Live data from Hacker News

Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

privacyaffairs.com

51–60 of 160 posts

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#51
post #26

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

> everything I used to be able to get in a phone book Fair, although you could opt out of the phone book. (And I don't think they had location/address, though it's been so long now that I can't remember for sure.) > I think people are grappling with the fact that the Internet just makes data scraping and processing possible on a scale previously unimaginable This is it right here. The scale and ease of access are ter…

  > And I don't think they had location/address,  
  > though it's been so long now that I can't remember for sure
Same here. initially i too couldn't remember for sure.

Then i remembered the scene from Terminator 2 (1991) in which it looks up Sarah Connor's phone-number and home-address in a phone-book! :-)

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#53
post #22
post #11

Earlier quoted context omitted.

> So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because it obviously is. With a phonebook (at least back in the day), you didn't risk having your account exposed and sold for a few dollars. Nor did that risk someone getting access to thousands, if not more, bank accounts or whatever through automation. In addition,…

> Facebook gives you the illusion that you can opt of this data being public. What makes you think that that isn't the case here? It sounds like they just scraped all the public profiles they could find. It's not a database "leak" or something like that.

Right, that's what I mean with "Facebook gives you the illusion that you can opt out of this data being public".

I recall when I still had Facebook, many people would randomly add you and pretend to be random people, sometimes famous, sometimes they "just want to be friends". I know most people have some settings along the lines of "no one except friends can see all this data". This is an issue, because people will add these "friends" and forget about these permissions. These "friends" can easily be attackers like these that suddenly have access to all your data. Hence the "illusion".

With a phonebook on the other hand, when you opt out, you've opted out.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#54
post #2

I know everyone on HN loves to hate on Facebook, but the fact that HN's servers are getting crushed when FB is down perhaps shows a revealed preference.

Not really. I noticed a lot of greyed-out comments cheering on Facebook being down

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#55
post #4

I'm glad I never gave FB my real phone number or birthday. Nobody should. I predicted this would happen some day. It's always just a matter of probability and time.

The day Facebook locked me out and asked for photo ID to get back in, that was the last day I used FB.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#56
post #26

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

> everything I used to be able to get in a phone book Fair, although you could opt out of the phone book. (And I don't think they had location/address, though it's been so long now that I can't remember for sure.) > I think people are grappling with the fact that the Internet just makes data scraping and processing possible on a scale previously unimaginable This is it right here. The scale and ease of access are ter…

Yeah, strong agree from me.

What is weird to me are so many of the responses to my comment are along the lines of "But the real danger now is that all of this data can be correlated with other sources of info, and it's all instantly searchable." It's weird to me because that's the point I was trying to make in my last paragraph, to explain that that really has nothing to do with Facebook. The "hackers" aren't even claiming there was a breach, just information they screen scraped. The ability to amass giant databases of information and make it available to the world to search is something fundamentally inherent to the Internet.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#57
post #45

I don't consider my name, date of birth or the city I live in to be personal information.

> I don't consider my name, date of birth or the city I live in to be personal information.

Of course it is personal information.

I think what you are trying to say is that you do not consider this data to be sensitive personal information. Emphasis on sensitive.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#58
post #17
post #2

I know everyone on HN loves to hate on Facebook, but the fact that HN's servers are getting crushed when FB is down perhaps shows a revealed preference.

Or it could be as simple as everyone wants to discuss one of the biggest tech companies suffering such a massive outage, combined with the aforementioned FB-haters basking in this moment.

Following Twitter, HN is top 2 places to check during an outage.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#59
post #26

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

> everything I used to be able to get in a phone book Fair, although you could opt out of the phone book. (And I don't think they had location/address, though it's been so long now that I can't remember for sure.) > I think people are grappling with the fact that the Internet just makes data scraping and processing possible on a scale previously unimaginable This is it right here. The scale and ease of access are ter…

All listed numbers in the White Pages had street addresses. Having an unlisted number was a premium service — you had to pay to be private.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#60

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

With a land line phone number from a phonebook, criminals can’t do much. With a smartphone number they can hack phones, potentially steal bank accounts, track their location and on and on.

As an example, my parents have been bombarded with calls from a scammer who it seems only has their phone number and email address, but that’s enough to give away their full names and the name of the ISP, so the scammer is using it to call and pretend to be the ISP support trying to trick them into giving up 2FA codes from password reset attempts they do at the same time while calling that phone. You don’t need much info to go a long way!
Post reply on HN