Live data from Hacker News

Facebook does not plan to notify half-billion users affected by data leak

reuters.com

101–110 of 315 posts

Re: Facebook does not plan to notify half-billion users affected by data leak

#101
post #83

Earlier quoted context omitted.

Where does SMS get used to do payments? (...and how?) SMS for 2FA is known to be a very bad idea, and some security experts have been shouting about the need to stop doing that for a while. I also can't see any country managing to implement more restrictions on SMS without either breaking a lot of "legitimate" sources of SMS or being ineffective outside of a very narrow window (e.g. only blocking forged SMS for numbe…

"Where?!" Everywhere. It's being phased out in many places, but as a rule of thumb, mostly everywhere still. "known to be very bad ... been shouting ..." Right, yeah, to put it in some perspective remember that you're talking second factor here. This is not your login, this is a secondary confirmation and you still need some serious motivation to bypass it. It's definitely doable, I work in security and I know what k…

I'd never seen or heard of it being used for payments before, which is why I asked - I'd heard of phone numbers being used as account names (effectively) in some payment systems, but being involved in the workflow of making payments is entirely novel to me.

I'm aware it's not your login, but it feels the same as asking someone for publicly searchable information to "verify your identity" - an additional "security" step that doesn't actually slow down any attacker more dedicated than a passing whim, but makes people feel good about whoever is using it, when there are better options that don't have the problems of SMS.

Yes, it doesn't scale well to bulk attacking, but most of my interactions are with people who take reasonable precautions like keeping their machines patched, not installing random crap from the internet, and generally avoiding other fun ways people get swept up in low-hanging fruit campaigns.

SMS 2FA is better than no 2FA at all, it's just frustrating to watch many companies deploy it and go home when there are better options, some of which solely also require a phone.

edited to correct my statement: I originally said "SMS 2FA is better than no 2FA at all in a number of cases", but no, I'm pretty confident it's strictly better, even with all my laments about it.

Re: Facebook does not plan to notify half-billion users affected by data leak

#102
post #10

This huge leak has definitely killed the SMS text messaging service. Sender can be spoofed and spam/scam/phishing have reached an intolerable level. The fact that they can cross reference you and then produce a more personalized content is huge. Changing password is easy (ok less easy if you recycle it) but changing phone number is something that I am not even relaxed to do.

Could someone elaborate on what the worst-case exploit would be for those number that got leaked? How would a scenario look like? Asking for a friend whose number got exposed...

My university is known to offer the option payment of tuition through a popular online system. This option is done by sending each student, at the start of the year, an SMS with a link to a payment option.

Suppose you can get a list of people studying there, their names, and their phone-numbers. Faking this SMS and putting a payment that goes to you instead of uni would be a nice way to earn about 2000 euros per student who falls for it.

Re: Facebook does not plan to notify half-billion users affected by data leak

#103

"The Facebook spokesman said the social media company *was not confident it had full visibility on which users would need to be notified*." @Facebook here you go: https://haveibeenpwned.com

If Facebook has since deleted some of those accounts or associated phone numbers, they may no longer have a way to contact those users. The GDPR in Europe would require them to delete that data in a bunch of circumstances.

The beach has phone numbers and emails- why wouldn't they be able to contact those users with that information?

Re: Facebook does not plan to notify half-billion users affected by data leak

#104

The "real names" myth was the biggest scam played against people in the past 15 years. The media are also wholesale responsible for perpetuating that damaging trend. Historians of the future will look at the past 2 decades with disbelief.

Yeah, it’s fine to have some public facing content online, but the first thing a child used to learn before going online was to never use your real name and to never give out any personal information like your address and telephone number. At least that’s how it was where I grew up.

I remember when Facebook launched I had a visceral reaction after seeing all the content being shared out in the open. My dad didn’t even want our phone number in the phonebook, and now I saw everyone else sharing every detail of their identity online.

Re: Facebook does not plan to notify half-billion users affected by data leak

#105

The "real names" myth was the biggest scam played against people in the past 15 years. The media are also wholesale responsible for perpetuating that damaging trend. Historians of the future will look at the past 2 decades with disbelief.

Scam? That assumes deliberately misleading people for the scammer to benefit. Who exactly is benefiting from this?

While I don't agree that it's obvious even now that that using real names is damaging (i.e. makes things worse than anonymity/pseudonymity) the assumption that it's a scam goes 100% against Hanlon's razor.

It's pretty easy to claim that using real names online does more harm than good when pointing at a data leak but we should also consider the opportunity costs, the outcome of the alternative scenario. I'd say that all the fake and troll profiles show that anonymity makes people behave in a way that's damaging to online communication (and hence is a lot, maybe most communication is online these days, all communication). You can say that fake profiles are there anyway, which is true, but it still doesn't mean that everyone going anonymous wouldn't be a lot worse. So at best it's an undecided question as opposed to being a deliberate scam.

Re: Facebook does not plan to notify half-billion users affected by data leak

#106
post #87

For years companies have been steadily asking, mandating or even trickling users to give them their phone numbers under the excuse of security (while the real reasons were different), now what? How can they be trusted anymore? This also strikes a great point about the data sharing between Facebook and WhatsApp. Linking data between services augments the dangers and the consequences are not obvious to the end user. I…

Obligatory:

"People just submitted it. I don't know why. They 'trust me'. Dumb fucks." -Mark Zuckerberg

Re: Facebook does not plan to notify half-billion users affected by data leak

#107
post #87

For years companies have been steadily asking, mandating or even trickling users to give them their phone numbers under the excuse of security (while the real reasons were different), now what? How can they be trusted anymore? This also strikes a great point about the data sharing between Facebook and WhatsApp. Linking data between services augments the dangers and the consequences are not obvious to the end user. I…

>How can they be trusted anymore? They never could be.

zuckerberg's infamous "dumb f**ks" quote comes to mind.

Re: Facebook does not plan to notify half-billion users affected by data leak

#109
post #93

Earlier quoted context omitted.

> Sender can be spoofed Is this worldwide or US? I for now trust the senderid and assume them to be valid if they are coming from bank etc. I also haven't heard of anyone spoofing SMS. Should I be more cautious?

Never trust caller ID or senderid on phone calls or SMS. The reason is that phone companies interoperate grudgingly and do the minimum required to pass calls and messages between each other, and also most phone companies are 100+ year old companies who have just layered modern tech on top of their old stuff. They handle a massive unending stream of calls/messages and they can't possibly validate each one (even if the…

>they can't possibly validate each one //

Why not?

They don't pass on all metadata, that's part of the problem. If a call originates in $foreign_country, the sender gets to spoof it as a local call (sometimes they even use your own phone number). Are you really telling me there's no way to tell the difference between an off-shore call and a local one. It seems if this were true that billing is impossible, yet somehow the origin gets billed (though admittedly that might only be the immediate upstream, but usually this will be enough to disambiguate a scam call).

Phone companies make money from scammers. It doesn't seem to be a technical bar, rather a financial disinclination that stops phone companies from robust action.

Post reply on HN