Live data from Hacker News

Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

privacyaffairs.com

131–140 of 160 posts

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#131
post #53
post #22

Earlier quoted context omitted.

> Facebook gives you the illusion that you can opt of this data being public. What makes you think that that isn't the case here? It sounds like they just scraped all the public profiles they could find. It's not a database "leak" or something like that.

Right, that's what I mean with "Facebook gives you the illusion that you can opt out of this data being public". I recall when I still had Facebook, many people would randomly add you and pretend to be random people, sometimes famous, sometimes they "just want to be friends". I know most people have some settings along the lines of "no one except friends can see all this data". This is an issue, because people will a…

Many people added you like that? Just asked a few people. No one gets many FB rando requests that aren’t super obviously fake. It isn’t that common.

I’ve had FB since 2007. Don’t recall there ever being a surge.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#132
post #116
post #26

Earlier quoted context omitted.

> everything I used to be able to get in a phone book Fair, although you could opt out of the phone book. (And I don't think they had location/address, though it's been so long now that I can't remember for sure.) > I think people are grappling with the fact that the Internet just makes data scraping and processing possible on a scale previously unimaginable This is it right here. The scale and ease of access are ter…

> And I don't think they had location/address They most definitely did have addresses.

This info had a logical purpose also. Phone books without location and address would be mostly useless because lots of people share the same name.

To find the phone number of a friend having just "John Smith, USA" would be impossible (or would annoy thousands of people and require months of calls).

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#133
post #51

Earlier quoted context omitted.

> And I don't think they had location/address, > though it's been so long now that I can't remember for sure Same here. initially i too couldn't remember for sure. Then i remembered the scene from Terminator 2 (1991) in which it looks up Sarah Connor's phone-number and home-address in a phone-book! :-)

I believe the LGR channel has shown some DOS programs from before 1990 that had the entire catalogue of the US phonebook available in a neat DOS UI, where you just choose a location/state (or non at all) then enter a letter and it would filter every entry on the chosen filter... (Name was ProPhone 1993, so not really pre 90's) https://youtu.be/yBupNdYe08g?t=1078

Yep, they were called Reverse Pages. You would buy the CD, and then just read the database yourself. This allowed you to type an address and you could get their phone number etc

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#134
post #51

Earlier quoted context omitted.

> And I don't think they had location/address, > though it's been so long now that I can't remember for sure Same here. initially i too couldn't remember for sure. Then i remembered the scene from Terminator 2 (1991) in which it looks up Sarah Connor's phone-number and home-address in a phone-book! :-)

I believe the LGR channel has shown some DOS programs from before 1990 that had the entire catalogue of the US phonebook available in a neat DOS UI, where you just choose a location/state (or non at all) then enter a letter and it would filter every entry on the chosen filter... (Name was ProPhone 1993, so not really pre 90's) https://youtu.be/yBupNdYe08g?t=1078

Yep, they were called Reverse Grey Pages. You would buy the CD, and then just read the database yourself. This allowed you to type an address and you could get their phone number etc

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#135
post #51

Earlier quoted context omitted.

> And I don't think they had location/address, > though it's been so long now that I can't remember for sure Same here. initially i too couldn't remember for sure. Then i remembered the scene from Terminator 2 (1991) in which it looks up Sarah Connor's phone-number and home-address in a phone-book! :-)

I believe the LGR channel has shown some DOS programs from before 1990 that had the entire catalogue of the US phonebook available in a neat DOS UI, where you just choose a location/state (or non at all) then enter a letter and it would filter every entry on the chosen filter... (Name was ProPhone 1993, so not really pre 90's) https://youtu.be/yBupNdYe08g?t=1078

The ones in Australia where one way - you could search for a name and it would give you a phone and address... but if you a programmer, you could read the database directly, so search on a phone number and get back the address and name, or search an address and get back name and phone number.

There were a few services in the early 2000s doing this, they were called Reverse Grey Pages

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#136

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

[deleted]

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#137

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

The new phone books are here!!

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#138

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

"So basically everything I used to be able to get in a phone book."

Assuming you had phone books from every city/region in every country. Thats a lot of phone books so you must have had a large warehouse to store them all. Then there is the fact that phone books did not list number for every individual. Multiple persons routinely shared the same number.

The comparison sounds apt in theory but in practice it isn't. Try looking these Facebook users up in the phone books of their respective locales, via the telcos' online phone books or directory assistance. Then, using what you find, tell me their email address, gender and Facebook user ID.

Good luck.

The problem with this argument, "all email addresses are public", which I see regularly on HN, is that information does not become "public" and lose its "private" designation if it is published without consent or lawful purpose. If someone steals secrets and publishes them, they are still secrets.

Whether this information from Facebook is truly "private" I cannot say but I do think it is possible to have email addresses that are not made public.

The recent NSO iMessage story was interesting because the exploit seemed to rely on NSO getting lists of mobile phone numbers for the targets. Not email addresses. Yet iMessage will work without a phone number, with no SIM inserted. Perhaps the targets chose to use phone numbers for iMessage, not email addresses.

Consider what happens if someone creates a Gmail address but never uses it to send mail, and never shares the address with anyone, except Facebook. If this person does not make their Facebook profile public, how is this address public information. Google does not publish a list of every Gmail address. According to the logic of the parent comment, they might just as well. Email addresses are "public", right. Because some HN commenters think they are.

What happened when someone scraped Apple's servers to obtain the email addresses of Apple iPad users. Did federal prosecutors think the information was "public" or "private". The media called the incident "theft of e-mail addresses".^1

1. http://www.nbcnews.com/id/41196595

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#140
post #120

Earlier quoted context omitted.

> And I don't think they had location/address I lived in a lot of different places in the US in the 70s and 80s. All the phone books had residential addresses listed. This is the format and font I remember: https://groovyhistory.com/content/50602/01af8c322a21e50d0b81...

Yes, they did (at least in my part of the US). But... you could tell the phone company not to list your address, and then they wouldn't. If you wanted to pay a monthly fee for even more privacy, you could have your number unlisted entirely.

And because families shared a phone only some family members would be listed in it.
Post reply on HN