Live data from Hacker News

Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

privacyaffairs.com

81–90 of 160 posts

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#81
post #2

I know everyone on HN loves to hate on Facebook, but the fact that HN's servers are getting crushed when FB is down perhaps shows a revealed preference.

I'm more of a 'shit on Facebook' man myself but I'm not above hate.

I find it hard to find fault with people expressing disgust with how knowingly predatory and exploitative the company's leadership have proven themselves to be.

Exhibit A: https://www.bbc.com/news/technology-58678332

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#83
post #51
post #26

Earlier quoted context omitted.

> everything I used to be able to get in a phone book Fair, although you could opt out of the phone book. (And I don't think they had location/address, though it's been so long now that I can't remember for sure.) > I think people are grappling with the fact that the Internet just makes data scraping and processing possible on a scale previously unimaginable This is it right here. The scale and ease of access are ter…

> And I don't think they had location/address, > though it's been so long now that I can't remember for sure Same here. initially i too couldn't remember for sure. Then i remembered the scene from Terminator 2 (1991) in which it looks up Sarah Connor's phone-number and home-address in a phone-book! :-)

It was earlier - the 1984 movie (Terminator) had the scene where he rips out the page from the phone book, looking for the Sarah Connors listed there. :)

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#84

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

> more sensitive personal information (like social security numbers or other government ID numbers)

I tend to think that there should be a publicly accessible, unique, and more or less immutable ID number for every citizen or resident. This ID would have pointers to our name, birth date and a few other identifiers that shouldn't really be considered secret.

My concern is that the absence of such a unique ID leads to a mess of overlapping systems in which only large organizations with the resources to track everyone will be able to uniquely identify people. So we'll have a degree of anonymity from random other individuals, not not from banks, tech corporations or the government. Computing power is becoming too cheap and ubiquitous to effectively hide information that isn't explicitly confidential. That is, as a society we need to adjust to a paradigm in which it is more expensive to keep information confidential than to allow it to be public. Especially keeping information private from those with deep pockets.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#85
post #46

Earlier quoted context omitted.

It's not just Facebook. Your phone is tattling on you 24/7. ALPRs are recording where you drive. Browser fingerprinting is creating a profile on you even if you block ads and trackers. Short of never using a computer, there is no opt out anymore.

That's a little different thought and I think you know it. There's a difference between information that government and big tech is scraping and storing, vs information that is publicly available to literally any random person online to scrape. Both are problems, but those are different discussions and we started with talking about the issue of truly publicly available information. I think that's an interesting topic…

A little different, yes, but what I'm saying is that it's not substantially different. Once data is collected, it won't be uncollected, and all it takes is one hack to permanently turn a private database into a public one. And the data that's being collected in these private databases is often justified on the grounds that it's not private information--i.e., if you're outside, you have no expectation of privacy. So in that sense it is "truly public" information. But what I'm saying is that the meaning of public/private has fundamentally changed because of the kind of differences of scale we're talking about here. In other words, there was a degree of implicit privacy afforded by the level of effort required to catalog and search "public" data. Whether that data comes from public or private databases is, I think, not particularly relevant.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#86

I honestly ask myself how the f Zuck has the guts and ego to still talk about a "metaverse" with a company and product so wrong, so poisonous and evil to humanity. I really can't wait to see him in jail already.

I'm not a big fan of Facebook but the hatred toward that company here is getting out of hand. You want to see Zuck in jail for what crime exactly? How is Twitter, Youtube, TikTok or Reddit any better than Facebook when it comes to being "poisonous" or "evil"? Youtube was literally financing terrorist groups with ad money 10 years ago. Twitter gives a platform to anti-Semites and the Taliban.

Perhaps those in power tend to be evil and don't deserve the air they breathe.

Why do you think it is out of hand, and what exactly do you mean by that? I will have a careful, lengthy discussion with you, if you'd like.

I'll open with the claim that what is moral is not necessarily what is legal.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#87
post #69

Earlier quoted context omitted.

Couldn't a social security number be easily bruteforced anyway

Yes. SSNs are distributed by year in blocks that are granted to hospitals. If you know a person's year and place of birth you can brute force them. For example if you wanted to generate plausible identities you could just use a common Jewish last name and get the SSN block from a major hospital in NYC for a high birth year. Say, 1955. The odds that you will be able to guess the SSN for Abraham Goldstein born in Manha…

10,000 is probably going to be the largest number of guesses needed, and if you have prior knowledge, like a distributed set of ssns from the same year and location, you can reduce the practical effective number of guesses to a few dozen.

The freely available databases of pii in the wild can be used to infer anything missing from releases like this, and that stuff can be used to inform probabilistic password guesses, and so on. It's only a matter of time before deep learning models make most common password based security measures completely transparent and obsolete.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#88
post #26

Earlier quoted context omitted.

> everything I used to be able to get in a phone book Fair, although you could opt out of the phone book. (And I don't think they had location/address, though it's been so long now that I can't remember for sure.) > I think people are grappling with the fact that the Internet just makes data scraping and processing possible on a scale previously unimaginable This is it right here. The scale and ease of access are ter…

All listed numbers in the White Pages had street addresses. Having an unlisted number was a premium service — you had to pay to be private.

Sure, but you weren't in the white pages if you weren't already paying for a phone. At that point the question of whether you're getting a discount for agreeing to be in the book, or paying not to be in the book is just an arbitrary distinction.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#90

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

Problem is user id link. From there you can get much more info. Facebook should be legally forced to reindex users and void all current user ids.
Post reply on HN