Live data from Hacker News

Bruteforcing the phone number of any Google user

brutecat.com

31–40 of 204 posts

Re: Bruteforcing the phone number of any Google user

#33
post #27
post #24

Earlier quoted context omitted.

If it makes you feel better (it probably won't) hundreds/thousands of services have collected your phone number over the years (for 2FA or any other reason), with or without consent, and a large chunk of them have had data breaches. So your name-email-phone number combo is 100% already available in public data dumps.

If you have used Twitter or Facebook long enough while keeping the account, public your information is.

Thanks yoda

Re: Bruteforcing the phone number of any Google user

#35
post #5

Earlier quoted context omitted.

> It must be a daunting chore to maintain all the legacy pages. Clearly $350 billion revenue in 2024 is not enough...

In addition to having the money, Google also needs the incentive to spend that money on such projects. If the perceived return on capital is low (or negative!), the incentive is simply not there.

In addition to having the money, Google also needs the incentive to spend that money on such projects. If the perceived return on capital is low (or negative!), the incentive is simply not there.

Perhaps Google should Google the concepts of "customer service," "standing behind your product," and "brand reputation."

Re: Bruteforcing the phone number of any Google user

#36
post #24
post #8

> This time can also be significantly reduced through phone number hints from password reset flows in other services such as PayPal, which provide several more digits (ex. +14•••••1779) I've never thought about this but it's extra scary. If you have the same phone number and email address with enough services and they all mask in a different order for reset hints...

If it makes you feel better (it probably won't) hundreds/thousands of services have collected your phone number over the years (for 2FA or any other reason), with or without consent, and a large chunk of them have had data breaches. So your name-email-phone number combo is 100% already available in public data dumps.

not so long ago practically everyone's name and phone number was available publicly for free in any phone box

Re: Bruteforcing the phone number of any Google user

#37
post #27
post #24

Earlier quoted context omitted.

If it makes you feel better (it probably won't) hundreds/thousands of services have collected your phone number over the years (for 2FA or any other reason), with or without consent, and a large chunk of them have had data breaches. So your name-email-phone number combo is 100% already available in public data dumps.

If you have used Twitter or Facebook long enough while keeping the account, public your information is.

Or Yahoo, AT&T, T-Mobile, Equifax, Capital One, Chase, eBay, Home Depot, Marriott, most health networks...

Re: Bruteforcing the phone number of any Google user

#40
post #36
post #24

Earlier quoted context omitted.

If it makes you feel better (it probably won't) hundreds/thousands of services have collected your phone number over the years (for 2FA or any other reason), with or without consent, and a large chunk of them have had data breaches. So your name-email-phone number combo is 100% already available in public data dumps.

not so long ago practically everyone's name and phone number was available publicly for free in any phone box

Not to mention that these "phone books" also included everyone's address, and married couples were usually listed together.
Post reply on HN