Live data from Hacker News

Facebook does not plan to notify half-billion users affected by data leak

reuters.com

111–120 of 315 posts

Re: Facebook does not plan to notify half-billion users affected by data leak

#111

Earlier quoted context omitted.

If Facebook has since deleted some of those accounts or associated phone numbers, they may no longer have a way to contact those users. The GDPR in Europe would require them to delete that data in a bunch of circumstances.

The beach has phone numbers and emails- why wouldn't they be able to contact those users with that information?

Facebook can't use the breach itself to contact users, no. The data could have been tampered with, and besides, Facebook doesn't have permission to process the leaked data in that way.

Re: Facebook does not plan to notify half-billion users affected by data leak

#112

"The Facebook spokesman said the social media company *was not confident it had full visibility on which users would need to be notified*." @Facebook here you go: https://haveibeenpwned.com

If Facebook has since deleted some of those accounts or associated phone numbers, they may no longer have a way to contact those users. The GDPR in Europe would require them to delete that data in a bunch of circumstances.

Can you clarify what you're talking about? I do not believe that GDPR regulations prevent Facebook from notifying their users about a data breach.

I mean, GDPR is a joke but that would be absolutely nonsensical.

Re: Facebook does not plan to notify half-billion users affected by data leak

#113

Isn't it just scraped public data? Calling it a leak for data that's public seems odd.

The data isn’t public. It’s based on the friend finding feature. If you fill a contact list with phone numbers Facebook will automatically suggest the person with that number as your friend. So if you make a contact list with all possible phone numbers, you can know who they belong to.

Re: Facebook does not plan to notify half-billion users affected by data leak

#114
My twitter account got flagged as suspicious even though I haven't used it during the past few months and have a long random password. Now they want my mobile number to "verify" me in addition to a captcha. It is ridiculous and ovcoiolsly tech companies can't be trusted with personal data of that caliber. I have never used my real name with that twitter account and now they want to know it all, why? Greed is my guess.

Re: Facebook does not plan to notify half-billion users affected by data leak

#116

I am surprised how the Facebook stock is pretty unaffected by all of this.

I own some of their stock and I keep buying more. Reason: FB is doing a great job with advertising and they are not just Facebook but also Instagram and other things.

Counterpoint: Facebook is taking your invested money and doing terrible things with it. Why fund that?

Re: Facebook does not plan to notify half-billion users affected by data leak

#117

Earlier quoted context omitted.

The beach has phone numbers and emails- why wouldn't they be able to contact those users with that information?

Facebook can't use the breach itself to contact users, no. The data could have been tampered with, and besides, Facebook doesn't have permission to process the leaked data in that way.

If they find a match against the leaked data, that would validate it and prove it had not been tampered with and at least allow them to contact a subset of users. Why can't they do that at least?

Re: Facebook does not plan to notify half-billion users affected by data leak

#118
post #87

For years companies have been steadily asking, mandating or even trickling users to give them their phone numbers under the excuse of security (while the real reasons were different), now what? How can they be trusted anymore? This also strikes a great point about the data sharing between Facebook and WhatsApp. Linking data between services augments the dangers and the consequences are not obvious to the end user. I…

>For years companies have been steadily asking, mandating or even trickling users to give them their phone numbers under the excuse of security (while the real reasons were different), now what? >How can they be trusted anymore?

I don't know if they can. I had specific conversations about things life preferring TOTP to phone in internship and job interviews, but I struggled to land the prestigious roles others did, though people I've spoken with informally certainly like to parrot key phrases I liked to use when we'd socialize at conferences.

Re: Facebook does not plan to notify half-billion users affected by data leak

#119

"The Facebook spokesman said the social media company *was not confident it had full visibility on which users would need to be notified*." @Facebook here you go: https://haveibeenpwned.com

If Facebook has since deleted some of those accounts or associated phone numbers, they may no longer have a way to contact those users. The GDPR in Europe would require them to delete that data in a bunch of circumstances.

> If Facebook has since deleted some of those accounts or associated phone numbers, they may no longer have a way to contact those users

That would totally defy logic.

I don't think that Facebook deletes anything ever.

Re: Facebook does not plan to notify half-billion users affected by data leak

#120
post #102

Earlier quoted context omitted.

Could someone elaborate on what the worst-case exploit would be for those number that got leaked? How would a scenario look like? Asking for a friend whose number got exposed...

My university is known to offer the option payment of tuition through a popular online system. This option is done by sending each student, at the start of the year, an SMS with a link to a payment option. Suppose you can get a list of people studying there, their names, and their phone-numbers. Faking this SMS and putting a payment that goes to you instead of uni would be a nice way to earn about 2000 euros per stud…

> My university is known to offer the option payment of tuition through a popular online system. This option is done by sending each student, at the start of the year, an SMS with a link to a payment option.

They don't email this information? They don't put it on an online notification system? I have no idea why SMS seems like the logical option for this.

Post reply on HN