Live data from Hacker News

From email to phone number, a new OSINT approach (2019)

martinvigo.com

1–10 of 127 posts

Re: From email to phone number, a new OSINT approach (2019)

#4
lol

> Paypal, which displays five digits including area code to anyone knowing the email address (but only three if the attacker knows the target’s password), decided this is working as designed and will not take action.

Wild.

Does anyone know how scammers are getting numbers off of LinkedIn? Or correlating them to numbers from elsewhere? I know a company whose employees are constantly getting fake CEO texts.

Re: From email to phone number, a new OSINT approach (2019)

#5
post #3

This kind of uncoordinated leaking is a deeper problem. Many share the last four digits of a SS#. Okay. But often the first five are easy to guess from the birthday and the birth state. The first few digits tell the state where the number was issued.

Hell a lot of people have a last 4 digit that is literally just their mothers birth year.

Re: From email to phone number, a new OSINT approach (2019)

#6
post #3

This kind of uncoordinated leaking is a deeper problem. Many share the last four digits of a SS#. Okay. But often the first five are easy to guess from the birthday and the birth state. The first few digits tell the state where the number was issued.

Only for ones issued prior to 2011. While this encompasses any current adult it is something to keep note of.

Re: From email to phone number, a new OSINT approach (2019)

#7
post #3

This kind of uncoordinated leaking is a deeper problem. Many share the last four digits of a SS#. Okay. But often the first five are easy to guess from the birthday and the birth state. The first few digits tell the state where the number was issued.

The core problem is that we have an utterly idiotic system in which knowing a nine-digit number lets you do any harm whatsoever.

We have all the worst parts of a proper national ID system—tracking and data gathering by government and other large organizations isn’t hindered a bit, and we’re required to engage with our ad-hoc national ID system all the time for anything important—but none of the benefits.

Tons of suffering and wasted time, for no damn reason.

Re: From email to phone number, a new OSINT approach (2019)

#9
post #4

lol > Paypal, which displays five digits including area code to anyone knowing the email address (but only three if the attacker knows the target’s password), decided this is working as designed and will not take action. Wild. Does anyone know how scammers are getting numbers off of LinkedIn? Or correlating them to numbers from elsewhere? I know a company whose employees are constantly getting fake CEO texts.

I just realized this is from 2019 and confirmed this literally still works on PayPal. SMH

Re: From email to phone number, a new OSINT approach (2019)

#10
post #8

Can someone summarize this? I think the site is struggling with traffic and I'm getting 503'd...

Martin Vigo's article discusses the security vulnerabilities in password reset options for various websites and how these can lead to the exposure of personal phone numbers. Vigo highlights that during a password reset process, websites often partially reveal the user's phone number. This partial display varies across websites; some show the last four digits, others the first, and so on. By initiating password resets across different sites, one can potentially piece together most of the digits of a phone number just from an email address.
Post reply on HN