Live data from Hacker News

WhatsApp data leak: 500M user records for sale

cybernews.com

51–60 of 109 posts

Re: WhatsApp data leak: 500M user records for sale

#51

I have ran into several crypto groups adding me to their group. I was not the only one. Several people were in this category who would be added randomly. They would eventually leave. And then another set of people would be added. I always wondered how they got my and people’s numbers. I think this is their database leak.

Yup, and there's a setting in WhatsApp I enabled that only allows my contacts to add me to groups. This should prevent this annoying issue.

Re: WhatsApp data leak: 500M user records for sale

#52

Are there any other data associated with the number, other than the country and whether it has a WhatsApp account? You can check if a given number is on WhatsApp easily, and associate the country based on the phone format itself. Make this for all possible phone numbers (big number, but not impossibly big) and you will have a "leak". Edit: having a list of WhatsApp users already generated for you is easier than check…

No post body was provided.

Re: WhatsApp data leak: 500M user records for sale

#53
post #26

Earlier quoted context omitted.

That sounds nice. I use bitwarden's "plus addressed email" generator I think it's called, the downside being that I need to specifically blackhole anything that bypasses the plus-addressing, or it'd be easy for anyone that actually looks to bypass. There still is the chance that some spammer will figure out that "blah+any-random-string" works for my email, but I'll deal with that if someone bothers someday. I'd just…

Yeah definitely; the "+" alias is built in to most emails (like, it works on Google/Proton at least). I'm more just saying that if you pay for ProtonMail (and therefore care about privacy more than the average person) you get another service for free that doesn't expose your "real" email if someone cared to look. Someone can look at joe+spam@joeschmo.com and figure out Joe's "real" email address. Something like Simpl…

Yeah it's definitely a better pattern, I hope more companies create something like it. I think I heard Apple is doing something similar maybe? I seem to recall Fastmail has one too, pretty sure I saw it in the bitwarden settings last I went in there.

Re: WhatsApp data leak: 500M user records for sale

#54
post #9

Earlier quoted context omitted.

The basic stuff helps a decent amount. Assume your name, phone, email, address are all public. Don't reuse passwords, ever (use a password manager), use 2fa wherever possible, ideally not the SMS kind. Use a password manager that has a tie-in with haveibeenpwned or whatever so you know asap to change your creds. Some extras: use unique email addresses per site if you can. Some setups allow infinite aliases. Then you…

>Some extras: use unique email addresses per site if you can. Some setups allow infinite aliases. Then you can blackhole one that gets leaked, and you can know where it got leaked from. If you pay for ProtonMail, you get a SimpleLogin Premium for free, which makes the creation of dummy/alias emails a lot easier. They're owned by the same company.

> If you pay for ProtonMail

These are free for all-

https://relay.firefox.com/

https://duckduckgo.com/email/

Re: WhatsApp data leak: 500M user records for sale

#55
post #43

Earlier quoted context omitted.

signal does what you say and keep the convience of connecting people via phone numbers, if you optin. but they still have a closed server... so who knows what really is logged where. still infinitely better than whatsbook/telegram/appleID/google/microsoft alternatives

Signal uses (or used?) SGX for remote attestation, which presumably lets the client verify that the code running on the server is a build of the OSS code and not a modified version. But I don't know the details or if this is reliable. SGX and remote attestation described here: https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/secure-value-recovery/

It should be possible to independently verify Signal's attestation, but I don't know if anyone has done it. Before you go and say "what's even the point then", the point is that this gives Signal plausible deniability for when the TLAs show up asking for user info.

Re: WhatsApp data leak: 500M user records for sale

#56
post #29

The norm for personal communications really ought to shift to a new protocol that doesn't expose phone numbers. It would be nice if I had a list of people who have my contact added and just remove their ability to do so without my consent. It would solve security, privacy, telemarketing, all sorts of nuisances.

Something like Matrix?

https://matrix.org/

Re: WhatsApp data leak: 500M user records for sale

#58

Earlier quoted context omitted.

signal does what you say and keep the convience of connecting people via phone numbers, if you optin. but they still have a closed server... so who knows what really is logged where. still infinitely better than whatsbook/telegram/appleID/google/microsoft alternatives

A closed/open source server doesn't matter since you can't actually confirm if the open source version is actually running.

If it's open source and has a reproducible build, then you can audit the codebase, compute the hash, then verify an attestation from the secure enclave that the code is running in.

Re: WhatsApp data leak: 500M user records for sale

#59
post #3

So... what advise is there for technology comfortable people who want to mitigate the effects of data leaks like these? It seems like data provided is will be exposed eventually and company size doesn't seem correlate with data safety. For example should people be advised to rotate phone numbers every N amount of time?

Quoted post unavailable.

Except that even if I don't use WhatsApp and somebody I know and who has my contact information does, WhatsApp also has my contact information.
Post reply on HN