Live data from Hacker News

From email to phone number, a new OSINT approach (2019)

martinvigo.com

81–90 of 127 posts

Re: From email to phone number, a new OSINT approach (2019)

#81

Fun to see this issue get talked about. Ancedote- I bought some car parts from a semi-scammer. Not a full-on scam but the guy wouldn't ship the complete order even though he had my money for several weeks. We had communicated on a few different platforms. Each platform offered up a little piece of his identity. Last four of this. First four of that. It was enough to piece it all together. I gave him a call at his pla…

I re-read this, not to fire back but to understand how you arrive at your conclusion. I think you are interpreting (or assuming maybe), from when I asked about his employer, that I suspected he stole the parts from his employer. That's not the case at all. I just needed a pressure point.

Re: From email to phone number, a new OSINT approach (2019)

#82

Earlier quoted context omitted.

Similarly to how Journalists feel justified in stories that have negative repercussions for some parties being reported upon. One way of assessing these decisions is answering the question "Is more harm done than good by releasing information this to the public?" From my perspective, I'm happy that Martin Vigo released this information (in 2019) as it helped me inform my employers (and now my clients) to additional t…

> Similarly to how Journalists feel justified in stories that have negative repercussions for some parties being reported upon. One way of assessing these decisions is answering the question "Is more harm done than good by releasing information this to the public?" That method leads to the worst evils in the world. Many have concluded, or used it to justify everything from, 'it's ok to take these poor people's land a…

eh?

Re: From email to phone number, a new OSINT approach (2019)

#83
post #55

Fun to see this issue get talked about. Ancedote- I bought some car parts from a semi-scammer. Not a full-on scam but the guy wouldn't ship the complete order even though he had my money for several weeks. We had communicated on a few different platforms. Each platform offered up a little piece of his identity. Last four of this. First four of that. It was enough to piece it all together. I gave him a call at his pla…

[flagged]

It's not like it's uncommon for folks to leverage employee discounts as arbitrage opportunities for a side hustle. Maybe it violates their terms of employment since they're competing with their employer, but it's not stolen goods.

Re: From email to phone number, a new OSINT approach (2019)

#84
post #55

Fun to see this issue get talked about. Ancedote- I bought some car parts from a semi-scammer. Not a full-on scam but the guy wouldn't ship the complete order even though he had my money for several weeks. We had communicated on a few different platforms. Each platform offered up a little piece of his identity. Last four of this. First four of that. It was enough to piece it all together. I gave him a call at his pla…

[flagged]

A more reasonable interpretation is that he was attempting to steal goods or time from the customer by dragging his feet on shipping; 'sorry, item is backordered' often results in the sale being lost, and salespeople are known for sometimes making promises to close deals, without regard to whether they can actually deliver.

Re: From email to phone number, a new OSINT approach (2019)

#85
I check GitHub's Trending page for Python projects every day or so. I was a little confused why this repo was trending today, particularly because the note at the top indicates that a lot of the services patched the exploit long ago.

It's interesting to see that this being posted here on Hacker News is presumably enough to push the GitHub repo to the trending page for Python.

Re: From email to phone number, a new OSINT approach (2019)

#86
post #62

Earlier quoted context omitted.

Why would a phone company know a person's SSN?!

So that they can seamlessly upsell you on upgrading to a new phone that you'll pay off in installments over the next couple years. Also, many postpaid plans (like my home ISP) require SSN because they are providing you service on credit. Postpaid cell paone plans have been the "default" in the US for a long time, though prepaid seems to be gaining market share.

We are kind of assuming a lot when a $100 a month account obviously requires a credit check.

They require a SSN because people don't care and it makes it cheaper to offer the accounts, not because it would actually be a big problem to sell internet service without credit checks.

Re: From email to phone number, a new OSINT approach (2019)

#88
post #48

Earlier quoted context omitted.

Last four of their SSN? That makes no sense, those digits are sequentially assigned at the issuing office.

Yes, last four. Don't ask me how I know.. Might be a "born on base" thing but it's no coincidence.

It's a coincidence.

http://web.archive.org/web/20070203124309rn_1/www.cpsr.org/p...

Re: From email to phone number, a new OSINT approach (2019)

#89

Earlier quoted context omitted.

Martin Vigo's article discusses the security vulnerabilities in password reset options for various websites and how these can lead to the exposure of personal phone numbers. Vigo highlights that during a password reset process, websites often partially reveal the user's phone number. This partial display varies across websites; some show the last four digits, others the first, and so on. By initiating password resets…

Awesome TLDR; Thx!

It's clearly AI generated, blatantly so.

Re: From email to phone number, a new OSINT approach (2019)

#90

One thing I've always wondered is how security researchers feel justified in releasing tools like the one in this blog post to the public. I can almost certainly say that the number of bad or creepy uses for an automated email to phone number generating tool massively outweighs the good reasons for having one. Does he get a pass because he's doing this for "research" and it's a grey area anyways? Does he feel better…

I agree, should've done responsible disclosure
Post reply on HN