Live data from Hacker News

Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

privacyaffairs.com

141–150 of 160 posts

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#141
post #84

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

> more sensitive personal information (like social security numbers or other government ID numbers) I tend to think that there should be a publicly accessible, unique, and more or less immutable ID number for every citizen or resident. This ID would have pointers to our name, birth date and a few other identifiers that shouldn't really be considered secret. My concern is that the absence of such a unique ID leads to…

And why exactly would everyone being easier to track be helpful to the actual people themselves? I don't want Facebook to have that information. I'm even less interested in some random small business having it.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#142
post #26

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

> everything I used to be able to get in a phone book Fair, although you could opt out of the phone book. (And I don't think they had location/address, though it's been so long now that I can't remember for sure.) > I think people are grappling with the fact that the Internet just makes data scraping and processing possible on a scale previously unimaginable This is it right here. The scale and ease of access are ter…

> you could opt out of the phone book.

Which cost money! Being listed was gratis.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#143
post #26

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

> everything I used to be able to get in a phone book Fair, although you could opt out of the phone book. (And I don't think they had location/address, though it's been so long now that I can't remember for sure.) > I think people are grappling with the fact that the Internet just makes data scraping and processing possible on a scale previously unimaginable This is it right here. The scale and ease of access are ter…

They did have one's address in the phone book. Now, you had to have a decent city map, and some sense of the city numbering scheme to know where that address was.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#144

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

> we need to start differentiating between

No, we don't. PII is PII.

These large scale breaches harm everyone's privacy (anonymity). Even people who are not included. Because with enough data you can deanon people, eg thru process of elimination.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#145
post #84

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

> more sensitive personal information (like social security numbers or other government ID numbers) I tend to think that there should be a publicly accessible, unique, and more or less immutable ID number for every citizen or resident. This ID would have pointers to our name, birth date and a few other identifiers that shouldn't really be considered secret. My concern is that the absence of such a unique ID leads to…

Agree on importance of correlating records across heterogenous systems.

AND:

All PII field level data must be encrypted at rest.

UUIDs unlock both the record linking and privacy achievements.

The book Translucent Databases shows how. Hide sensitive data with salt + hash, just like with proper password files. Use UUIDs as opaque pointers for linking.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#146
post #130

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

Wait until HN readers find out what these faceless companies that appear around election time and mail me junk are able to gleam from public voting registration data.

Don't forget LexisNexis.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#147

I honestly ask myself how the f Zuck has the guts and ego to still talk about a "metaverse" with a company and product so wrong, so poisonous and evil to humanity. I really can't wait to see him in jail already.

I'm not a big fan of Facebook but the hatred toward that company here is getting out of hand. You want to see Zuck in jail for what crime exactly? How is Twitter, Youtube, TikTok or Reddit any better than Facebook when it comes to being "poisonous" or "evil"? Youtube was literally financing terrorist groups with ad money 10 years ago. Twitter gives a platform to anti-Semites and the Taliban.

FB is inherently evil and must be stopped at all costs. And your last part about giving those two groups a platform: so fucking what? Those groups are much more prestigious than our 'leaders'.

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#148

Some might laugh this off as 'oh it's just scraping'. But I remember reading some comments in HN that there are apps that can scan faces and pull personal info including where they live, work etc. So each leak uncovers a person little by little. This vindicates the stance taken by Signal to not even collect metadata. Edit: I mean surreptitiously scan the face of a stranger you see in public and the app will tell you…

https://pimeyes.com does just that, I just posted it here on HN.

I always want to know what a service like that has found, but I'm also pretty unwilling to upload an image of me to it, given that there's not a lot of public images of me out there that I'm aware of. Then again, maybe if I did check I'd see a bunch of images where I was tagged by other people and that would disabuse me of the notion that images of me online are rare at all...

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#149
post #51

Earlier quoted context omitted.

> And I don't think they had location/address, > though it's been so long now that I can't remember for sure Same here. initially i too couldn't remember for sure. Then i remembered the scene from Terminator 2 (1991) in which it looks up Sarah Connor's phone-number and home-address in a phone-book! :-)

I believe the LGR channel has shown some DOS programs from before 1990 that had the entire catalogue of the US phonebook available in a neat DOS UI, where you just choose a location/state (or non at all) then enter a letter and it would filter every entry on the chosen filter... (Name was ProPhone 1993, so not really pre 90's) https://youtu.be/yBupNdYe08g?t=1078

I think we actually had that, bought on a whim by my Dad at a computer show in the 90's. We had some fun looking up how many people with certain first/last names were in the US, but didn't have much other use for it.

And funnily enough, family members of mine have started multiple businesses named A-1 something. :)

Re: Web Scrapers Claim to Sell Personal Data on Facebook Users on a Hacker Forum

#150
post #11

I feel like we need to start differentiating between "public" personal information and more sensitive personal information (like social security numbers or other government ID numbers). The breach lists this info: Name Email Location Gender Phone number User ID So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because i…

> So basically, everything I used to be able to get in a phone book. Honestly, at this point all of that information should just be considered public, because it obviously is. With a phonebook (at least back in the day), you didn't risk having your account exposed and sold for a few dollars. Nor did that risk someone getting access to thousands, if not more, bank accounts or whatever through automation. In addition,…

Social engineering did not begin with computers, that's just when we put a fancy name on it. Personal information has been used to impersonate people in person or over the phone for a very long time.
Post reply on HN