Live data from Hacker News

A database of Facebook users’ phone numbers found online

techcrunch.com

61–70 of 177 posts

Re: A database of Facebook users’ phone numbers found online

#61
post #45
post #25

Heads up: when Facebook asks you to give them your phone number to "prevent you getting locked out of your account", they really just want it so they can identify your other profiles in datasets they've bought/own (e.g. WhatsApp). If you've ever given the service your number, you should consider your real identity linked to it.

> If you've ever given the service your number, you should consider your real identity linked to it. I have a feeling it's worse than that. (I haven't rigorously perused the ToS, if I'm wrong please lmk.) Let's say your friend John has an iPhone and saves your name and # in their contacts. One day John installs the Facebook app & opens it. John is not technical and when the app requests permissions he taps 'Allow'. A…

This is the entire business model of TrueCaller, and the reason they have a very accurate phone nbr lookup function

Re: A database of Facebook users’ phone numbers found online

#62

Earlier quoted context omitted.

How many people change their phone numbers more than once a decade? How many people change their facebook accounts ever? The age of this data may be "old" by whatever definition Facebook is using, but it is still of great interest to identity thieves and ne'er-do-wells.

Yep. As far as I’m accustomed most people do whatever they can to maintain their phone numbers even across services. So much so that it’s law in Canada a provider can’t lock in your number and must let you take it with you to another provider.

Good to know it's a law. I was discussing this yesterday as being easy and frequent to port over number between providers. Do you know if providers are allowed to charge a fee for the transfer?

Re: A database of Facebook users’ phone numbers found online

#63
post #55

Earlier quoted context omitted.

Real security is picking a unique password and not forgetting it. Letting someone handle your security by giving them your phone number in case you can't handle it was never a good idea. Get a password safe, and don't forget your complex passwords.

2FA (through an third-party like an email provider or, even, dare I say it, an SMS provider; not TOTP) continues to protect you when your password is compromised by a backend-side database breach. They might get your password; they might get your TOTP token seed; but there's nothing in the DB that will allow them to receive an email as you and then click the link in said email. Yes, allowing someone to reset their pa…

This is a good distinction and absolutely right. The problem comes when people substitute good passwords for 2fa resets via phone. The problem with that is that the majority of usage now comes from the phone, so it's not really a second factor if you lose your phone. It's a complex problem that depends on the situation and really too complex to make a matrix of when it's ok for your average Joe. Passwords suck, and we still use them, because as a general rule, it's the best thing we have.

Re: A database of Facebook users’ phone numbers found online

#65
post #45
post #25

Heads up: when Facebook asks you to give them your phone number to "prevent you getting locked out of your account", they really just want it so they can identify your other profiles in datasets they've bought/own (e.g. WhatsApp). If you've ever given the service your number, you should consider your real identity linked to it.

> If you've ever given the service your number, you should consider your real identity linked to it. I have a feeling it's worse than that. (I haven't rigorously perused the ToS, if I'm wrong please lmk.) Let's say your friend John has an iPhone and saves your name and # in their contacts. One day John installs the Facebook app & opens it. John is not technical and when the app requests permissions he taps 'Allow'. A…

You're exactly right. Add in the fact that Facebook can pose this as a puzzle to be solved, and attract a steady stream of sharp young people who can solve the puzzle without being bothered too much by the ethical consequences of solving the puzzle.

Re: A database of Facebook users’ phone numbers found online

#68

Heads up: T-mobile will allow you to take over an account if you can guess one of the most recent phone numbers that the target account has called.

That sounds very secure indeed. Nobody would ever guess that I'd recently called my folks! /s

In Vietnam, scammers use a few numbers to call the target first, making those number the "most frequent recently", then take over the target phone number. This security model is terrible.
Post reply on HN