Live data from Hacker News

From email to phone number, a new OSINT approach (2019)

martinvigo.com

121–127 of 127 posts

Re: From email to phone number, a new OSINT approach (2019)

#121

Earlier quoted context omitted.

> Similarly to how Journalists feel justified in stories that have negative repercussions for some parties being reported upon. One way of assessing these decisions is answering the question "Is more harm done than good by releasing information this to the public?" That method leads to the worst evils in the world. Many have concluded, or used it to justify everything from, 'it's ok to take these poor people's land a…

I cannot follow your thread from a security researcher sharing tools to put pressure on an insecure website, to a megacorporation stealing someone's land.

I'm talking generally about this reasoning, whether used by security researchers or governments condemning land for megacorps (or anyone else):

>>> One way of assessing these decisions is answering the question "Is more harm done than good by releasing information this to the public?"

Re: From email to phone number, a new OSINT approach (2019)

#122

Fun to see this issue get talked about. Ancedote- I bought some car parts from a semi-scammer. Not a full-on scam but the guy wouldn't ship the complete order even though he had my money for several weeks. We had communicated on a few different platforms. Each platform offered up a little piece of his identity. Last four of this. First four of that. It was enough to piece it all together. I gave him a call at his pla…

I re-read this, not to fire back but to understand how you arrive at your conclusion. I think you are interpreting (or assuming maybe), from when I asked about his employer, that I suspected he stole the parts from his employer. That's not the case at all. I just needed a pressure point.

Why are you replying to yourself and staging arguments? This is just...confusing.

Re: From email to phone number, a new OSINT approach (2019)

#123
post #59

Earlier quoted context omitted.

Why is this not tied to a person's SSN (if possible)?

Is there an accessible database somewhere that would allow T-Mobile to get a name from an SSN (or verify that an SSN and a name match)?

Yes, by running a credit check through one of the credit bureaus.

Re: From email to phone number, a new OSINT approach (2019)

#124
post #4

lol > Paypal, which displays five digits including area code to anyone knowing the email address (but only three if the attacker knows the target’s password), decided this is working as designed and will not take action. Wild. Does anyone know how scammers are getting numbers off of LinkedIn? Or correlating them to numbers from elsewhere? I know a company whose employees are constantly getting fake CEO texts.

"Does anyone know how scammers are getting numbers off of LinkedIn?"

They probably have their phone number visible on their profile or they have an email and the scammer found the number on another platform (like facebook)

Re: From email to phone number, a new OSINT approach (2019)

#126

> If it is a requirement, consider using a virtual number like Google Voice or even a dedicated SIM that you only use for this purpose and never give the number away. For the second SIM option, that requires a dual-SIM device, which are still fairly niche in the US. When it comes to VOIP numbers, unfortunately, many sites look up phone numbers and block VOIP providers, which sucks because Android still has no good wa…

If you're a Linux user, "KDE Connect" is actually by far the best desktop interface for texting and more. It's changed how my phone and my laptop interact and I think might be my favorite open source project. You can use your laptop as a keyboard, reply to messages from any app that sends a notification, and so much more. The file sending functionality is also far better (and faster) than anything else I've used. It'…

A bit late but I had completely forgotten about KDE Connect. Back when I last tried it, it did not filter out spam messages (though maybe Google Messages' spam filtering operates on its own layer and thus spam classifications are not reflected back in the OS SMS store, making it impossible for KDE Connect to know about them). Regardless, I get much less SMS spam these days, so maybe that'll be a viable option once more.

Re: From email to phone number, a new OSINT approach (2019)

#127

Keeping a phone number secret is "security by obscurity" and therefore the whole point of this article is rather moot.

Not completely, when you have the email + the phone number, you can make much more sophisticated phishing attempts

That doesn't change the fact that these are not "secrets" (except by accident) and that their current secrecy-by-coincidence therefore should not be relied upon
Post reply on HN