Live data from Hacker News

Facebook claimed phone number was only for 2FA. Now it's searchable

twitter.com

1–10 of 17 posts

Re: Facebook claimed phone number was only for 2FA. Now it's searchable

#2
Synchrony branded credit cards do the same thing, they use your SSN to obtain phone numbers from one of the Transunion skip trace databases. So even though I’ve only ever given Synchrony my dummy number, when I try to change my password I get a selection of phone numbers that they want to send a verification code to, and those numbers only exist in that Transunion database.

You can’t correct or remove anything from the Transunion database, because it’s not used for credit decisions there is no way to force them to do it.

So instead I’ve made it a game to try and see how many phone numbers I can get added to the database. My goal is to request a free copy of my file one day and have it arrive on a pallet.

Maybe if I fill out a credit card application and list Kevin Bacon’s address as a former residence then they’ll add him to my list of known associates...

Re: Facebook claimed phone number was only for 2FA. Now it's searchable

#3

Synchrony branded credit cards do the same thing, they use your SSN to obtain phone numbers from one of the Transunion skip trace databases. So even though I’ve only ever given Synchrony my dummy number, when I try to change my password I get a selection of phone numbers that they want to send a verification code to, and those numbers only exist in that Transunion database. You can’t correct or remove anything from t…

Hey, if you can automate the process, you have a free backup service with unlimited storage ;)

Re: Facebook claimed phone number was only for 2FA. Now it's searchable

#4

Synchrony branded credit cards do the same thing, they use your SSN to obtain phone numbers from one of the Transunion skip trace databases. So even though I’ve only ever given Synchrony my dummy number, when I try to change my password I get a selection of phone numbers that they want to send a verification code to, and those numbers only exist in that Transunion database. You can’t correct or remove anything from t…

When you figure out how to game the system charge others to do it.

People would pay to create fuzz in their records.

Re: Facebook claimed phone number was only for 2FA. Now it's searchable

#7

could this be a GDPR violation of any sort in the EU?

I should think so. They don't have consent; vital interest, public task, legal obligation and contract do not apply; they must be relying on legitimate interest. I can't imagine this would pass an unbiased balancing test.

Re: Facebook claimed phone number was only for 2FA. Now it's searchable

#8
For some unfathomable reason Google no longer allows Google Voice clients to forward their calls to Project Fi numbers. So my new layer of abstraction is a $3/mo Call Centric number routed to a $12 SIP deskset.

Call Centric lets you whitelist so step one is to upload your contacts to them and then drop any calls not in your list. Goodbye telemarketers. Second step is to leave the phone unplugged altogether unless you need to use it since anyone you know has your mobile number anyway. :-)

If you really need it, you can add the Call Centric number to your cellphone via a SIP client but in my experience that's a bit of a battery sucker and call quality can be poor with noticeable voice delay.

Re: Facebook claimed phone number was only for 2FA. Now it's searchable

#10

Synchrony branded credit cards do the same thing, they use your SSN to obtain phone numbers from one of the Transunion skip trace databases. So even though I’ve only ever given Synchrony my dummy number, when I try to change my password I get a selection of phone numbers that they want to send a verification code to, and those numbers only exist in that Transunion database. You can’t correct or remove anything from t…

When you figure out how to game the system charge others to do it. People would pay to create fuzz in their records.

I think they key is that data brokers are greedy and accept all inputs with little validation. Their data quality teams are more focused on algorithmicly removing “obvious” duplicates due to small transpositional errors and such. They are usually not geared towards stoping people from intentionally entering incorrect but valid data. Even in cases where they might hold back data because they are uncertain about, they don’t delete it, as soon as there are enough “signals” that it might be correct they pass it through.

So knowing that data brokers are greedy the trick isn’t to get governments to force them to delete and protect information, the trick is to give them so much bad information that the good data becomes indistinguishable.

Post reply on HN