Live data from Hacker News

Bruteforcing the phone number of any Google user

brutecat.com

51–60 of 204 posts

Re: Bruteforcing the phone number of any Google user

#51
post #41

Neat find, though it's funny to me that a phone number is something people (including everyone on this thread I bet) have been handing out like candy their entire adult lives - to friends, stores, banks, employers, government agencies, random websites – but still expect it to remain some critical secret that no one should ever find out. A phone number is about as private as your name, and you should consider it as su…

Uhh . . . this is not an earth-shattering take, considering they used to publish entire books with everyone's phone numbers and addresses in them, and you had to pay a fee not to have your number listed. Are we really to the point people don't understand the concept of a phone book anymore?

Back when phone books were a thing, you couldn't take over a phone number from the other side of the country in the middle of the night and use it to transfer funds to a foreign bank account before you even wake up.

Social security numbers were also never supposed to be secret but as their use changed over the years, so did the way people treat them.

Yes, phone numbers are leaked everywhere. So are social security numbers and home addresses. That doesn't mean your website should be leaking that information.

Re: Bruteforcing the phone number of any Google user

#52
post #40
post #36

Earlier quoted context omitted.

not so long ago practically everyone's name and phone number was available publicly for free in any phone box

Not to mention that these "phone books" also included everyone's address, and married couples were usually listed together.

Yeah, you could get an unlisted number but you were charged for it and almost no one did because it was also how people you wanted to get in touch with you found you a lot of the time. Not that data breaches aren't bad but a lot of the breached info has been pretty routinely available for a very long time. (And, as you say, cell phone numbers are probably less routinely available than landlines were.)

I don't go out of my way to publish my cell or address but a lot of people have them.

Re: Bruteforcing the phone number of any Google user

#53
post #21
post #4

It must be a daunting chore to maintain all the legacy pages. The amount of now-years-old stuff that long-standing sites have to maintain, or choose to maintain, is shockingly high, and testing the combination of all that stuff is impossible. If you want an example of how diverse in age these apps are, dig around in the Gmail settings panel. Eventually you will land on a popup that uses the original Gmail look and fe…

Which is exactly why companies are aggressive about deprecating old products and services. "But why can't they just leave them running and not touch it?" Because every such service eventually becomes a security hole. The only secure code is no code.

While your argument seems to make sense on the surface, it fails in deeper inspection.

What security implications did Google Reader have? I do understand keeping older APIs and endpoints for authentication and authorization are indeed dangerous. However, if your architecture causes the mere clients of those authorization infra to be exploited, I think the problem isn't keeping the products running. You designed something inherently insecure.

Re: Bruteforcing the phone number of any Google user

#54
post #15
post #10

Earlier quoted context omitted.

what’s the risk? your email being made public? your phone number?

Get personal info, then call carrier for a SIM swap, access crypto from there. Bonus: no KYC, since it's the other person's identity + you can login from 4G internet, so a trusted IP range.

What can be done to protect oneself from a SIM swap attack?

Re: Bruteforcing the phone number of any Google user

#55
post #5

Earlier quoted context omitted.

> It must be a daunting chore to maintain all the legacy pages. Clearly $350 billion revenue in 2024 is not enough...

Something that can be hard to appreciate if you haven't managed this sort of project is that it can be surprisingly hard to throw money at the problem. If you try to hire at your regular "bar" for skill for boring work like this - people will often quit. This is one of the reasons many company's integrations are lacking despite it being a strategic interest - integration work is miserable and doesn't help your career…

isnt exactly this why most of it ends up outsorced to consultants or third parties generally?

Re: Bruteforcing the phone number of any Google user

#56
post #50
post #8

> This time can also be significantly reduced through phone number hints from password reset flows in other services such as PayPal, which provide several more digits (ex. +14•••••1779) I've never thought about this but it's extra scary. If you have the same phone number and email address with enough services and they all mask in a different order for reset hints...

There's services that do this automatically for a price, and they've been around for a while, for e-mail, phone numbers, and much more. Any bits (literally, bits ) of information given without authorization (or plausible belief it's the intended user on the other side) will be efficiently put together from a variety of sources, as there's no shortage of incentive, and many all over the world prodding services used by…

There used to be deep web services that provided a lot of this stuff for free back in the early 2000s or so. I think everything like that is behind at least some level of paywall now but it's not hard to get a fairly complete dossier on someone given a bit of background information and a pretty small expenditure.

Re: Bruteforcing the phone number of any Google user

#57
post #36
post #24

Earlier quoted context omitted.

If it makes you feel better (it probably won't) hundreds/thousands of services have collected your phone number over the years (for 2FA or any other reason), with or without consent, and a large chunk of them have had data breaches. So your name-email-phone number combo is 100% already available in public data dumps.

not so long ago practically everyone's name and phone number was available publicly for free in any phone box

people always trot this out, but it was very possible to have your information unlisted so it was not printed in the book. you could also use a different name. an old coworker selected to have his name listed as David King so that when found in the book it would show up as King David.

having an unlisted number wasn't uncommon. for privacy minded people, it was a simple phone call to make it unlisted, and most just did it at time of getting the number.

Re: Bruteforcing the phone number of any Google user

#58
post #53
post #21

Earlier quoted context omitted.

Which is exactly why companies are aggressive about deprecating old products and services. "But why can't they just leave them running and not touch it?" Because every such service eventually becomes a security hole. The only secure code is no code.

While your argument seems to make sense on the surface, it fails in deeper inspection. What security implications did Google Reader have? I do understand keeping older APIs and endpoints for authentication and authorization are indeed dangerous. However, if your architecture causes the mere clients of those authorization infra to be exploited, I think the problem isn't keeping the products running. You designed somet…

If “what security implications does xyz have” was easy to answer then there would never be another hack or data breach. The simple answer is that we don’t know. And it is very expensive to find out.

Re: Bruteforcing the phone number of any Google user

#59

Earlier quoted context omitted.

It must be a daunting chore to maintain all the legacy pages. The amount of now-years-old stuff that long-standing sites have to maintain, or choose to maintain, is shockingly high, and testing the combination of all that stuff is impossible. One company I worked for used interns and new hires for that. One of the early tasks assigned to the intern pool was to comb the web sites for outdated information, or things th…

On the other hand they had no idea if the information was valid or wildly outdated. But better something than nothing I guess. :-)

This is where modern "learning" falls down. You load a page, read its contents, compare with what it is supposed to be, update if outdated, move on. I know I know, that sounds like, egad, work, but that's called a job.

Your immediate dismissal of an actual task I've been assigned irks to the point of being given a snarky response.

Re: Bruteforcing the phone number of any Google user

#60
post #15

Earlier quoted context omitted.

Get personal info, then call carrier for a SIM swap, access crypto from there. Bonus: no KYC, since it's the other person's identity + you can login from 4G internet, so a trusted IP range.

What can be done to protect oneself from a SIM swap attack?

Absolutely nothing whatsoever.

If SIM Swap doesn’t work, you can always attack SS7. There’s also nothing you can do about that.

So stop using your phone number as an authentication factor. It’s trivial to pwn for any actor determined-enough.

Post reply on HN