Live data from Hacker News

Look Up Unknown Phone Numbers Using Facebook Reset Password

bytexd.com

1–10 of 140 posts

Re: Look Up Unknown Phone Numbers Using Facebook Reset Password

#4

This is gross violation of user privacy but if you file a bug with FB they will say - "won't fix" ; is working as intended.

Have they said that? They've previously removed the ability to search for users by phone number, so they recognise the problem.

I can see why someone would have unthinkingly added the profile picture to the recovery screen, but since the downside of resetting the wrong account is so low (an SMS that can be ignored by the rightful user), it seems easily fixable.

Re: Look Up Unknown Phone Numbers Using Facebook Reset Password

#6
post #5

This is gross violation of user privacy but if you file a bug with FB they will say - "won't fix" ; is working as intended.

Facebook profile stuff is public info anyway, I don't really see the privacy issue here.

Phone numbers that are meant for account recovery and/or two-factor security only are most definitely not public info.

Re: Look Up Unknown Phone Numbers Using Facebook Reset Password

#7
password reset flows are generally a privacy leak

if you use email as some kind of account key, you can generally find out whether that email has signed up (if not the username)

automatic password reset and email verification are good for businesses and users in a lot of ways so this is a tradeoff

if FB is showing the specific account linked to an SMS that's IMO negligent but shrug, they employ more lawyers than I do and they've never been investigated by the FTC for privacy issues

Re: Look Up Unknown Phone Numbers Using Facebook Reset Password

#10

password reset flows are generally a privacy leak if you use email as some kind of account key, you can generally find out whether that email has signed up (if not the username) automatic password reset and email verification are good for businesses and users in a lot of ways so this is a tradeoff if FB is showing the specific account linked to an SMS that's IMO negligent but shrug, they employ more lawyers than I do…

I’ve seen this obfuscated by some systems by always just throwing the user a message saying the reset email has been sent so that there’s no indication whether or not the email is associated with an account or not.

Of course, that doesn’t help someone who can’t remember if they’d signed up or not but it’s probably the safer way to go in general.

Post reply on HN