Live data from Hacker News

Bruteforcing the phone number of any Google user

brutecat.com

111–120 of 204 posts

Re: Bruteforcing the phone number of any Google user

#111
post #41

Neat find, though it's funny to me that a phone number is something people (including everyone on this thread I bet) have been handing out like candy their entire adult lives - to friends, stores, banks, employers, government agencies, random websites – but still expect it to remain some critical secret that no one should ever find out. A phone number is about as private as your name, and you should consider it as su…

Uhh . . . this is not an earth-shattering take, considering they used to publish entire books with everyone's phone numbers and addresses in them, and you had to pay a fee not to have your number listed. Are we really to the point people don't understand the concept of a phone book anymore?

Do I give it out? Not so much.

Do I expect it to be private? No.

You can for a small fee on some websites get my number.

Heck if you find a phone book from ~2000 where I use to live then you could just look it up in the phone book. Number portability saw to that.

Considering the number of data breaches and past history of phone numbers. To expect any sort of privacy is 'nice to have' but not going to happen. At this point it is basically security thru obscurity to expect it to be private.

Even when they had 'unlisted' numbers you could buy a book from the phone company that had it in there anyway. They even had reverse phone books you could buy. I even remember CD's from ~1998 that had the whole country. You didn't even need to keep the books.

Re: Bruteforcing the phone number of any Google user

#112

Earlier quoted context omitted.

What if the user only get one address, how to separate the two? Seems like a need to share if a larger block (providor) is handing out based on blocks or single addresses…

Say what? IPv6 was designed that first 64 bits are network, last 64 bit are host. Since /64 is smallest network in IPv6 and because of that most providers hand out /64 when you ask for IPv6 public address because A) Most Rate Limiting uses /64 and B) IPv6 has so many IPs, no one cares. Vultr has at least one /32 I was able to find (2001:19F0::/32) which if you cut that into /64 comes out ~4.2 Billion different networ…

> Since /64 is smallest network in IPv6

A /64 is not the smallest network in IPv6. Nothing stops you having a /112 or a /126 or whatever you like.

It is the only network size on which SLAAC works however, so it's a good choice for lan sizes.

Re: Bruteforcing the phone number of any Google user

#113
post #64

Earlier quoted context omitted.

No it isn't. You give it to people you trust mostly you don't expect them to make it available publicly on the Internet.

You really trust that not a single friend of yours has ever clicked the "share contacts" button after downloading Facebook/Instagram/Snapchat/LinkedIn/TikTok...? You trust that your auto dealer or bank has not shared your details with Experian (even though you signed a piece of paper explicitly authorizing that)? You trust that your mobile operator itself isn't sharing your contact data with advertisers (go back and…

I feel like both sides are right here:

1. Google shouldn't make it trivial to find out my phone number from my email. Given that even Google itself, despite having better technology available, still allows the dumpster that is SMS verification to be used as an auth "factor," they should not be enabling SIM-swapping so directly. Just knowing someone's number makes it trivial to social engineer a SIM-swap, and that can likely unlock every account most people have, and a lot of important accounts (like banks) even for security-minded people, since banks love SMS and hate everything else.

2. I shouldn't act like my phone number is a well-protected secret, or trust that anyone who calls or texts me has gotten it from a trusted source.

Re: Bruteforcing the phone number of any Google user

#114
post #90

Earlier quoted context omitted.

This is why I don't use a real phone number with any of these services. They don't need my phone number to operate either.

g has been demanding a valid phone for years, as have most other major providers. if you lose the number you sign up with, you can potentially get locked out of the account. whats your mo?

Not sure how it looks in USA, but in EU you can get a prepaid SIM card for $2 and use it forever for cases like this. You'll probably have to top it up with another $1-2 if used sparingly, but that's the price of such separation.

Re: Bruteforcing the phone number of any Google user

#115
post #91

Earlier quoted context omitted.

The information is transferred through a method called "communication" by another human.

