Live data from Hacker News

Bruteforcing the phone number of any Google user

brutecat.com

101–110 of 204 posts

Re: Bruteforcing the phone number of any Google user

#101
post #65

Wow, if I needed any more proof Google is a ghost ship then this is it. The $5K bounty is an insult, and the fact that they low-balled it in the first place makes them look like absolute clowns. Good on you for calling out how little of a shit Google gives about actually protecting user data.

Nobody is forced to participate in a bug bounty. If you don't like the rewards, don't do it. There's a limit to the financial viability of these programs.

Who's talking about participation? We can be appalled by their business practices as their customers (actual or potential). These are the same companies that tell us that our privacy and security is their #1 concern, and use that justification to take away our rights "for our own good", but when there's a real threat they address it with with a business-casual equivalent of "fuck off".

Re: Bruteforcing the phone number of any Google user

#102
post #62

This article highlights something interesting... it is quite common to get at least one /64 IPv6 block from a hosting provider or ISP. Yet most of the rate-limiting and IP blocking is done for a single IP. Sounds like when dealing with IPv6, an entire block of /64 should be rate-limited or blocked.

I'd be rather surprised if IPv6 hasn't done some damage to the idea of IP blocking on the whole. It's possible, even as a residential Internet user, to request a /56 or /48 automatically with DHCPv6 Prefix Delegation. I have a /56 with Comcast. That's potentially up to 65536 /64 blocks, just from a residential user, so if you're going to attempt IP filtering for IPv6, it's got to be a lot smarter than swapping out your single-IP blocking for /64 blocking.

Re: Bruteforcing the phone number of any Google user

#103
post #91

Earlier quoted context omitted.

How does a new hire know "what it is supposed to be"?

The information is transferred through a method called "communication" by another human.

What is the point of assigning something to a new hire, if they can't do it without another person watching the whole thing over their shoulder AND they are unlikely to benefit from this knowledge in the future (since it's a legacy page that is supposed to be deleted)?

Re: Bruteforcing the phone number of any Google user

#104
post #5

Earlier quoted context omitted.

> It must be a daunting chore to maintain all the legacy pages. Clearly $350 billion revenue in 2024 is not enough...

Something that can be hard to appreciate if you haven't managed this sort of project is that it can be surprisingly hard to throw money at the problem. If you try to hire at your regular "bar" for skill for boring work like this - people will often quit. This is one of the reasons many company's integrations are lacking despite it being a strategic interest - integration work is miserable and doesn't help your career…

> pay out of band salaries, and legal tells you that opens you to massive liabilities

can you elaborate on this?

Re: Bruteforcing the phone number of any Google user

#105
post #62

This article highlights something interesting... it is quite common to get at least one /64 IPv6 block from a hosting provider or ISP. Yet most of the rate-limiting and IP blocking is done for a single IP. Sounds like when dealing with IPv6, an entire block of /64 should be rate-limited or blocked.

I'd be rather surprised if IPv6 hasn't done some damage to the idea of IP blocking on the whole. It's possible, even as a residential Internet user, to request a /56 or /48 automatically with DHCPv6 Prefix Delegation. I have a /56 with Comcast. That's potentially up to 65536 /64 blocks, just from a residential user, so if you're going to attempt IP filtering for IPv6, it's got to be a lot smarter than swapping out yo…

It is already pretty common to start with IP blocking but upgrade to blocks when the bad behavior continues.

Assuming a /64 as a starting point is an easy win and bumping it up with repeat offenders seems pretty easy in the grand scheme of things.

Re: Bruteforcing the phone number of any Google user

#106

Earlier quoted context omitted.

In addition to having the money, Google also needs the incentive to spend that money on such projects. If the perceived return on capital is low (or negative!), the incentive is simply not there.

In addition to having the money, Google also needs the incentive to spend that money on such projects. If the perceived return on capital is low (or negative!), the incentive is simply not there. Perhaps Google should Google the concepts of "customer service," "standing behind your product," and "brand reputation."

> Google the concepts of "customer service," "standing behind your product," and "brand reputation."

They're probably satisfied with their reputation with their customers, who are advertisers. The corporate IT folks who buy their G Suite products are also their customers, but overall the majority of the users of Google's software are not their customers, and Google cares about them the same way I care about how the gasoline in my car feels.

Re: Bruteforcing the phone number of any Google user

#107
post #5

Earlier quoted context omitted.

> It must be a daunting chore to maintain all the legacy pages. Clearly $350 billion revenue in 2024 is not enough...

Google's main search page is the slowest page & UI I have found on the internet today (not accounting for bandwidth limits). Even on modern devices it lags at text entry and even rearranges characters in the text box so you have to wait 10+ seconds for it to finish loading or it will go haywire. The shopping and other pages are actually worse. So it appears you're right, $350B isn't enough money to maintain a web pag…

don't forget how long the google.com redirect takes now if you dare to click a link on the SERP instead of just consuming their "AI Slop Overview" directly.

Re: Bruteforcing the phone number of any Google user

#108
post #91

Earlier quoted context omitted.

How does a new hire know "what it is supposed to be"?

The information is transferred through a method called "communication" by another human.

OP originally pitched the website clean up work providing a way to learn about the company, its products, history, etc.

If something is obvious, sure, but how is the new intern even going to know when to ask?

Re: Bruteforcing the phone number of any Google user

#109
post #91

Earlier quoted context omitted.

The information is transferred through a method called "communication" by another human.

What is the point of assigning something to a new hire, if they can't do it without another person watching the whole thing over their shoulder AND they are unlikely to benefit from this knowledge in the future (since it's a legacy page that is supposed to be deleted)?

Anytime a website is created, the information/text to used in the site is provided to the devs. You provide the same data to the QA team to ensure the Dev team did their job.

How are we seriously this obtuse? Is it deliberate?

Re: Bruteforcing the phone number of any Google user

#110
post #90
post #49

I did something similar way back when I was trying to find the phone number for a person, using Facebook. When recovering a password Facebook would give you most of the digits of the phone number, so I wrote them down in a vcard file and imported it on my phone to just look at the pictures. It worked surprisingly good.

This is why I don't use a real phone number with any of these services. They don't need my phone number to operate either.

g has been demanding a valid phone for years, as have most other major providers. if you lose the number you sign up with, you can potentially get locked out of the account. whats your mo?
Post reply on HN