Live data from Hacker News

WhatsApp data leak: 500M user records for sale

cybernews.com

91–100 of 109 posts

Re: WhatsApp data leak: 500M user records for sale

#91
post #86

so the leak isn't a leak but a database of numbers they scraped together > To prevent personal data leaks, regular users should adopt common data security practices. This includes using a high-quality VPN and getting a reliable antivirus program. And since the shopping holidays are close, you can already find great market-leading NordVPN Black Friday and TotalAV deals. this post is basically spam.

Should be changed to something like https://www.techradar.com/news/whatsapp-data-breach-sees-nea...

I like that this article doesn't mention the county that is likely most affected: India.

> More than 32 million of the leaked records are said to be from users in the US, with 11 million from UK users. Other affected nations include Egypt (45 million), Italy (35 million), Saudi Arabia (29 million), France (20 million), Turkey (20 million), and Russia (10 million).

Re: WhatsApp data leak: 500M user records for sale

#93
post #40

Earlier quoted context omitted.

Probably he is referring to that WhatsApp is from a US company vs telegram with Russian origin.

general tendency in HN is Telegram bad, Signal/WhatsApp is good. Even small mistake made by Telegram will be judged harshly, when it comes to WhatsApp, their mistakes are not important. Yes I am a Telegram fanboy (how can you not like such a beautiful/fast app, in the Electron world where everything takes 10s of seconds to load)

Signal seems like a pretty light/fast/good electron app (on windows at least)?

Re: WhatsApp data leak: 500M user records for sale

#94
post #58

Earlier quoted context omitted.

A closed/open source server doesn't matter since you can't actually confirm if the open source version is actually running.

If it's open source and has a reproducible build, then you can audit the codebase, compute the hash, then verify an attestation from the secure enclave that the code is running in.

So you need to trust the server to return a valid, unmodified hash?

Re: WhatsApp data leak: 500M user records for sale

#95
post #75

Earlier quoted context omitted.

That remains to be seen. People are fairly ingenious when it comes to abusing information and information runs the world now. I will offer an unrelated example, partially because I do not want to give ideas on how to benefit from this. Do you remember when certain entrepreneurial billionaire offered a checkmark for sale, which resulted in people impersonating companies and manipulating their stock price[1]? Like with…

> Like with most things, any tool is worth what one is able to do with it. Yes, and given an attacker will not get new capabilities from this data, it is worth nothing. Any attack that could be feasibly run with a list of nothing but phone numbers associated with some (unknown) WhatsApp account could be done without that list just as easily. That's because of two things: a) phone numbers within a given country are ea…

You do have a point and it is possible I misunderstood the 'value proposition' from this data set.

From the forum referenced in the article:

"Name / Whatsapp Number - Country Wise "

What I see in that post is name field ( or potentially just a number ) and country field. If I was a person buying it, the main benefit would be "being able to reach a seemingly random ( unless it is separately checked against some other available list/s ) individual in a desired geographic location". As you correctly assessed, by itself it is not a terrible security threat.

Yes ( although admittedly, mostly because "bad things" is sufficiently generic to allow for it and I already admitted I think you are right on the security aspect ).

Fraud-wise this is a perfectly sufficient set of information ( current valid numbers likely corresponding with real phone numbers ) as those tend to be number games anyway ( one out of how many answers a spam email type of deal ). In that area, the most common scam lately is grandson scam[1] or romance scam[2]( those having extra benefit of less likely being reported even if others point it out to the victim ). Seniors do seem to use Whatsapp in the old country partially due to price and reliability ( dunno how common it is in US though ) so they fit that target demographic, but that assumes fraudster can reliably identify a victim set of seniors ( or burn existing set with a more generic pitch ). For non-seniors, crypto scams seemed very common lately ( and how many people just click yes, when an invitation pops up ) although recent crash likely made it less desirable.

In other words, I think you are right about not doing anything specific security-wise, but it may be worthwhile talking with your social circle if they use Whatsapp since they may now see an increase in unsolicited calls/messages/invites and benefit from a conversation about about safety online in general.

[1]https://www.aarp.org/money/scams-fraud/info-2019/grandparent... [2]https://www.fbi.gov/how-we-can-help-you/safety-resources/sca...

Re: WhatsApp data leak: 500M user records for sale

#96
post #76

Earlier quoted context omitted.

No, instead they use this radical method called actually identifying the person they're about to give a bunch of cash to instead of trying to pretend a username is a password.

Sorry, I did not understand your comment (English is not my first language)

Gp is saying that no, it doesn't increase identity theft. Other (better) methods of verification are used instead.

Re: WhatsApp data leak: 500M user records for sale

#97
post #58

Earlier quoted context omitted.

If it's open source and has a reproducible build, then you can audit the codebase, compute the hash, then verify an attestation from the secure enclave that the code is running in.

So you need to trust the server to return a valid, unmodified hash?

In the case of the above, you're not trusting the server, you're only trusting the CPU manufacturer. Attestation happens within the secure enclave inside the CPU, at which point having physical access to the machine doesn't (well, shouldn't, if it's correctly implemented) give you any insight into what code it's running or what data it's operating upon.

Re: WhatsApp data leak: 500M user records for sale

#98
post #53

Earlier quoted context omitted.

Yeah definitely; the "+" alias is built in to most emails (like, it works on Google/Proton at least). I'm more just saying that if you pay for ProtonMail (and therefore care about privacy more than the average person) you get another service for free that doesn't expose your "real" email if someone cared to look. Someone can look at joe+spam@joeschmo.com and figure out Joe's "real" email address. Something like Simpl…

Yeah it's definitely a better pattern, I hope more companies create something like it. I think I heard Apple is doing something similar maybe? I seem to recall Fastmail has one too, pretty sure I saw it in the bitwarden settings last I went in there.

Apple does this with email forwarding aliases on your phone; I can sign up using a generated Apple relay, which then pushes to your main email. I don't like it that much, mostly because you're still kind of locking into the Apple ecosystem, though.

Re: WhatsApp data leak: 500M user records for sale

#99
post #97

Earlier quoted context omitted.

So you need to trust the server to return a valid, unmodified hash?

In the case of the above, you're not trusting the server, you're only trusting the CPU manufacturer. Attestation happens within the secure enclave inside the CPU, at which point having physical access to the machine doesn't (well, shouldn't, if it's correctly implemented) give you any insight into what code it's running or what data it's operating upon.

How can you know which CPU is running? Also, the software could easily change the output of the security chip (secure enclave is only on apple devices).

Re: WhatsApp data leak: 500M user records for sale

#100
post #28

Earlier quoted context omitted.

I might be missing something here. Why would HN care any differently about WhatsApp vs Telegram?

WhatsApp chats are end-to-end encrypted (even their iCloud backups are). Telegram group messages are always plaintext / available to Telegram, and Telegram 1:1 direct messages are plaintext by default.

Yet they hold the encryption keys to decrypt your chats on the fly. What inspires so much trust in Meta? Especially in a company with "targeted advertisements" as its business?
Post reply on HN