Live data from Hacker News

Facebook privacy fuckup reveals who has your number in their phone

alexmuir.com

51–60 of 124 posts

Re: Facebook privacy fuckup reveals who has your number in their phone

#51
post #46

Earlier quoted context omitted.

Because, as the article says, it can reveal Facebook accounts that you didn't knew your friends had, such has this friend of the OP who has a "straight" and a "gay" FB account.

I'm not sure that's such a huge sin -- technically I think FB says that you cannot have more than 1 account/actual person; I'd imagine when this `feature` was baked in the engineers didn't imagine that anyone would maintain an account that 1) they would keep hidden from friends _and_ 2) add their phone numbers to. At the very least, the friend could have blocked the set of people he didn't want to know about his pref…

That simple search by name would not show his account with the gay persona - so they thought they were safe. His phone # was probably not listed publicly either.

You work at Facebook, don't you?

Re: Facebook privacy fuckup reveals who has your number in their phone

#52
post #48

These little privacy leaks are not important on their own. A little data leaks here, a little there. What is concerning is that we can guarantee private investigators and professional identity fraudsters are well on top of all these little loopholes. And combined, I'd say Facebook is probably pissing data out. Some sweet law enforcement potential here - slap in a request to Facebook on a drug-dealing suspect, find a…

If you are truly concerned about harm to users, did you try reporting this to facebook.com/security or facebook.com/whitehat? FWIW, I've alerted some people. Your post is unclear on one point. Did you see this screen BEFORE confirming via SMS that you were in possession of the mobile number you entered? If it was after confirmation, that's a very different thing.

For context of readers, I note you are a FB engineer. Thanks for looking at this.

1. I'm not concerned about harm to users from this issue, I don't pretend to be. That should be Facebook's role.

2. This isn't a bug or a vulnerability, it's something you've actually coded - a feature. It doesn't 'accidentally' match up the number I've just entered with other people's phonebooks, you've programmed it to do that. Fine, that's a commercial choice made by Facebook (value of engaging new users vs concerns over publicising people's phonebooks) - but reporting it through those links would be nothing more than a complaint letter.

Re: Facebook privacy fuckup reveals who has your number in their phone

#53
post #48

Earlier quoted context omitted.

If you are truly concerned about harm to users, did you try reporting this to facebook.com/security or facebook.com/whitehat? FWIW, I've alerted some people. Your post is unclear on one point. Did you see this screen BEFORE confirming via SMS that you were in possession of the mobile number you entered? If it was after confirmation, that's a very different thing.

For context of readers, I note you are a FB engineer. Thanks for looking at this. 1. I'm not concerned about harm to users from this issue, I don't pretend to be. That should be Facebook's role. 2. This isn't a bug or a vulnerability, it's something you've actually coded - a feature. It doesn't 'accidentally' match up the number I've just entered with other people's phonebooks, you've programmed it to do that. Fine,…

/whitehat is not a "complaint letter". It goes directly to the security team oncall, whose job is to keep users safe even if it means killing things written by other engineers at Facebook that had unintended consequences.

(edit: removed snark)

Re: Facebook privacy fuckup reveals who has your number in their phone

#54
I suppose it's worth noting that your gay friend had to add your phone number to his secret account, which is a privacy snafu on his part. After all, if he was trying to hide his sexual orientation from you, why would he enter your contact details into that account?

We also have to take some responsibility for our security and privacy.

Re: Facebook privacy fuckup reveals who has your number in their phone

#55
post #48

Earlier quoted context omitted.

If you are truly concerned about harm to users, did you try reporting this to facebook.com/security or facebook.com/whitehat? FWIW, I've alerted some people. Your post is unclear on one point. Did you see this screen BEFORE confirming via SMS that you were in possession of the mobile number you entered? If it was after confirmation, that's a very different thing.

