Live data from Hacker News

Facebook does not plan to notify half-billion users affected by data leak

reuters.com

91–100 of 315 posts

Re: Facebook does not plan to notify half-billion users affected by data leak

#91
post #64

This is probably illegal in Europe. They have 72h to notify their users after noticing a breach according to GDPR's article 33: https://gdpr-info.eu/art-33-gdpr/ Edit: My bad, only notify the authorities.

Except they're not claiming 'breach' they're claiming 'scraping'. Not sure semantic acrobatics is going to fly with the regulator however.

They claim “scraping” in contexts where it benefits them to use that term (requirement to notify users) and “exploited vulnerability” when it benefits them in other contexts (answering to why private personal info was found online). Sometimes they even claim both in the same sentence:

> A Facebook spokesperson told Insider that the data had been scraped because of a vulnerability that the company patched in 2019

They absolutely can’t have this both ways.

Re: Facebook does not plan to notify half-billion users affected by data leak

#92

Earlier quoted context omitted.

Could someone elaborate on what the worst-case exploit would be for those number that got leaked? How would a scenario look like? Asking for a friend whose number got exposed...

It's still going to be a scam message, but they can use your Facebook ID to see everything public on your profile now, as well as the other fields in the leak like full name, location, bio, birthday. So whatever the most convincing scam message somebody can come up with is combining all of that data. Off the top of my head, "happy birthday here's a gift from us" messages from companies leading to phishing pages and p…

Birthday is a form of identity verification too, for password reset.

Re: Facebook does not plan to notify half-billion users affected by data leak

#93
post #10

This huge leak has definitely killed the SMS text messaging service. Sender can be spoofed and spam/scam/phishing have reached an intolerable level. The fact that they can cross reference you and then produce a more personalized content is huge. Changing password is easy (ok less easy if you recycle it) but changing phone number is something that I am not even relaxed to do.

> Sender can be spoofed Is this worldwide or US? I for now trust the senderid and assume them to be valid if they are coming from bank etc. I also haven't heard of anyone spoofing SMS. Should I be more cautious?

Never trust caller ID or senderid on phone calls or SMS.

The reason is that phone companies interoperate grudgingly and do the minimum required to pass calls and messages between each other, and also most phone companies are 100+ year old companies who have just layered modern tech on top of their old stuff.

They handle a massive unending stream of calls/messages and they can't possibly validate each one (even if they wanted to), so when a call comes into your provider (mobile or land line) it comes with all the metadata fields (sender, etc) populated, and your provider just passes that along without any verification.

This was less of a problem with there was a reasonably limited number of phone companies (a few per country) and they were all large enterprises..

Now with the rise of Twilio and tons of other pay-as-you-go companies that can hook into the global phone network to send calls and messages, and MVNOs (virtual phone companies that sit on top of the incumbent ones), there are too many players to track and in the name of convenience (and cost-savings) we haven't kept up with the verification part of the chain.

Re: Facebook does not plan to notify half-billion users affected by data leak

#94
Oh, facebook will pay for this breach. A lot. One thing is breach, the second part is hiding and not notifying "natural persons". They have basically violated (ignoring data collection methods etc.) what GDPR is about. But probably they wont notify non EU users. As they are not obliged so they don't care.

Article 33.

"In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. 2Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay."

https://gdpr-info.eu/art-33-gdpr/

Article 34:

"When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay."

https://gdpr-info.eu/art-34-gdpr/

Re: Facebook does not plan to notify half-billion users affected by data leak

#95
post #10

This huge leak has definitely killed the SMS text messaging service. Sender can be spoofed and spam/scam/phishing have reached an intolerable level. The fact that they can cross reference you and then produce a more personalized content is huge. Changing password is easy (ok less easy if you recycle it) but changing phone number is something that I am not even relaxed to do.

> Sender can be spoofed Is this worldwide or US? I for now trust the senderid and assume them to be valid if they are coming from bank etc. I also haven't heard of anyone spoofing SMS. Should I be more cautious?

This is probably overkill to say but to be sure:

Never trust any information from SMS, or from a telephone call (or email) - both SMS and CallerID can both be trivially spoofed, and frequently are.

If they have e.g. found out what bank you use, they can make the number look like it came from your bank ("See, this number is listed on the back of your card" is a common approach)

If you get a call or SMS requiring followup, then look/ask for a reference number and a publicly listed number you can call back on - _and verify this number is listed on the organisation website before calling_, ideally on a telephone you know they can't "hold the line open" on (less of a problem now people mostly don't have landlines). It's okay to "engage" with a caller as long as you are careful to not give up any personal information - especially in cases where it's a bank they should be fine with you refusing security until you can call back.

Don't ever relay information between channels e.g. if you _think_ you are talking to the bank, don't relay the contents of a 2-factor SMS you get, even if they say they are "sending" one to you. There have been cases where scammers have called the bank at the same time as calling the mark, so that when the scamee called the bank on a different line the bank verified that "they" were on another line.

In reflection, it's kind of crazy the things you have to be suspicious/paranoid and aware of, I'm not surprised that even competent/intelligent people get scammed, it often seems that the infrastructure that we rely on for trust is even flimsier than you could imagine.

Probably there are more extreme cases where these general rules aren't enough but probably unless you are a big CEO or something you are below the targeting threshold (see e.g. https://nakedsecurity.sophos.com/2019/09/05/scammers-deepfak... which will probably only become easier over time). A healthy skepticism about complicated workflows is probably helpful.

Re: Facebook does not plan to notify half-billion users affected by data leak

#96

I suppose a well meaning spammer could just SMS everyone pretending to be Facebook.

Let me just drop a note here that I happen to have two "unlimited" SMS subscriptions (i.e. could at least notify a few thousand people) in different European countries and that contact info is in my profile in case anyone has... ideas... :-)

Re: Facebook does not plan to notify half-billion users affected by data leak

#97

"The Facebook spokesman said the social media company *was not confident it had full visibility on which users would need to be notified*." @Facebook here you go: https://haveibeenpwned.com

If Facebook has since deleted some of those accounts or associated phone numbers, they may no longer have a way to contact those users.

The GDPR in Europe would require them to delete that data in a bunch of circumstances.

Re: Facebook does not plan to notify half-billion users affected by data leak

#98
post #87

For years companies have been steadily asking, mandating or even trickling users to give them their phone numbers under the excuse of security (while the real reasons were different), now what? How can they be trusted anymore? This also strikes a great point about the data sharing between Facebook and WhatsApp. Linking data between services augments the dangers and the consequences are not obvious to the end user. I…

>How can they be trusted anymore?

They never could be.

Re: Facebook does not plan to notify half-billion users affected by data leak

#99

This is probably illegal in Europe. They have 72h to notify their users after noticing a breach according to GDPR's article 33: https://gdpr-info.eu/art-33-gdpr/ Edit: My bad, only notify the authorities.

Notification to users is required by article 34, not 33: https://gdpr-info.eu/art-34-gdpr/

There is no 72h requirement, but "the controller shall communicate the personal data breach to the data subject without undue delay"

Re: Facebook does not plan to notify half-billion users affected by data leak

#100
post #87

For years companies have been steadily asking, mandating or even trickling users to give them their phone numbers under the excuse of security (while the real reasons were different), now what? How can they be trusted anymore? This also strikes a great point about the data sharing between Facebook and WhatsApp. Linking data between services augments the dangers and the consequences are not obvious to the end user. I…

> with a real deletion

Lol.

Post reply on HN