Live data from Hacker News

Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

privacyaffairs.com

121–130 of 160 posts

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#121
post #4

I'm glad I never gave FB my real phone number or birthday. Nobody should. I predicted this would happen some day. It's always just a matter of probability and time.

The day Facebook locked me out and asked for photo ID to get back in, that was the last day I used FB.

IANAL but is it legal to just use a fake ID with photoshopped numbers, considering there is no legal or financial damage done in doing so in the FB case? You aren't causing someone to serve alcohol to minors, you aren't giving it to the government, you're just telling a social media giant that they have no right to that information.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#123

Earlier quoted context omitted.

Any particular reason you think a metaverse is incompatible with an evil organization? The evil co. in Ready Player One, the movie, literally imprisoned people and used them for forced labor. (then, somehow, the CEO gets arrested by regular cops, lol).

> (then, somehow, the CEO gets arrested by regular cops, lol). Because he had a gun in hand not because of his forced labor practices.

You're not wrong, but on some level given his freedom to enslave and murder people, it is surprising that in universe he is vulnerable to normal cops

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#124
post #119

Earlier quoted context omitted.

The day Facebook locked me out and asked for photo ID to get back in, that was the last day I used FB.

IANAL but is it legal to just use a fake ID with photoshopped numbers, considering there is no legal or financial damage done in doing so in the FB case? You aren't causing someone to serve alcohol to minors, you aren't giving it to the government, you're just telling a social media giant that they have no right to that information. I'm looking at this https://www.shouselaw.com/ca/defense/vehicle-code/470b/ and IANAL…

> "in order to cause loss or damage to a legal, financial, or property right".

It would be a stretch, but perhaps an imaginative prosecutor could claim that the user is trying to diminish Facebook's finances/property by generating web responses (using CPU time and electricity) which it otherwise wouldn't.

That's discounting all the expansive interpretations of the CFAA which would deem any breach of Facebook's terms of service to be an act of illegal hacking, not to mention an interpretation of copyright law that asserted that the user was receiving unlicensed copies of Facebook's intellectual property (e.g. their HTML).

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#126
post #120
post #26

Earlier quoted context omitted.

> everything I used to be able to get in a phone book Fair, although you could opt out of the phone book. (And I don't think they had location/address, though it's been so long now that I can't remember for sure.) > I think people are grappling with the fact that the Internet just makes data scraping and processing possible on a scale previously unimaginable This is it right here. The scale and ease of access are ter…

> And I don't think they had location/address I lived in a lot of different places in the US in the 70s and 80s. All the phone books had residential addresses listed. This is the format and font I remember: https://groovyhistory.com/content/50602/01af8c322a21e50d0b81...

Yes, they did (at least in my part of the US).

But... you could tell the phone company not to list your address, and then they wouldn't.

If you wanted to pay a monthly fee for even more privacy, you could have your number unlisted entirely.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#127

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

My neighbour who is 87 years old has all the phone books from tbe Lage 50s-mid 60s. I checked my grandfather and it listed bis adress, phone and occupation.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#128
post #98
post #40

(just a wild theory) Is the downtime (at the time of writing) their way of blocking a known ongoing attack that can't be stopped fast and safely enough by other means? Something like: 1) take everything down, 2) fix the bug, 3) deploy everywhere, 4) start everything up. And, to stop clients from connecting, take down the DNS too. DNS is also a great scapegoat.

I worked at WhatsApp until 2019; I don't remember any disaster plans where taking everything down was an option (although I'm sure they exist), but dropping BGP sessions is probably not the best way to do it, because it's hard to reverse and hard to inspect the system without BGP. Over in WA land, we'd probably just kill all the frontend servers if needed. For all of FB infrastructure, killing all the loadbalancers w…

I agree that it's highly unlikely to be a deliberate action, but your listed mitigations would only help against security issues that impact the web services.

It could be the only way to go in the highly unlikely scenario that attackers are able to compromise the management APIs of various infrastructure devices like routers, baremetal servers etc.

These APIs are usually on airgapped networks though, which makes this extremely unlikely

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#129

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

> So basically, everything I used to be able to get in a phone book.

Even if people didn't have unlisted numbers, phone books would allow listing only last name and first initial of one person in the household, without any location data beyond the phone book service area (you could provide more if you wanted to be found), and didn’t include gender.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#130

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

Wait until HN readers find out what these faceless companies that appear around election time and mail me junk are able to gleam from public voting registration data.
Post reply on HN