For context of readers, I note you are a FB engineer. Thanks for looking at this. 1. I'm not concerned about harm to users from this issue, I don't pretend to be. That should be Facebook's role. 2. This isn't a bug or a vulnerability, it's something you've actually coded - a feature. It doesn't 'accidentally' match up the number I've just entered with other people's phonebooks, you've programmed it to do that. Fine,…

Exactly. It's timely to discuss where the line is drawn in sharing user data. Trickling here and there amounts to what can be summed up as gaping holes.

As time went by, it seems that Facebook left behind their mantra of exclusivity and private social circles. They are vigorously facilitating the opposite when you see 'features' like this.

Re: Facebook privacy fuckup reveals who has your number in their phone

#56
post #54

I suppose it's worth noting that your gay friend had to add your phone number to his secret account, which is a privacy snafu on his part. After all, if he was trying to hide his sexual orientation from you, why would he enter your contact details into that account? We also have to take some responsibility for our security and privacy.

He didn't... Most likely his phone did it for him.

Re: Facebook privacy fuckup reveals who has your number in their phone

#57
post #53

Earlier quoted context omitted.

For context of readers, I note you are a FB engineer. Thanks for looking at this. 1. I'm not concerned about harm to users from this issue, I don't pretend to be. That should be Facebook's role. 2. This isn't a bug or a vulnerability, it's something you've actually coded - a feature. It doesn't 'accidentally' match up the number I've just entered with other people's phonebooks, you've programmed it to do that. Fine,…

/whitehat is not a "complaint letter". It goes directly to the security team oncall, whose job is to keep users safe even if it means killing things written by other engineers at Facebook that had unintended consequences. (edit: removed snark)

Well, what I am wondering is: is this actually an unintended consequence or a conscious choice that has been made?

Re: Facebook privacy fuckup reveals who has your number in their phone

#58
post #46

Earlier quoted context omitted.

I'm not sure that's such a huge sin -- technically I think FB says that you cannot have more than 1 account/actual person; I'd imagine when this `feature` was baked in the engineers didn't imagine that anyone would maintain an account that 1) they would keep hidden from friends _and_ 2) add their phone numbers to. At the very least, the friend could have blocked the set of people he didn't want to know about his pref…

That simple search by name would not show his account with the gay persona - so they thought they were safe. His phone # was probably not listed publicly either. You work at Facebook, don't you?

I am supposed to _start_ work at FB assuming I get a visa.

I'm a bit curious about why a search for name won't show the alternate persona? I've had friends who made 2 profiles and both used to show up whenever I typed their name in; and his # being listed publicly doesn't affect the argument either way.

Edit: Reply to child comment by jarofgreen: apparently the comments are too deeply nested to reply directly: "using FB wrong therefore deserves to have his privacy violated"

I've never stated that he _deserved_ to get his privacy violated; it's simply that the behaviour of any s/w is based on what settings you choose. Your argument would have to be that it's the S/Ws fault for not being transparent enough/not easily understandable enough leading the user to be misled - but the general response seems to be that the s/w is actively out to get the user.

Re: Facebook privacy fuckup reveals who has your number in their phone

#59
post #57
post #53

Earlier quoted context omitted.

/whitehat is not a "complaint letter". It goes directly to the security team oncall, whose job is to keep users safe even if it means killing things written by other engineers at Facebook that had unintended consequences. (edit: removed snark)

Well, what I am wondering is: is this actually an unintended consequence or a conscious choice that has been made?

[deleted]

Re: Facebook privacy fuckup reveals who has your number in their phone

#60
post #48

These little privacy leaks are not important on their own. A little data leaks here, a little there. What is concerning is that we can guarantee private investigators and professional identity fraudsters are well on top of all these little loopholes. And combined, I'd say Facebook is probably pissing data out. Some sweet law enforcement potential here - slap in a request to Facebook on a drug-dealing suspect, find a…

If you are truly concerned about harm to users, did you try reporting this to facebook.com/security or facebook.com/whitehat? FWIW, I've alerted some people. Your post is unclear on one point. Did you see this screen BEFORE confirming via SMS that you were in possession of the mobile number you entered? If it was after confirmation, that's a very different thing.

[deleted]
Post reply on HN