https://haveibeenpwned.com

If Facebook has since deleted some of those accounts or associated phone numbers, they may no longer have a way to contact those users. The GDPR in Europe would require them to delete that data in a bunch of circumstances.

[flagged]

Re: Facebook does not plan to notify half-billion users affected by data leak

#158

Earlier quoted context omitted.

A company that employs dozes of data scientists and has petabytes of data is now supposedly unable to compare and match two datasets? Come on, this is beyond ridiculous.

Clearly they technically can. It's that the GDPR doesn't allow it. Think about it... If you asked a company to delete your data, are you giving them permission to go refind that data on the dark web, cross reference it with records they should have deleted, and use it to send you email? Clearly not.

If GDPR prevents people from being notified that their data was breached, then the GDPR needs revision.

Re: Facebook does not plan to notify half-billion users affected by data leak

#159

Earlier quoted context omitted.

Kids are more likely to text, less likely to email these days. I can understand why they’d use SMS for their target demographic. That doesn’t justify the security implications of doing this...

Do kids still text or is that a generation or two removed from the current iMessages/WhatsApp/Signal/WhateverComesAfterSignalBecauseImOldAndDontKnow?

I'm sure they'd prefer to receive notifications from their university on WhateverComesAfterSignalBecauseImOldAndDontKnow, but I imagine that SMS is the 2nd best thing (and probably still generates eye-rolling about the university being old fashioned).

Re: Facebook does not plan to notify half-billion users affected by data leak

#160
post #10

This huge leak has definitely killed the SMS text messaging service. Sender can be spoofed and spam/scam/phishing have reached an intolerable level. The fact that they can cross reference you and then produce a more personalized content is huge. Changing password is easy (ok less easy if you recycle it) but changing phone number is something that I am not even relaxed to do.

Can anyone on HN please explain why, why, WHY are we still using SMS/telephony which has exactly 0 encryption wh---I guess that's the reason? It's insane. I've heard banks using SMS!!!! To send a code. We have TOTP for that! Or even perhaps a push notification or something better than bloody SMS. I refuse to use the networking system altogether. No phones, no calls. Of course you do 'need' a number so I keep one hand…

I don't know anything about the technical details with this, but I wonder why mobile service providers don't just kill off regular SMS and calling, and start providing service exclusively through data connections? The infrastructure for that old stuff can't be free for them, there must be some significant costs associated with it.

Maybe Starlink will be able to provide a mobile phone service that only offers a data connection one day, and that will be the "disruption" the mobile industry needs.

Post reply on HN