What is the point of assigning something to a new hire, if they can't do it without another person watching the whole thing over their shoulder AND they are unlikely to benefit from this knowledge in the future (since it's a legacy page that is supposed to be deleted)?

I often assign things to new hires because I expect them to approach the question without the biases of long-time team members who have learned to overlook and normalize some bullshit. Either the new person is wrong, and I explain why, and they learned something, or they're right and the existing stuff can't be defended or justified, and I learned something.

Re: Bruteforcing the phone number of any Google user

#116

> 2025-05-15 - Panel awards $1,337 + swag. Rationale: Exploitation likelihood is low. (lol) Oh, so this is how vendors are going to start playing it to minimize bug bounty costs, huh? Good luck with that- the whole point of the award being a decent chunk of change is to make responsible disclosure more appealing to researchers who might otherwise go the other direction.

I run the BBP at work and we have gotten great reports from it that I'm really glad we didn't find out the "bad" way.

But I kind of think that, instead of any person or group of people choosing between "submit to a BBP" or "sell a 0-day to evil state actors or dark web clients" a BBP is better seen as allowing you to employ stunningly smart and ethical researchers in India (where a $2k bounty goes pretty far) to find all your vulns ASAP so that you have way fewer vulns for the actual bad guys to find. A pretty good "High" vuln is so valuable to people like CIA, FSB, Mossad, etc, not to mention terrorists, money launderers, etc. that it would be hard to compete with those guys financially if we were dealing with strictly economically rational but amoral researchers.

We've paid thousands to a couple of the same researchers, and it's money well spent.

Re: Bruteforcing the phone number of any Google user

#117
post #15

Earlier quoted context omitted.

Get personal info, then call carrier for a SIM swap, access crypto from there. Bonus: no KYC, since it's the other person's identity + you can login from 4G internet, so a trusted IP range.

What can be done to protect oneself from a SIM swap attack?

[deleted]

Re: Bruteforcing the phone number of any Google user

#118
post #104

Earlier quoted context omitted.

Something that can be hard to appreciate if you haven't managed this sort of project is that it can be surprisingly hard to throw money at the problem. If you try to hire at your regular "bar" for skill for boring work like this - people will often quit. This is one of the reasons many company's integrations are lacking despite it being a strategic interest - integration work is miserable and doesn't help your career…

> pay out of band salaries, and legal tells you that opens you to massive liabilities can you elaborate on this?

In my country, there is already a (little known and not really enforced) law, that says, that for similar work there has to be a similar pay (simplifying massively). There is possibly a bunch of workarounds for this (as usual), but a good HR will not like the idea of hiring another SWE, with the same title as other SWEs, but with 2x pay.

Re: Bruteforcing the phone number of any Google user

#119
post #87
post #68

Earlier quoted context omitted.

> Eventually you will land on a popup that uses the original Gmail look and feel, from 2004. Indeed, I recently ran into a Google page that served up the old (~2013) Catull logo.

I was recently editing the Wikipedia page for Google Bookmarks (2005-2021). I wanted to add a logo to the page, but I was having a lot of trouble finding a high-quality copy of the logo anywhere. Eventually I figured out that Google's old URL scheme for product logos was very guessable, and they had never taken it down: https://www.google.com/intl/en-US/images/logos/bookmarks_log... They'll probably never stop servin…

That's good! Cool URLs never die. I thought they would be able to do a more effective search of their codebase to find references to their old logo in their own code.

Re: Bruteforcing the phone number of any Google user

#120
post #41

Neat find, though it's funny to me that a phone number is something people (including everyone on this thread I bet) have been handing out like candy their entire adult lives - to friends, stores, banks, employers, government agencies, random websites – but still expect it to remain some critical secret that no one should ever find out. A phone number is about as private as your name, and you should consider it as su…

> A phone number is about as private as your name

Your name should also be somewhat private. No need to use your real name on the internet. There was a furor over Google requiring real names on Google+; this kind of outcry needs to continue.

Post reply on HN