Live data from Hacker News

533M Facebook users' phone numbers and personal data have been leaked online

businessinsider.com

461–470 of 524 posts

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#461
post #459

Earlier quoted context omitted.

The problem is completely the opposite. The flaw is the existence of social security numbers. Prohibit them from being used for anything but social security. Then there is no "your social security number" or "your identity" for someone to open a bank account against. You open a bank account and they give you a bank card and you set an address and phone number. The day you open it, they shouldn't need to know who you…

I stand by your SSN only for social security point. But the rest sounds plain wrong to me. Your phone might get stolen, your name might change due to marriage, your address might change because you moved/got evicted. What now?

Your phone gets stolen so you use your bank card and password to set a new phone number on your account. Your bank card gets stolen so you use your phone and password to get a new bank card.

If someone steals your phone and password and bank card and ability to receive mail at your home address all at once then you're pretty screwed, but you're pretty screwed then regardless, right? That's the level of screwed where somebody else can also get a government ID in your name.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#462
post #459

Earlier quoted context omitted.

I stand by your SSN only for social security point. But the rest sounds plain wrong to me. Your phone might get stolen, your name might change due to marriage, your address might change because you moved/got evicted. What now?

Your phone gets stolen so you use your bank card and password to set a new phone number on your account. Your bank card gets stolen so you use your phone and password to get a new bank card. If someone steals your phone and password and bank card and ability to receive mail at your home address all at once then you're pretty screwed, but you're pretty screwed then regardless, right? That's the level of screwed where…

Well, you did not mention a password before. With a password, you introduce a new 'security feature' which changes your argument in a non-trivial way.

This might work better than your proposal before.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#463

I mean, at this point I think everyone should just accept that at the very least their name, age, address(es), email(s), phone number(s) and screen name(s) have been fully leaked if you have ever had any kind of online presence. Not saying that's right or good, but at this point it's just a fact. So if that's the case, I think we should move beyond really even trying to think of this info as private or a marker of id…

> So if that's the case, I think we should move beyond really even trying to think of this info as private or a marker of identity, and we need to move everyone to more secure forms of identity verification.

Even if this info wouldn't be good enough to sign for official stuff it's still private and unique enough to target you though.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#464

I mean, at this point I think everyone should just accept that at the very least their name, age, address(es), email(s), phone number(s) and screen name(s) have been fully leaked if you have ever had any kind of online presence. Not saying that's right or good, but at this point it's just a fact. So if that's the case, I think we should move beyond really even trying to think of this info as private or a marker of id…

The problem is completely the opposite. The flaw is the existence of social security numbers. Prohibit them from being used for anything but social security. Then there is no "your social security number" or "your identity" for someone to open a bank account against. You open a bank account and they give you a bank card and you set an address and phone number. The day you open it, they shouldn't need to know who you…

Money-laundering rules make it illegal for banks not to know who the customer is. Also various anti-bribery and sanctions rules.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#465
post #395

Earlier quoted context omitted.

What you are proposing is that third-party apps should ask Facebook's app to find the friends, right? But Facebook's app needs to access Facebook's database somehow; and anyone can impersonate Facebook's app and query that database too.

Facebook’s phone app does not need to access the database. The whole thing could be implemented on the backend.

This is what I meant. Replace "database" with "backend" in my previous message and it still stands.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#466

I mean, at this point I think everyone should just accept that at the very least their name, age, address(es), email(s), phone number(s) and screen name(s) have been fully leaked if you have ever had any kind of online presence. Not saying that's right or good, but at this point it's just a fact. So if that's the case, I think we should move beyond really even trying to think of this info as private or a marker of id…

Well, I think at this point we can conclude that companies will not be good shepherds of our should-be-private data if we don't incentivize them to. Who'd have guessed?

I appreciate the pragmatic stance you take, and we should definitely move to more robust identification methods.

