Live data from Hacker News

From email to phone number, a new OSINT approach (2019)

martinvigo.com

31–40 of 127 posts

Re: From email to phone number, a new OSINT approach (2019)

#31

One thing I've always wondered is how security researchers feel justified in releasing tools like the one in this blog post to the public. I can almost certainly say that the number of bad or creepy uses for an automated email to phone number generating tool massively outweighs the good reasons for having one. Does he get a pass because he's doing this for "research" and it's a grey area anyways? Does he feel better…

Similarly to how Journalists feel justified in stories that have negative repercussions for some parties being reported upon. One way of assessing these decisions is answering the question "Is more harm done than good by releasing information this to the public?"

From my perspective, I'm happy that Martin Vigo released this information (in 2019) as it helped me inform my employers (and now my clients) to additional threat model vectors to consider before deciding how to best perform password resets.

Also in his defense: 1) He originally released a rather crippled form of the PoC 2) It requires a Twilio account, which raises the barrier to entry and provides a data point for analysts were the tool to be used criminally.

Re: From email to phone number, a new OSINT approach (2019)

#32

One thing I've always wondered is how security researchers feel justified in releasing tools like the one in this blog post to the public. I can almost certainly say that the number of bad or creepy uses for an automated email to phone number generating tool massively outweighs the good reasons for having one. Does he get a pass because he's doing this for "research" and it's a grey area anyways? Does he feel better…

I think the idea is to highlight the bad security practices that allow this in hopes that these companies patch these holes (in this case reduce leaked data in the password reset process). A GREAT example of this was when Firesheep forced Facebook (and countless other sites) into embracing https. Firesheep was a firefox plugin that anyone could run on a public wifi (e.g. coffee shop) and instantly start getting the p…

> I don't know that this release will be that impactful

It was released in 2019 and it is still going on, so unfortunately it wasn't.

Re: From email to phone number, a new OSINT approach (2019)

#33

> If it is a requirement, consider using a virtual number like Google Voice or even a dedicated SIM that you only use for this purpose and never give the number away. For the second SIM option, that requires a dual-SIM device, which are still fairly niche in the US. When it comes to VOIP numbers, unfortunately, many sites look up phone numbers and block VOIP providers, which sucks because Android still has no good wa…

eBay doesn't block Google voice numbers. The only site which seems to is Discord in my experience.

Personally I prefer to use a non-obvious dedicated email per account e.g. ebpnw@mydomain.com, so the attacker has to guess the email as well.

Re: From email to phone number, a new OSINT approach (2019)

#34

> If it is a requirement, consider using a virtual number like Google Voice or even a dedicated SIM that you only use for this purpose and never give the number away. For the second SIM option, that requires a dual-SIM device, which are still fairly niche in the US. When it comes to VOIP numbers, unfortunately, many sites look up phone numbers and block VOIP providers, which sucks because Android still has no good wa…

> For the second SIM option, that requires a dual-SIM device Or a device that supports an eSIM, which is every iPhone since 2018, for starters.

The eSIM is going to be more expensive than a regular SIM since no MVNO I'm aware of in the US supports eSIMs

Re: From email to phone number, a new OSINT approach (2019)

#35
post #34

Earlier quoted context omitted.

> For the second SIM option, that requires a dual-SIM device Or a device that supports an eSIM, which is every iPhone since 2018, for starters.

The eSIM is going to be more expensive than a regular SIM since no MVNO I'm aware of in the US supports eSIMs

Mint.

Re: From email to phone number, a new OSINT approach (2019)

#36

There's one missing piece in that article, and it's the CNAM database (US only). CNAM is the database that carriers use to give you alphanumeric caller ID ("SMITH JOHN" instead of "+1 (555) 123-4567"). Many carriers don't display this data as far as I believe, but most of them make it available. Querying that database isn't free, but you could probably find a way to do it for a few hundred numbers relatively cheaply.…

Why is this not tied to a person's SSN (if possible)?

Re: From email to phone number, a new OSINT approach (2019)

#38

Keeping a phone number secret is "security by obscurity" and therefore the whole point of this article is rather moot.

Not completely, when you have the email + the phone number, you can make much more sophisticated phishing attempts

Re: From email to phone number, a new OSINT approach (2019)

#39
post #5
post #3

This kind of uncoordinated leaking is a deeper problem. Many share the last four digits of a SS#. Okay. But often the first five are easy to guess from the birthday and the birth state. The first few digits tell the state where the number was issued.

Hell a lot of people have a last 4 digit that is literally just their mothers birth year.

Last four of their SSN? That makes no sense, those digits are sequentially assigned at the issuing office.

Re: From email to phone number, a new OSINT approach (2019)

#40
post #34

Earlier quoted context omitted.

> For the second SIM option, that requires a dual-SIM device Or a device that supports an eSIM, which is every iPhone since 2018, for starters.

The eSIM is going to be more expensive than a regular SIM since no MVNO I'm aware of in the US supports eSIMs

I'm also not aware of any but that's less about whether they're actually available and almost entirely because like 7.6 billion other people, I don't live in the US.
Post reply on HN