Live data from Hacker News

From email to phone number, a new OSINT approach (2019)

martinvigo.com

111–120 of 127 posts

Re: From email to phone number, a new OSINT approach (2019)

#111
post #99

Earlier quoted context omitted.

I re-read this, not to fire back but to understand how you arrive at your conclusion. I think you are interpreting (or assuming maybe), from when I asked about his employer, that I suspected he stole the parts from his employer. That's not the case at all. I just needed a pressure point.

Didn’t you basically blackmail the guy?

Pressuring to follow up on a made deal does not really count as blackmail imo.

Re: From email to phone number, a new OSINT approach (2019)

#112
I use my real name as my email (as many of us do). And my phone number is publicly listed in many phonebooks. In Sweden it's standard practice for everyone to have their address and phone number searchable unless you opt out. Basically what used to be in the phone books in the 80s (which was everyone) just moved online in the 90s so now everyone's adress and phone number is publicly searchable. This can be really useful, but of course it can be used for evil as well.

But one of the really positive things about having so much "public PII" (SSNs, Addresses, phone numbers, birth days) is that people don't have to treat this information as some sort of secret. Everyone needs proper ID and eID because knowing someones digits doesn't make it any easier to impersonate them.

If someone wants my phone number, they take my email which has first- and last name, go to any of the N search sites and they find 100 people sharing my first and last name. If they know a city and approximate age (Which they can easily get from a social platform) they can narrow it down to just a couple of people. Public records then shows my birthdays, my cars, my income, who's also registered on the address, and so on. It's not difficult doing OSINT in Sweden...

Re: From email to phone number, a new OSINT approach (2019)

#113
post #64

Earlier quoted context omitted.

I know that iPhones with SIM+eSIM can have both active at the same time, and iPhones with just eSIM can have two eSIMs active.

Yeah I found this out the hard way when travelling recently. There are some great apps that let you buy cheap data-only eSIMs in dozens of countries. You can even buy an eSIM before you travel. It’s crazy convenient and much cheaper than roaming fees. My girlfriend could keep her home phone line enabled while using the eSIM but I couldn’t, even though we have the same model of phone! Turns out her home line uses a ph…

I’m currently traveling internationally with an iPhone 12 and I can confirm the single eSIM + single physical SIM limitation. Although, in my case, I'm using a physical international SIM and a US eSIM.

I would love to turn off my US eSIM when not in use (I think it uses more power connected to two cellular networks) but that would require unenrolling my US iMessage number and I can’t do that. Definitely the most annoying part of the whole thing.

I considered using a spare iPhone to host a physical SIM with my US number because that would allow the number to stay bonded with my Apple ID and potentially forward SMS over iCloud, but I decided not to because in my experience the SMS part is too flaky to be relied on.

Re: From email to phone number, a new OSINT approach (2019)

#114
post #64

Earlier quoted context omitted.

Yeah I found this out the hard way when travelling recently. There are some great apps that let you buy cheap data-only eSIMs in dozens of countries. You can even buy an eSIM before you travel. It’s crazy convenient and much cheaper than roaming fees. My girlfriend could keep her home phone line enabled while using the eSIM but I couldn’t, even though we have the same model of phone! Turns out her home line uses a ph…

Good news, with the elimination of the SIM card slot, they fixed this bug and you can have two eSIMs active with no chance of ever getting a physical travel sim to work! /s

Bleh physical sim swapping when travelling is such a pain. I used travel data only esims all through the US, Europe and Egypt. All set up through a single app. I didn’t need to talk to dodgy airport phone shop people a single time in 3 months on the road - which, iPhone limitations aside, I consider a massive win.

(I used the Airalo app. No association. It worked great.)

Re: From email to phone number, a new OSINT approach (2019)

#115
post #99

Earlier quoted context omitted.

I re-read this, not to fire back but to understand how you arrive at your conclusion. I think you are interpreting (or assuming maybe), from when I asked about his employer, that I suspected he stole the parts from his employer. That's not the case at all. I just needed a pressure point.

Didn’t you basically blackmail the guy?

From a legal standpoint blackmail requires the "receipt of money or valuable thing". Because the thing being received is an even exchange of goods already agreed to by both parties, and the threat on not receiving is not an illegal action in itself, it is not likely or plausibly blackmail.

