Live data from Hacker News

WhatsApp data leak: 500M user records for sale

cybernews.com

21–30 of 109 posts

Re: WhatsApp data leak: 500M user records for sale

#22
post #17
post #3

Earlier quoted context omitted.

Quoted post unavailable.

It's disgusting that this comment had to be vouched for, it's common sense.

It's also low quality.

Not using WhatsApp isn't going to magically secure your details online.

As per GP's point, most services eventually seem to leak data, so it may as well be saying "Don't go online".

Compare that to the alternate response which provides solid actionable advice for how to limit exposure when these services ultimately leak your data, and you can see why that post was downvoted to oblivion.

Re: WhatsApp data leak: 500M user records for sale

#23
post #9

So... what advise is there for technology comfortable people who want to mitigate the effects of data leaks like these? It seems like data provided is will be exposed eventually and company size doesn't seem correlate with data safety. For example should people be advised to rotate phone numbers every N amount of time?

The basic stuff helps a decent amount. Assume your name, phone, email, address are all public. Don't reuse passwords, ever (use a password manager), use 2fa wherever possible, ideally not the SMS kind. Use a password manager that has a tie-in with haveibeenpwned or whatever so you know asap to change your creds. Some extras: use unique email addresses per site if you can. Some setups allow infinite aliases. Then you…

Assume your name, phone, email, address are all public.

Someone on HN will invariably point out that this is how it was for the last hundred years, and it was only when we made computers powerful enough to abuse the information that this level of privacy became a concern.

I remember the days when your name, address, and phone number were public information. I paid something like $15/month to keep it out of the phone book.

What I recently learned, browsing through old books that a local library was throwing away, is that sometimes those phone book listings would also include things like a woman's maiden name, and the name of her husband, and/or marital status. Something like:

  Smith, Margaret C (nee Jones, widow of George): 202-555-1212
That part was new to me.

Re: WhatsApp data leak: 500M user records for sale

#24
post #8

These seem to be “just” phone numbers. Most of which probably already leaked through the last Facebook leak. Not sure how significant the data is.

That’s not leak actually, phone information about active/inactive is open. Anybody can run a spider to collect this.

Re: WhatsApp data leak: 500M user records for sale

#25

So... what advise is there for technology comfortable people who want to mitigate the effects of data leaks like these? It seems like data provided is will be exposed eventually and company size doesn't seem correlate with data safety. For example should people be advised to rotate phone numbers every N amount of time?

People should be advised to not use phone numbers at all.

There was a joke "all phone numbers leaked" list that just listed everything from 000-000-0000 to 999-999-9999. If there is no other information associated (names, pictures, emails, anything) then this leak is of almost comparable severity.

Re: WhatsApp data leak: 500M user records for sale

#26
post #9

Earlier quoted context omitted.

The basic stuff helps a decent amount. Assume your name, phone, email, address are all public. Don't reuse passwords, ever (use a password manager), use 2fa wherever possible, ideally not the SMS kind. Use a password manager that has a tie-in with haveibeenpwned or whatever so you know asap to change your creds. Some extras: use unique email addresses per site if you can. Some setups allow infinite aliases. Then you…

>Some extras: use unique email addresses per site if you can. Some setups allow infinite aliases. Then you can blackhole one that gets leaked, and you can know where it got leaked from. If you pay for ProtonMail, you get a SimpleLogin Premium for free, which makes the creation of dummy/alias emails a lot easier. They're owned by the same company.

That sounds nice. I use bitwarden's "plus addressed email" generator I think it's called, the downside being that I need to specifically blackhole anything that bypasses the plus-addressing, or it'd be easy for anyone that actually looks to bypass.

There still is the chance that some spammer will figure out that "blah+any-random-string" works for my email, but I'll deal with that if someone bothers someday. I'd just need to add an allow-list or something probably.

Re: WhatsApp data leak: 500M user records for sale

#27
>To prevent personal data leaks, regular users should adopt common data security practices. This includes using a high-quality VPN and getting a reliable antivirus program. And since the shopping holidays are close, you can already find great market-leading NordVPN Black Friday and TotalAV deals.

What a disgusting site... Adding this blurb to a "news" article with "security measures" that do absolutely nothing against phone number scraping just to get those affilliate clicks...

Re: WhatsApp data leak: 500M user records for sale

#28

Earlier quoted context omitted.

You can check whith your own cellphone, if a phone number have a Whatsapp account, without any hacker knowledge, this is not significant at all.

> this is not significant at all. I wonder if HN community would say same if Telegram data was leaked in a similar way

I might be missing something here. Why would HN care any differently about WhatsApp vs Telegram?

Re: WhatsApp data leak: 500M user records for sale

#29
The norm for personal communications really ought to shift to a new protocol that doesn't expose phone numbers.

It would be nice if I had a list of people who have my contact added and just remove their ability to do so without my consent.

It would solve security, privacy, telemarketing, all sorts of nuisances.

Re: WhatsApp data leak: 500M user records for sale

#30
post #9

Earlier quoted context omitted.

The basic stuff helps a decent amount. Assume your name, phone, email, address are all public. Don't reuse passwords, ever (use a password manager), use 2fa wherever possible, ideally not the SMS kind. Use a password manager that has a tie-in with haveibeenpwned or whatever so you know asap to change your creds. Some extras: use unique email addresses per site if you can. Some setups allow infinite aliases. Then you…

Assume your name, phone, email, address are all public. Someone on HN will invariably point out that this is how it was for the last hundred years, and it was only when we made computers powerful enough to abuse the information that this level of privacy became a concern. I remember the days when your name, address, and phone number were public information. I paid something like $15/month to keep it out of the phone…

In Sweden almost everything about you is public information. Your address, social security number, tax records, criminal record etc.
Post reply on HN