But making this case for better ID tech should IMHO not be confused with giving facebook and the others a pass. This should never have happened, and the very fact that we have a data trove this big is already a problem. That they don't seem to even attempt to protect that data is another one.

Close that shop up. The fines for this kind of stuff (and the other stunts they've pulled) should make it economically no longer viable to keep it open, really. The first time you fuck up this hard, the fines should hurt. This is not their first time.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#467

I mean, at this point I think everyone should just accept that at the very least their name, age, address(es), email(s), phone number(s) and screen name(s) have been fully leaked if you have ever had any kind of online presence. Not saying that's right or good, but at this point it's just a fact. So if that's the case, I think we should move beyond really even trying to think of this info as private or a marker of id…

Well, I think at this point we can conclude that companies will not be good shepherds of our should-be-private data if we don't incentivize them to. Who'd have guessed? I appreciate the pragmatic stance you take, and we should definitely move to more robust identification methods. But making this case for better ID tech should IMHO not be confused with giving facebook and the others a pass. This should never have hap…

Wont happen. All the politicians world over have been trained like Pavlovs dogs to chase Likes as a route to power. So its like asking addicts to not just give up their drugs but to take down the cartels.

The time to shutdown Facebook has past. Now we just have to suck it up and endure them and their effects like we do Cancer.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#468
post #467

Earlier quoted context omitted.

Well, I think at this point we can conclude that companies will not be good shepherds of our should-be-private data if we don't incentivize them to. Who'd have guessed? I appreciate the pragmatic stance you take, and we should definitely move to more robust identification methods. But making this case for better ID tech should IMHO not be confused with giving facebook and the others a pass. This should never have hap…

Wont happen. All the politicians world over have been trained like Pavlovs dogs to chase Likes as a route to power. So its like asking addicts to not just give up their drugs but to take down the cartels. The time to shutdown Facebook has past. Now we just have to suck it up and endure them and their effects like we do Cancer.

Again, I get the sentiment, but I disagree.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#469
post #457
post #353

Earlier quoted context omitted.

Absolutely, and e-mail or Paypal account name too. Neither of them are trivial to change. If you try to create a new account for each thing at a generic mail provider such as Gmail, your accounts will be shut down by automatic abuse filters. If you roll your own domain, then, well... the domain becomes the foreign key.

Would using a separate service email accounts help mitigate issues? seng-baking@gmail.com, then seng-banking+icici@gmail.com, seng-banking+axis@gmail.com, etc? That way my primary email would stay private and will used only for email, not for identity.

Your private email that you don't use for signing up anywhere is irrelevant except for phishing and spam. Your secondary email address will become the foreign key that is used to correlate the datasets from everywhere you signed up with it. The +tags can just be removed since it is known how they work. Might give you a small protection against attackers who don't know about email address tags.

Re: 533M Facebook users' phone numbers and personal data have been leaked online

#470

Earlier quoted context omitted.

Google has a huge number of activist (and surely some corruptible) employees, and yet the incidents of users data getting out are very close to zero. I think this demonstrates that user data can be managed safely and effectively. Usually the incidents reports on user data leaks show that the company seemed to barely be trying - We need laws that force them (even small companies) to put serious effort into it.

> Google has a huge number of activist (and surely some corruptible) employees, and yet the incidents of users data getting out are very close to zero Am I reading this wrong, or are you saying that activists would be more likely to leak data? Then I would wonder what kind of activists you have in mind. Agreed that yes indeed it seems possible to build a security serious company, and that Google is (seems to be) a go…

Surely they would. We already learned that members of their own security team don't seem to see any problems with employees abusing privileged access to mandatory Chrome extensions to agitate for unionisation (at Google of all places!!). Twitter employees screwed with the account of the president of the United States.

Ideological employees of big tech firms taking a sudden disliking to someone or some group and abusing privileged access is certainly a threat that ever larger numbers of people are talking seriously. In particular, it is a concern for industries that do things activists don't like, such as working with immigration control (though perhaps that's no longer an issue now Trump is gone).

Post reply on HN