-not a lawyer, just work with too many of them

Re: From email to phone number, a new OSINT approach (2019)

#116
post #62

Earlier quoted context omitted.

Why would a phone company know a person's SSN?!

> Why would a phone company know a person's SSN?! As Brit-expat+US-resident (since 2012) T-Mobile got my SSN when I signed-up for my pre-paid first mobile phone plan in 2012. Paying $50/mo was quite a shock when equivalent (or rather: far superior) service was available in the UK on a PAYG (not even pre-paid!) basis for £10/mo. ...and now I'm on a $110/mo postpaid plan because eventually you get tired of the limitati…

When visiting the USA I have often bought prepaid T-Mobile SIM cards for cash without showing any ID.

Re: From email to phone number, a new OSINT approach (2019)

#117
post #113
post #64

Earlier quoted context omitted.

Yeah I found this out the hard way when travelling recently. There are some great apps that let you buy cheap data-only eSIMs in dozens of countries. You can even buy an eSIM before you travel. It’s crazy convenient and much cheaper than roaming fees. My girlfriend could keep her home phone line enabled while using the eSIM but I couldn’t, even though we have the same model of phone! Turns out her home line uses a ph…

I’m currently traveling internationally with an iPhone 12 and I can confirm the single eSIM + single physical SIM limitation. Although, in my case, I'm using a physical international SIM and a US eSIM. I would love to turn off my US eSIM when not in use (I think it uses more power connected to two cellular networks) but that would require unenrolling my US iMessage number and I can’t do that. Definitely the most anno…

> but that would require unenrolling my US iMessage number

It nags you but you don't have to agree to remove the number. I routinely replace my SIM card when traveling outside the EU and my iMessage number still works for green-bubble people. I ignore/refuse the phone's occasional suggestions to "update" the number.

Re: From email to phone number, a new OSINT approach (2019)

#118

Earlier quoted context omitted.

Good news, with the elimination of the SIM card slot, they fixed this bug and you can have two eSIMs active with no chance of ever getting a physical travel sim to work! /s

Bleh physical sim swapping when travelling is such a pain. I used travel data only esims all through the US, Europe and Egypt. All set up through a single app. I didn’t need to talk to dodgy airport phone shop people a single time in 3 months on the road - which, iPhone limitations aside, I consider a massive win. (I used the Airalo app. No association. It worked great.)

For the five minutes it takes to get a physical SIM card, I'll take the much cheaper and typically faster service I get with local carriers vs eSIM MVNOs.

Re: From email to phone number, a new OSINT approach (2019)

#119

Earlier quoted context omitted.

Similarly to how Journalists feel justified in stories that have negative repercussions for some parties being reported upon. One way of assessing these decisions is answering the question "Is more harm done than good by releasing information this to the public?" From my perspective, I'm happy that Martin Vigo released this information (in 2019) as it helped me inform my employers (and now my clients) to additional t…

> Similarly to how Journalists feel justified in stories that have negative repercussions for some parties being reported upon. One way of assessing these decisions is answering the question "Is more harm done than good by releasing information this to the public?" That method leads to the worst evils in the world. Many have concluded, or used it to justify everything from, 'it's ok to take these poor people's land a…

I cannot follow your thread from a security researcher sharing tools to put pressure on an insecure website, to a megacorporation stealing someone's land.

Re: From email to phone number, a new OSINT approach (2019)

#120
post #5
post #3

This kind of uncoordinated leaking is a deeper problem. Many share the last four digits of a SS#. Okay. But often the first five are easy to guess from the birthday and the birth state. The first few digits tell the state where the number was issued.

Hell a lot of people have a last 4 digit that is literally just their mothers birth year.

Anyone alive today would be born between 1900 and 2023, right?

And their mothers, assuming they were between 13 and 50 when they gave birth, would therefore have been born between 1850 and 2010.

So that's 161 out of 9999 available last-4's (0000 is not used) that could possibly be someone's mother's birth year.

And then, of course, it has to be the right year within that space.

I am guessing this was something that happened to a few folks by chance and then was blown up by people who don't understand how many coincidences can occur across a population of millions.

Post reply on HN