Live data from Hacker News

From email to phone number, a new OSINT approach (2019)

martinvigo.com

51–60 of 127 posts

Re: From email to phone number, a new OSINT approach (2019)

#51

> If it is a requirement, consider using a virtual number like Google Voice or even a dedicated SIM that you only use for this purpose and never give the number away. For the second SIM option, that requires a dual-SIM device, which are still fairly niche in the US. When it comes to VOIP numbers, unfortunately, many sites look up phone numbers and block VOIP providers, which sucks because Android still has no good wa…

I broke down and bought a prepaid SIM and a small dumb phone which I use solely for 2FA. Its about the size as old-school 2FA systems like crypto cards. My original motivation in getting it was my wife was always taking my real phone to get security codes for some shared accounts (on sites that don't have an option for linked accounts). But I also like that it provides small OPSEC improvements over using my real telephone number.

Re: From email to phone number, a new OSINT approach (2019)

#52
Fun to see this issue get talked about. Ancedote- I bought some car parts from a semi-scammer. Not a full-on scam but the guy wouldn't ship the complete order even though he had my money for several weeks. We had communicated on a few different platforms. Each platform offered up a little piece of his identity. Last four of this. First four of that. It was enough to piece it all together. I gave him a call at his place of employment which happened to be in the exact same industry as the parts that were being sold. I asked him to ship the parts and casually asked if his employer was involved in the sale. He perked right up and the next day he shipped everything I had bought and a few extras.

Re: From email to phone number, a new OSINT approach (2019)

#53

One thing I've always wondered is how security researchers feel justified in releasing tools like the one in this blog post to the public. I can almost certainly say that the number of bad or creepy uses for an automated email to phone number generating tool massively outweighs the good reasons for having one. Does he get a pass because he's doing this for "research" and it's a grey area anyways? Does he feel better…

> I can almost certainly say that the number of bad or creepy uses for an automated email to phone number generating tool massively outweighs the good reasons for having one Meanwhile, I can almost certainly say that the number of ways to bury your head in the sand instead of simply facing an uncomfortable problem massively outweighs the good reasons for doing so anyway. A person who is in need of money and lacking i…

I think knowing that this is a vulnerability is fine. The tool is what I take issue with.

I mean creepy as in a violation of a right to privacy. I don't consent to you knowing my phone number or any PII I put into private websites.

It's a lot easier to get caught lockpicking and it has some legitimate uses. This is like more like an autopicking machine imo.

Re: From email to phone number, a new OSINT approach (2019)

#54

One thing I've always wondered is how security researchers feel justified in releasing tools like the one in this blog post to the public. I can almost certainly say that the number of bad or creepy uses for an automated email to phone number generating tool massively outweighs the good reasons for having one. Does he get a pass because he's doing this for "research" and it's a grey area anyways? Does he feel better…

The bad guys know these and a million more exploits already so personally I'm fine with these guys exposing the industries dirty laundry especially if it shames them into doing something. There is also no defense from the company that they did not know when it comes to legal action.

Re: From email to phone number, a new OSINT approach (2019)

#55

Fun to see this issue get talked about. Ancedote- I bought some car parts from a semi-scammer. Not a full-on scam but the guy wouldn't ship the complete order even though he had my money for several weeks. We had communicated on a few different platforms. Each platform offered up a little piece of his identity. Last four of this. First four of that. It was enough to piece it all together. I gave him a call at his pla…

[flagged]

Re: From email to phone number, a new OSINT approach (2019)

#56
post #51

> If it is a requirement, consider using a virtual number like Google Voice or even a dedicated SIM that you only use for this purpose and never give the number away. For the second SIM option, that requires a dual-SIM device, which are still fairly niche in the US. When it comes to VOIP numbers, unfortunately, many sites look up phone numbers and block VOIP providers, which sucks because Android still has no good wa…

I broke down and bought a prepaid SIM and a small dumb phone which I use solely for 2FA. Its about the size as old-school 2FA systems like crypto cards. My original motivation in getting it was my wife was always taking my real phone to get security codes for some shared accounts (on sites that don't have an option for linked accounts). But I also like that it provides small OPSEC improvements over using my real tele…

That's a great idea for a shared 2FA device

Re: From email to phone number, a new OSINT approach (2019)

#57
post #55

Fun to see this issue get talked about. Ancedote- I bought some car parts from a semi-scammer. Not a full-on scam but the guy wouldn't ship the complete order even though he had my money for several weeks. We had communicated on a few different platforms. Each platform offered up a little piece of his identity. Last four of this. First four of that. It was enough to piece it all together. I gave him a call at his pla…

[flagged]

He easily could have bought parts for a better price seeing as his has the hook-up through his employer.

Without further detail none of us can know the results. Calling someone a thief is a bit of a move…

Re: From email to phone number, a new OSINT approach (2019)

#58
post #34

Earlier quoted context omitted.

The eSIM is going to be more expensive than a regular SIM since no MVNO I'm aware of in the US supports eSIMs

Almost all of them do now, since iPhones don't have SIM card slots in the US anymore.

Thanks. Apparently my info was out-of-date; I last checked in early 2022.

Re: From email to phone number, a new OSINT approach (2019)

#59

There's one missing piece in that article, and it's the CNAM database (US only). CNAM is the database that carriers use to give you alphanumeric caller ID ("SMITH JOHN" instead of "+1 (555) 123-4567"). Many carriers don't display this data as far as I believe, but most of them make it available. Querying that database isn't free, but you could probably find a way to do it for a few hundred numbers relatively cheaply.…

Why is this not tied to a person's SSN (if possible)?

Is there an accessible database somewhere that would allow T-Mobile to get a name from an SSN (or verify that an SSN and a name match)?

Re: From email to phone number, a new OSINT approach (2019)

#60
post #48

Earlier quoted context omitted.

Last four of their SSN? That makes no sense, those digits are sequentially assigned at the issuing office.

Yes, last four. Don't ask me how I know.. Might be a "born on base" thing but it's no coincidence.

It is a coincidence. You have a 1-in-10000 chance of getting any 4 digit number and they assign 5.5M a year, so we can expect that 550 people get their mother's year of birth every year. You just happened to get 1961.

(Total guess but how cool would it be if I was right?)

Post reply on HN