Live data from Hacker News

WhatsApp data leak: 500M user records for sale

cybernews.com

61–70 of 109 posts

Re: WhatsApp data leak: 500M user records for sale

#61
post #29

The norm for personal communications really ought to shift to a new protocol that doesn't expose phone numbers. It would be nice if I had a list of people who have my contact added and just remove their ability to do so without my consent. It would solve security, privacy, telemarketing, all sorts of nuisances.

Something like Matrix? https://matrix.org/

Yeah, but with a conveniently usable implementation.

Re: WhatsApp data leak: 500M user records for sale

#62
post #43

Earlier quoted context omitted.

signal does what you say and keep the convience of connecting people via phone numbers, if you optin. but they still have a closed server... so who knows what really is logged where. still infinitely better than whatsbook/telegram/appleID/google/microsoft alternatives

Signal uses (or used?) SGX for remote attestation, which presumably lets the client verify that the code running on the server is a build of the OSS code and not a modified version. But I don't know the details or if this is reliable. SGX and remote attestation described here: https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/secure-value-recovery/

I wonder, how could one use SGX for remote attestation when they didn't publish the source code for more than a year just to get their insiders' knowledge cryptocoin deployed.

Re: WhatsApp data leak: 500M user records for sale

#63
post #9

Earlier quoted context omitted.

The basic stuff helps a decent amount. Assume your name, phone, email, address are all public. Don't reuse passwords, ever (use a password manager), use 2fa wherever possible, ideally not the SMS kind. Use a password manager that has a tie-in with haveibeenpwned or whatever so you know asap to change your creds. Some extras: use unique email addresses per site if you can. Some setups allow infinite aliases. Then you…

>Some extras: use unique email addresses per site if you can. Some setups allow infinite aliases. Then you can blackhole one that gets leaked, and you can know where it got leaked from. If you pay for ProtonMail, you get a SimpleLogin Premium for free, which makes the creation of dummy/alias emails a lot easier. They're owned by the same company.

I've been using alias addresses since forever, though with Tutanota, not Proton (due to cost & nice app). It's great when you can simply deactivate an address and the spam stops coming.

Re: WhatsApp data leak: 500M user records for sale

#64
post #18

So... what advise is there for technology comfortable people who want to mitigate the effects of data leaks like these? It seems like data provided is will be exposed eventually and company size doesn't seem correlate with data safety. For example should people be advised to rotate phone numbers every N amount of time?

The advise is to do literally nothing about it. What effect do you think this specific leak has on you? What kind of adversary do you think will be able to benefit from this data, and how? The reality is that the data is useless trash, and there is no indication that this has actually leaked from Facebook or is showing any kind of security problem in their systems.

That remains to be seen. People are fairly ingenious when it comes to abusing information and information runs the world now. I will offer an unrelated example, partially because I do not want to give ideas on how to benefit from this. Do you remember when certain entrepreneurial billionaire offered a checkmark for sale, which resulted in people impersonating companies and manipulating their stock price[1]?

Like with most things, any tool is worth what one is able to do with it.

I would not advise to panic, but doing nothing is not exactly great advice either. Some re-assessment of one's current security posture may be warranted.

[1]https://www.fiercepharma.com/marketing/eli-lilly-hit-new-twi...

Re: WhatsApp data leak: 500M user records for sale

#68

I wonder what percent of "hacks" are from insiders, or from inside information/credentials given to outsiders. With the huge number of people involved in these companies, there has to be some percentage of illicit leaking going on.

E.g., https://www.wsj.com/articles/meta-employees-security-guards-...
Post reply on HN