Earlier quoted context omitted.
The idea that using your state-given name online is beneficial.
What is a state-given name?
Facebook does not plan to notify half-billion users affected by data leak
71–80 of 315 posts
Re: Facebook does not plan to notify half-billion users affected by data leak
#72Re: Facebook does not plan to notify half-billion users affected by data leak
#73Earlier quoted context omitted.
Any idea on the extra security measures? In Turkey for example, when you change your SIM card the 2FA from the banks will stop working and you need to call your bank to re-activate it. That of course seems like a measure to prevent SIM cloning but maybe there are some security protections against spoofing. In many places SMS is a popular way to do payments and 2FA for high security applications.
Where does SMS get used to do payments? (...and how?) SMS for 2FA is known to be a very bad idea, and some security experts have been shouting about the need to stop doing that for a while. I also can't see any country managing to implement more restrictions on SMS without either breaking a lot of "legitimate" sources of SMS or being ineffective outside of a very narrow window (e.g. only blocking forged SMS for numbe…
In India, for every card transaction, for every DMAT transaction, for every password/PIN change SMS is used as 2FA. It is also mandated to require SMS 2FA for every one of these cases.
If my bank has any means to use TOTP/Yubikey, it is absolutely not made obvious, led alone clear or even possible.
Re: Facebook does not plan to notify half-billion users affected by data leak
#74Earlier quoted context omitted.
Are you seriously claiming it's too hard? They could send out emails, Facebook messages or show some banner in the profile page. This is Facebook ffs, they almost have a monopoly on communication.
> too hard to notify users Legally seen. The way privacy protection laws are, especially in Germany, is kinda stupid. On one side they often doesn't protect you in practice, on the other side they effectively hinder and sometimes prevent reasonable usage. Just a view examples: - A local government couldn't properly inform elder people that they now can get Vaccinated for free because the interplay of various privacy…
This is false. I've been tested about 15 times within the last year and none of the things I "signed" included any of that.
I didn't have to physically sign ANYTHING at all. What are you talking about?? It's just a click field on the online application and that only says that you're okay with your data being shared with the lab that also sends you your test results.
> then when you get the result you still need to agree again to share this information.
This is also absolutely untrue as Covid, among others, is on the list of illnesses that the local Gesundheitsamt has to be notified of. It's not even optional. It's the law. https://www.gesetze-im-internet.de/ifsg/__6.html
Honestly curious where you got that information from?
Re: Facebook does not plan to notify half-billion users affected by data leak
#75Re: Facebook does not plan to notify half-billion users affected by data leak
#76Earlier quoted context omitted.
Where does SMS get used to do payments? (...and how?) SMS for 2FA is known to be a very bad idea, and some security experts have been shouting about the need to stop doing that for a while. I also can't see any country managing to implement more restrictions on SMS without either breaking a lot of "legitimate" sources of SMS or being ineffective outside of a very narrow window (e.g. only blocking forged SMS for numbe…
> Where does SMS get used to do payments? (...and how?) In India, for every card transaction, for every DMAT transaction, for every password/PIN change SMS is used as 2FA. It is also mandated to require SMS 2FA for every one of these cases. If my bank has any means to use TOTP/Yubikey, it is absolutely not made obvious, led alone clear or even possible.
Unfortunately, quickly looking, [1] suggests at least one of the listed services for sending arbitrarily forged SMS messages explicitly works in India, so it seems like this is still true for you. :(
[1] - https://www.usethistip.com/5-websites-to-send-anonymous-or-f...
Re: Facebook does not plan to notify half-billion users affected by data leak
#77Earlier quoted context omitted.
> Sender can be spoofed Is this worldwide or US? I for now trust the senderid and assume them to be valid if they are coming from bank etc. I also haven't heard of anyone spoofing SMS. Should I be more cautious?
> Is this worldwide or US? Worldwide. SMS is just like e-mail, you can put anything you want in the sender field. You should absolutely not trust SMS.
Re: Facebook does not plan to notify half-billion users affected by data leak
#78This huge leak has definitely killed the SMS text messaging service. Sender can be spoofed and spam/scam/phishing have reached an intolerable level. The fact that they can cross reference you and then produce a more personalized content is huge. Changing password is easy (ok less easy if you recycle it) but changing phone number is something that I am not even relaxed to do.
Re: Facebook does not plan to notify half-billion users affected by data leak
#79Earlier quoted context omitted.
What is a state-given name?
Presumably your birth name given to you by your parents. Describing it as "state given" seems intentionally misleading...
The state does not give you name, but it registers it and uses it to recognize you in various situations. Usually the name is not enough to identify a person (and fun/disaster ensues when this is attempted) so, usually, more information is needed to identify a person.
Re: Facebook does not plan to notify half-billion users affected by data leak
#80My understanding is they are wilfully violating Australian law too, not just the GDPR. I wonder how various countries will react?