Live data from Hacker News

Facebook does not plan to notify half-billion users affected by data leak

reuters.com

121–130 of 315 posts

Re: Facebook does not plan to notify half-billion users affected by data leak

#121
post #93

Earlier quoted context omitted.

> Sender can be spoofed Is this worldwide or US? I for now trust the senderid and assume them to be valid if they are coming from bank etc. I also haven't heard of anyone spoofing SMS. Should I be more cautious?

Never trust caller ID or senderid on phone calls or SMS. The reason is that phone companies interoperate grudgingly and do the minimum required to pass calls and messages between each other, and also most phone companies are 100+ year old companies who have just layered modern tech on top of their old stuff. They handle a massive unending stream of calls/messages and they can't possibly validate each one (even if the…

We have STIR/SHAKEN but the phone companies are dragging their feet on implementing it.

Re: Facebook does not plan to notify half-billion users affected by data leak

#122
post #66
post #22

Why notifiy? Victims got notified everyday with many spam-sms. Thanks Facebook!

Because I would really like to know if I'm affected. According to "Have I Been Pwned" my phone number is not in the list, but about one or two weeks ago I noticed that my spam folder was unusually full, which led me to believe that something new must have happened. Shortly thereafter Facebook's leak hit the news. From my point of view it is their obligation to notify all the affected users. It's morally the right thi…

The leak did not include email addresses, so your email spam issue is unrelated.

Re: Facebook does not plan to notify half-billion users affected by data leak

#123
post #39

Earlier quoted context omitted.

Any idea on the extra security measures? In Turkey for example, when you change your SIM card the 2FA from the banks will stop working and you need to call your bank to re-activate it. That of course seems like a measure to prevent SIM cloning but maybe there are some security protections against spoofing. In many places SMS is a popular way to do payments and 2FA for high security applications.

Where does SMS get used to do payments? (...and how?) SMS for 2FA is known to be a very bad idea, and some security experts have been shouting about the need to stop doing that for a while. I also can't see any country managing to implement more restrictions on SMS without either breaking a lot of "legitimate" sources of SMS or being ineffective outside of a very narrow window (e.g. only blocking forged SMS for numbe…

> Where does SMS get used to do payments? (...and how?)

Look up M-Pesa[1]. Which is a hugely successful, mobile phone based payment system in multiple countries.

In Kenya alone, where it started, it had 17Million subscribers. In 2011, that was.

[1] https://en.wikipedia.org/wiki/M-Pesa

Re: Facebook does not plan to notify half-billion users affected by data leak

#124
post #4

It's from 2019 is the stupid excuse they have. The amount of laxity they have shown in this matter is appalling!!

If you change your DoB every year like I do, you'll be fine...

The leak didn't include DoB.

Re: Facebook does not plan to notify half-billion users affected by data leak

#126
post #96

I suppose a well meaning spammer could just SMS everyone pretending to be Facebook.

Let me just drop a note here that I happen to have two "unlimited" SMS subscriptions (i.e. could at least notify a few thousand people) in different European countries and that contact info is in my profile in case anyone has... ideas... :-)

[deleted]

Re: Facebook does not plan to notify half-billion users affected by data leak

#127

"The Facebook spokesman said the social media company *was not confident it had full visibility on which users would need to be notified*." @Facebook here you go: https://haveibeenpwned.com

If Facebook has since deleted some of those accounts or associated phone numbers, they may no longer have a way to contact those users. The GDPR in Europe would require them to delete that data in a bunch of circumstances.

Because they might have deleted some of the accounts they no longer have an obligation to notify the rest that they haven't deleted?

Re: Facebook does not plan to notify half-billion users affected by data leak

#128
post #66

Earlier quoted context omitted.

Because I would really like to know if I'm affected. According to "Have I Been Pwned" my phone number is not in the list, but about one or two weeks ago I noticed that my spam folder was unusually full, which led me to believe that something new must have happened. Shortly thereafter Facebook's leak hit the news. From my point of view it is their obligation to notify all the affected users. It's morally the right thi…

The leak did not include email addresses, so your email spam issue is unrelated.

It did include email addresses in some cases, just not all of them.

Re: Facebook does not plan to notify half-billion users affected by data leak

#129
post #87

For years companies have been steadily asking, mandating or even trickling users to give them their phone numbers under the excuse of security (while the real reasons were different), now what? How can they be trusted anymore? This also strikes a great point about the data sharing between Facebook and WhatsApp. Linking data between services augments the dangers and the consequences are not obvious to the end user. I…

Certainly I cannot be the only one who finds phone numbers, email addresses, and many other things quite inconsequential compared to name and address.

In particular, there could easily be a postal system implemented where the sender would not need the actual physical address of the receiver. The receiver could easily ask the postal service to generate an arbitrary key which could either be single use, or multiple use, in order to deliver, so that one could receive mail and packages without having to surrender information regarding one's place of residence to the sending party.

Recently, I was hand delivered something from my sports club at my address as an apology for COVID. All quite considerable but I'm not so comfortable with that apparently my physical address is known to arbitrary members of said club, and that I was required to give it in order to sign up, which is necessary with modern technology.

There is no theoretical need to surrender one's physical address to join a sports club in theory, but physical addresses are exchanged everywhere as though there be no problem with this. They are of course the easiest way to stalk and harm someone.

Post reply on HN