Live data from Hacker News

Facebook privacy fuckup reveals who has your number in their phone

alexmuir.com

81–90 of 124 posts

Re: Facebook privacy fuckup reveals who has your number in their phone

#81
post #48

Earlier quoted context omitted.

If you are truly concerned about harm to users, did you try reporting this to facebook.com/security or facebook.com/whitehat? FWIW, I've alerted some people. Your post is unclear on one point. Did you see this screen BEFORE confirming via SMS that you were in possession of the mobile number you entered? If it was after confirmation, that's a very different thing.

> Your post is unclear on one point. Did you see this screen BEFORE confirming via SMS that you were in possession of the mobile number you entered? If it was after confirmation, that's a very different thing. Good point, but it's not a very different thing, it's a slightly different thing. SMS confirmation would not have stopped FB outing his gay friend to the author. The only different thing is that it would have s…

Fair enough, I won't quibble. In the absence of a bug report, and having to do this in public, I'm trying to get what information I can. I'm also trying to respond to the author's claims about private investigators, etc.

Re: Facebook privacy fuckup reveals who has your number in their phone

#82
post #57
post #53

Earlier quoted context omitted.

/whitehat is not a "complaint letter". It goes directly to the security team oncall, whose job is to keep users safe even if it means killing things written by other engineers at Facebook that had unintended consequences. (edit: removed snark)

Well, what I am wondering is: is this actually an unintended consequence or a conscious choice that has been made?

A company doesn't have a single conscience. It may have been a conscious choice by an engineer, or it may have been an unintended consequence of some other code change. Either way, I highly doubt it involved the check-off from a director-level employee.

If every decision had to get approval from the management team, then progress would grind to a halt, and Facebook would end up like Microsoft.

Re: Facebook privacy fuckup reveals who has your number in their phone

#83
post #70

I am not surprised by this. If I share my phone's contact list with Facebook, I expect that it will become a part of the social graph, just as who I am friends with on Facebook is.

Do you think, facebook should tell you about this forehand in simple words ?

Re: Facebook privacy fuckup reveals who has your number in their phone

#84
post #63
post #62

Um..... I don't get it. How can Facebook have access to numbers on anyone's phone?

Mobile apps.

The phone apps can have access to phonebook? OK, I didn't know that.

It seems that I am heavily downvoted, so... sorry for my comment.

Re: Facebook privacy fuckup reveals who has your number in their phone

#85
post #10
post #7

Not so much of a "fuckup" as it is a "feature". Not to say that I agree with this practice (I don't), but someone deliberately implemented this, and there's a good business case for it. The privacy implications are unfortunate, but what else are we to expect from Facebook these days?

Hum. Respect the law ? I don't know in the US. But here in Europe that's pretty much against the law in most countries.

Point of order:

If you don't even know what the law is, you might try finding out, before sniping about how someone supposedly is not "respecting" it.

If you did, you might then find, for instance, that the best course of action is to complain about the law (or lack of laws), and do something about that.

Re: Facebook privacy fuckup reveals who has your number in their phone

#86

You know I've been wondering about Facebook saying they have 500 million + users but I wonder if they count the deactivated. Which is a fancy word for suspend. I went to delete my account the other day just because there is so much crap and it's time wasting and I go searching for delete but couldn't find a link! I then came across the deactivate which I had heard about before and went with that but they still keep a…

Our user metrics are in terms of monthly and daily active users. More than 800 million people logged in last month with more than 500 million logging in on a single day.

That's right, I remember reading that somewhere. Thanks for clearing that up!

Re: Facebook privacy fuckup reveals who has your number in their phone

#87
post #5
post #2

How do the guy know Facebook used specifically the phone number he gave them ? It's pretty much possible. And Facebook is Evil. But I don't understand how he did to be certain of that ?

They had no other information - there is no doubt. I 100% guarantee that's how it was done.

They have your IP address.

Re: Facebook privacy fuckup reveals who has your number in their phone

#88

Earlier quoted context omitted.

I also reproduced something like this. On "Step 1: Add Friends", it showed people who I actually know (presumably who have my phone number, since that's the only info I gave that actually relates to me) On "Step 3: Profile Information", it offered many more people, most of whom I don't actually know (presumably friends of the people from step 1) Note that to trigger the mobile-number-confirmation request, you may nee…

Jackpot - the name is the trigger, possibly combined with an own-domain email address.

I created an account with a fake name and mailinator email (after several tries where it rejected mailinator domains, it finally worked with bobmail.info). It asked me for my cell phone number to confirm, and when I entered the code it had quite a large number of "John Doe is someone you may know". These people are not all people who I'd expect to have my phone number saved in their phones. My phone number is linked to my primary account, but I don't think it is visible.

Re: Facebook privacy fuckup reveals who has your number in their phone

#89

I can confirm that the "security check" thing is related to having a fake name, or perhaps an empty profile. Both of those apply to my primary account and I'm prompted to enter a phone number every time I log in. It doesn't seem to be required, I've always just dismissed those "security" prompts by clicking the FB logo in the top left, which forwards me to the homepage just fine. The chances of facebook getting my mo…

Couldn't they just get your mobile number, from one of your friends iPhones? Even if you had a fake name on your profile, I would assume its still fairly straightforward to identify you purely from the network structure.

I've no idea if they are doing this, but I wouldn't put the possibility in moon/willpower territory.

Re: Facebook privacy fuckup reveals who has your number in their phone

#90
post #48

These little privacy leaks are not important on their own. A little data leaks here, a little there. What is concerning is that we can guarantee private investigators and professional identity fraudsters are well on top of all these little loopholes. And combined, I'd say Facebook is probably pissing data out. Some sweet law enforcement potential here - slap in a request to Facebook on a drug-dealing suspect, find a…

If you are truly concerned about harm to users, did you try reporting this to facebook.com/security or facebook.com/whitehat? FWIW, I've alerted some people. Your post is unclear on one point. Did you see this screen BEFORE confirming via SMS that you were in possession of the mobile number you entered? If it was after confirmation, that's a very different thing.

You know, buddy, I think from FB we could all use a little more "thanks for pointing out this problem that we at FB should have prevented or refused to implement" and a little less of sarcastic "if you are truly concerned...jump through our hoops."

Preventing harm to users is your job, not ours.

Associates of mine have made SEVERAL complaints to FB about security concerns through your standard "hoops" (including /whitehat), and have received exactly ZILCH, NADA in response.

Post reply on HN