Live data from Hacker News

Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

privacyaffairs.com

91–100 of 160 posts

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#91

Earlier quoted context omitted.

> Fair, although you could opt out of the phone book. (And I don't think they had location/address, though it's been so long now that I can't remember for sure.) you can opt out of Facebook too... and Irish phone books had addresses...

you can opt out of Facebook too This is not true. Facebook builds profiles about millions of people who have never had a Facebook account. For example, people who happened to be in the background of a photograph taken by a stranger. Another example: people who installed an app on their phone without knowing that it included a Facebook SDK that was tracking them. This is nothing new. It's been discussed in public, and…

Yes, shadow profiles exist and really show how shallow Facebook's promises of privacy are:

https://www.theverge.com/2018/4/11/17225482/facebook-shadow-...

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#92

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

In the past "public" did not mean a single, all-encompassing global village of information that anyone on earth with a computer could get access to. People then operated within local shells of information, extending outward from the neighborhood block to the city to the country and maybe finally to the world.

What time you walk your dog each day would be neighborhood level public info. Phone numbers would be city level. For greater reach than that you usually had to put the info out there yourself or be someone of media prominence.

Nowadays the time you walk your dog is out on the internet because it was leaked from some Amazon S3 bucket collecting pings from your dog's smart collar. And what more it's been joined with your name, phone number, and other personal info to create an automated profile of you by interested groups.

That's a whole different ball game, and not one that many people expect despite living their lives (in their minds) the same way as before.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#93

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

>I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers).

The flipside of this is that we need to make it such that simply knowing someone's Name, Address, DOB, and SSN is not adequate to fraudulently assume their financial identity and incur debts in their name.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#94
1. You publish your information on a public site designed to disseminate information to as many people as possible.

2. Somebody sees this information and records it.

3. They publish this information on another site.

4. "Hackers stole my private data!!!!"

Really?!

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#96
SearchPeopleFreecom pretty much has a ton on a good majority of people. Get their phone number and if you want learn a lot about them. So it just compiles public information. No opinion whether it's a good or bad thing here from me just pointing it out.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#97

What a broken product. There isn’t 1.5B users with public profiles in FB, so whatever methods these guys used clearly went beyond regular data scrapping.

Do you have a source for that? Facebook claim 2.9 billion MAUs, half of them having a public profile seems pretty likely to me.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#98
post #40

(just a wild theory) Is the downtime (at the time of writing) their way of blocking a known ongoing attack that can't be stopped fast and safely enough by other means? Something like: 1) take everything down, 2) fix the bug, 3) deploy everywhere, 4) start everything up. And, to stop clients from connecting, take down the DNS too. DNS is also a great scapegoat.

I worked at WhatsApp until 2019; I don't remember any disaster plans where taking everything down was an option (although I'm sure they exist), but dropping BGP sessions is probably not the best way to do it, because it's hard to reverse and hard to inspect the system without BGP.

Over in WA land, we'd probably just kill all the frontend servers if needed. For all of FB infrastructure, killing all the loadbalancers would probably work, and also the outgoing proxy hosts, as appropriate. No need to mess with DNS or BGP.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#100
post #10

Earlier quoted context omitted.

It could be more than that. Vodafone broadband Internet (used to be UPC) is down in all of Czech Republic since about an hour. Their website is down (vodafone.cz), their mobile Internet seems slow. Coincidence?

If you change your DNS servers, it works! Their DNS servers probably crashed due to FB's DNS not resolving! ( https://twitter.com/BlazejKrajnak )

I tried changing DNS server, including 8.8.8.8 and 1.1.1.1, nothing doing.

I looked up Facebook IP address and tried to go there directly, bypassing the DNS. No response.

(I don't care about Facebook much, it was a test. WhatsApp though I have to use to communicate with relatives.)

Post reply on HN