Live data from Hacker News

WhatsApp data leak: 500M user records for sale

cybernews.com

41–50 of 109 posts

Re: WhatsApp data leak: 500M user records for sale

#41
post #8

These seem to be “just” phone numbers. Most of which probably already leaked through the last Facebook leak. Not sure how significant the data is.

You can check whith your own cellphone, if a phone number have a Whatsapp account, without any hacker knowledge, this is not significant at all.

That mostly seems to be what they did lol!

“ 2. Only Verified Whatsapp Numbers - Country Wise ( This is to cover all the mobile subscribers exhaustively . We generate mobile numbers based teh series allocated for the telecom operators in each countries and then verify / validate those numbers with the Whatsapp Servers )”

Re: WhatsApp data leak: 500M user records for sale

#42
post #29

The norm for personal communications really ought to shift to a new protocol that doesn't expose phone numbers. It would be nice if I had a list of people who have my contact added and just remove their ability to do so without my consent. It would solve security, privacy, telemarketing, all sorts of nuisances.

signal does what you say and keep the convience of connecting people via phone numbers, if you optin. but they still have a closed server... so who knows what really is logged where. still infinitely better than whatsbook/telegram/appleID/google/microsoft alternatives

A closed/open source server doesn't matter since you can't actually confirm if the open source version is actually running.

Re: WhatsApp data leak: 500M user records for sale

#43
post #29

The norm for personal communications really ought to shift to a new protocol that doesn't expose phone numbers. It would be nice if I had a list of people who have my contact added and just remove their ability to do so without my consent. It would solve security, privacy, telemarketing, all sorts of nuisances.

signal does what you say and keep the convience of connecting people via phone numbers, if you optin. but they still have a closed server... so who knows what really is logged where. still infinitely better than whatsbook/telegram/appleID/google/microsoft alternatives

Signal uses (or used?) SGX for remote attestation, which presumably lets the client verify that the code running on the server is a build of the OSS code and not a modified version. But I don't know the details or if this is reliable.

SGX and remote attestation described here:

https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/secure-value-recovery/

Re: WhatsApp data leak: 500M user records for sale

#44

Are there any other data associated with the number, other than the country and whether it has a WhatsApp account? You can check if a given number is on WhatsApp easily, and associate the country based on the phone format itself. Make this for all possible phone numbers (big number, but not impossibly big) and you will have a "leak". Edit: having a list of WhatsApp users already generated for you is easier than check…

Photos and I imagine in most cases, full names.

Re: WhatsApp data leak: 500M user records for sale

#45
I have ran into several crypto groups adding me to their group. I was not the only one. Several people were in this category who would be added randomly. They would eventually leave. And then another set of people would be added. I always wondered how they got my and people’s numbers.

I think this is their database leak.

Re: WhatsApp data leak: 500M user records for sale

#46
post #30

Earlier quoted context omitted.

In Sweden almost everything about you is public information. Your address, social security number, tax records, criminal record etc.

Out of curiosity: does this lead to more identity theft (or misuse)?

I live in Norway, which has a similar system, so I can’t answer for op, but the answer here is, no. Your “social security number” is not ever used as a password or other form of presumably secret key. While you probably don’t go blabbing it everywhere, there’s not much you can do if you know mine. You would also have to physically steal my phone and also learn my secret pin, or break into my fire safe in order to successfully use my personal number for anything. Address and phone number are the same thing, that’s just where you mail things to, it’s not used as a secret key.

Re: WhatsApp data leak: 500M user records for sale

#47

Earlier quoted context omitted.

Profile pictures come to mind.

Profile, last connection time and status is public unless configured to not be. I was thinking about data not obtainable without a normal use of the service.

> Profile, last connection time and status is public

Isn't those details (+ profile pictures) only available only you've accepted the first message from another user?

I think I recall that I cannot see a persons avatar when I message first unless they hit "Accept message" after me sending the message.

Is it not like that everywhere perhaps? I use Whatsapp with a number in the EU region.

Re: WhatsApp data leak: 500M user records for sale

#48
post #26

Earlier quoted context omitted.

>Some extras: use unique email addresses per site if you can. Some setups allow infinite aliases. Then you can blackhole one that gets leaked, and you can know where it got leaked from. If you pay for ProtonMail, you get a SimpleLogin Premium for free, which makes the creation of dummy/alias emails a lot easier. They're owned by the same company.

That sounds nice. I use bitwarden's "plus addressed email" generator I think it's called, the downside being that I need to specifically blackhole anything that bypasses the plus-addressing, or it'd be easy for anyone that actually looks to bypass. There still is the chance that some spammer will figure out that "blah+any-random-string" works for my email, but I'll deal with that if someone bothers someday. I'd just…

Yeah definitely; the "+" alias is built in to most emails (like, it works on Google/Proton at least). I'm more just saying that if you pay for ProtonMail (and therefore care about privacy more than the average person) you get another service for free that doesn't expose your "real" email if someone cared to look.

Someone can look at joe+spam@joeschmo.com and figure out Joe's "real" email address. Something like SimpleLogin (sorry, not a shill for them, I swear) gives you a completely new email/domain (and lets you set up your OWN domains), which then forwards to your proper inbox.

Re: WhatsApp data leak: 500M user records for sale

#49
post #35

I really need to figure out how to save off all the pictures and videos from WhatsApp iOS so I can uninstall it.

Export each (or the most important) chats as zip files.

How? when I try to backup my chats, whatsapp says my only option is to send them to google (i dont want to do that even if they're encrypted)

Re: WhatsApp data leak: 500M user records for sale

#50

Earlier quoted context omitted.

Profile, last connection time and status is public unless configured to not be. I was thinking about data not obtainable without a normal use of the service.

> Profile, last connection time and status is public Isn't those details (+ profile pictures) only available only you've accepted the first message from another user? I think I recall that I cannot see a persons avatar when I message first unless they hit "Accept message" after me sending the message. Is it not like that everywhere perhaps? I use Whatsapp with a number in the EU region.

It depends on the other party's privacy settings. You can set it to display the profile picture to Everyone or Contacts.
Post reply on HN