Live data from Hacker News

Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

privacyaffairs.com

61–70 of 160 posts

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#61
post #17

Earlier quoted context omitted.

Or it could be as simple as everyone wants to discuss one of the biggest tech companies suffering such a massive outage, combined with the aforementioned FB-haters basking in this moment.

As the CEO of a social network with more active users than Facebook, I am very confident in my analysis.

I see what you did there

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#62
post #40

(just a wild theory) Is the downtime (at the time of writing) their way of blocking a known ongoing attack that can't be stopped fast and safely enough by other means? Something like: 1) take everything down, 2) fix the bug, 3) deploy everywhere, 4) start everything up. And, to stop clients from connecting, take down the DNS too. DNS is also a great scapegoat.

Also thinking that these two events are not independent...

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#63
post #38
post #4

I'm glad I never gave FB my real phone number or birthday. Nobody should. I predicted this would happen some day. It's always just a matter of probability and time.

If you want to talk about a matter of probability, your real phone number and birthday are almost certainly already out there.

I have a fake birthday I use consistently across most of the internet.

I don't have a consistent "real" phone number -- I change it periodically. I then have virtual numbers that redirect to those, which I change from time to time as well.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#64

Some might laugh this off as 'oh it's just scraping'. But I remember reading some comments in HN that there are apps that can scan faces and pull personal info including where they live, work etc. So each leak uncovers a person little by little. This vindicates the stance taken by Signal to not even collect metadata. Edit: I mean surreptitiously scan the face of a stranger you see in public and the app will tell you…

https://pimeyes.com does just that, I just posted it here on HN.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#65
post #46

Earlier quoted context omitted.

> Fair, although you could opt out of the phone book. (And I don't think they had location/address, though it's been so long now that I can't remember for sure.) you can opt out of Facebook too... and Irish phone books had addresses...

It's not just Facebook. Your phone is tattling on you 24/7. ALPRs are recording where you drive. Browser fingerprinting is creating a profile on you even if you block ads and trackers. Short of never using a computer, there is no opt out anymore.

"Ooh, lookit that funny car over there!" - points phone almost at your face, takes picture - uploads picture to Facebook

You'd literally have to have the kind of Momma that would dig a hole and hide you in it at birth to really be "off the grid" at this point.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#66
post #4

I'm glad I never gave FB my real phone number or birthday. Nobody should. I predicted this would happen some day. It's always just a matter of probability and time.

Never gave mine either, but that’s the strength of FB: you don’t even need to have an account. They know everything about you because your friends, family and colleagues gave them that information.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#67
post #26

Earlier quoted context omitted.

> everything I used to be able to get in a phone book Fair, although you could opt out of the phone book. (And I don't think they had location/address, though it's been so long now that I can't remember for sure.) > I think people are grappling with the fact that the Internet just makes data scraping and processing possible on a scale previously unimaginable This is it right here. The scale and ease of access are ter…

> Fair, although you could opt out of the phone book. (And I don't think they had location/address, though it's been so long now that I can't remember for sure.) you can opt out of Facebook too... and Irish phone books had addresses...

you can opt out of Facebook too

This is not true.

Facebook builds profiles about millions of people who have never had a Facebook account. For example, people who happened to be in the background of a photograph taken by a stranger. Another example: people who installed an app on their phone without knowing that it included a Facebook SDK that was tracking them.

This is nothing new. It's been discussed in public, and even before the U.S. congress.

Personally, I'd love to opt out of Facebook. But I can't. Because I can't log in to my Facebook account, and Facebook ignores my requests for access. I even did the "send in a picture of your government ID" route, and nothing happened. So please inform me how I can opt out of Facebook's data gathering.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#68

“The traders claim to have obtained the data by scraping rather than hacking or compromising individual users’ accounts.”

I think they're just riding the Facebook wave for more clicks. This is hardly news.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#69

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

Couldn't a social security number be easily bruteforced anyway

Yes. SSNs are distributed by year in blocks that are granted to hospitals. If you know a person's year and place of birth you can brute force them. For example if you wanted to generate plausible identities you could just use a common Jewish last name and get the SSN block from a major hospital in NYC for a high birth year. Say, 1955. The odds that you will be able to guess the SSN for Abraham Goldstein born in Manhattan in 1955 are going to be pretty good, especially if you have some oracle that will let you guess several times.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#70
Expected in all honesty, data these days is a currency to be bartered. I despise facebooks and everything it stands for, I wish people would take themselves more seriously. This need to fill a void with nonsense, is just simply unbecoming. So, suffer the consequences.
Post reply on HN