Live data from Hacker News

Bruteforcing the phone number of any Google user

brutecat.com

181–190 of 204 posts

Re: Bruteforcing the phone number of any Google user

#181
post #112

Earlier quoted context omitted.

> Since /64 is smallest network in IPv6 A /64 is not the smallest network in IPv6. Nothing stops you having a /112 or a /126 or whatever you like. It is the only network size on which SLAAC works however, so it's a good choice for lan sizes.

I'm talking practical. I know you can reduce networks further BUT there is plenty of stuff that could break.

GCP for example hands out /96s to each VM, so this isn’t a theoretical or niche usecase.

Re: Bruteforcing the phone number of any Google user

#182

Earlier quoted context omitted.

I'm talking practical. I know you can reduce networks further BUT there is plenty of stuff that could break.

GCP for example hands out /96s to each VM, so this isn’t a theoretical or niche usecase.

Yes, but for GCP all the VMs with a /96 in the same /64 will be closely related: in the same project, same VPC network, same cloud region.

So from the point of abuse logic it's appropriate to treat the whole /64 as a single unit. (That was the starting point of the thread, even though I realize that due to thread drift that's probably not what your comment was about.)

Re: Bruteforcing the phone number of any Google user

#183
post #36

Earlier quoted context omitted.

not so long ago practically everyone's name and phone number was available publicly for free in any phone box

people always trot this out, but it was very possible to have your information unlisted so it was not printed in the book. you could also use a different name. an old coworker selected to have his name listed as David King so that when found in the book it would show up as King David. having an unlisted number wasn't uncommon. for privacy minded people, it was a simple phone call to make it unlisted, and most just di…

nonetheless, pre-opting, your information was there, so anyone with a phonebook from before you made that decision would have your information. if an organisation had an interest in invading people's privacy it would not be complex to simply keep a copy of every edition of the phonebook

Re: Bruteforcing the phone number of any Google user

#184
post #62

This article highlights something interesting... it is quite common to get at least one /64 IPv6 block from a hosting provider or ISP. Yet most of the rate-limiting and IP blocking is done for a single IP. Sounds like when dealing with IPv6, an entire block of /64 should be rate-limited or blocked.

The problem here is, that also larger networks (eg. student wifi at some university) uses a /64 for maybe even hundreds of students connected at the same time. Hold a lecture, tell the students to go to github to download some tool, and the first 10 will succeed, and the rest will get rate limited.

The same is true now with NAT (where they're all behind a single ip or a very small pool of IPs), but IPv6 should make these things better.

Re: Bruteforcing the phone number of any Google user

#185
post #145

Earlier quoted context omitted.

They can just take your number anyway if you ever insert a SIM, since they control "your" phone.

Interestingly, your phone number is actually not stored on the SIM card. It instead holds a globally unique ICCID number which your operator links to your account (phone number) on their systems. This actually makes it possible to transfer your phone number between SIM cards or even operators, and means your cell phone is blissfully unaware of its own phone number.

It's surprisingly annoying if the phone is unaware, like mine!

Re: Bruteforcing the phone number of any Google user

#187
post #62

This article highlights something interesting... it is quite common to get at least one /64 IPv6 block from a hosting provider or ISP. Yet most of the rate-limiting and IP blocking is done for a single IP. Sounds like when dealing with IPv6, an entire block of /64 should be rate-limited or blocked.

I'm on a relatively large Indian ISP, and my home network gets an IPv6 network assigned, which is directly routable. Didn't think about it until tailscale told me it was connecting over a direct IPv6 connection and I wondered how that was possible. Sounds like 90s network rampage may be back here.

Direct connections are a good thing and how the Internet is supposed to work. NAT is the only reason IPv4 has lasted this long.

Re: Bruteforcing the phone number of any Google user

#188
post #4

It must be a daunting chore to maintain all the legacy pages. The amount of now-years-old stuff that long-standing sites have to maintain, or choose to maintain, is shockingly high, and testing the combination of all that stuff is impossible. If you want an example of how diverse in age these apps are, dig around in the Gmail settings panel. Eventually you will land on a popup that uses the original Gmail look and fe…

Bug bounty program appears to be an efficient spend. For a few thousand dollars they mobilize unpaid people looking for extreme edge cases and then surface these issues. It would’ve cost way more to pay an employee to search for this.

The main cost of running a bug bounty program is developer time spent triaging submissions from all the people who just run an automated scanner against your website and submit everything it outputs.

Re: Bruteforcing the phone number of any Google user

#189
post #85

Earlier quoted context omitted.

Google's main search page is the slowest page & UI I have found on the internet today (not accounting for bandwidth limits). Even on modern devices it lags at text entry and even rearranges characters in the text box so you have to wait 10+ seconds for it to finish loading or it will go haywire. The shopping and other pages are actually worse. So it appears you're right, $350B isn't enough money to maintain a web pag…

There is something wrong with your computer.

1) it happens on both an Android smartphone and a Linux computer 2) it only happens with Google 3) it is consistent and reproducible

Re: Bruteforcing the phone number of any Google user

#190
post #40
post #36

Earlier quoted context omitted.

not so long ago practically everyone's name and phone number was available publicly for free in any phone box

Not to mention that these "phone books" also included everyone's address, and married couples were usually listed together.

My old man was a doctor and the local phone company at the time (GTE) automatically made our home number unlisted. Presumably this was done for other “critical” professions who might receive many home calls that should be directed at their place of work.

Being unlisted was sometimes devastating to a 1980s kid’s social life… I missed out on multiple birthday parties and other invitations. My sisters probably lost out on some dating opportunities.

Post reply on HN