[HN Gopher] The Facebook phone numbers are now searchable in Hav...
___________________________________________________________________
The Facebook phone numbers are now searchable in Have I Been Pwned
Author : helb
Score : 493 points
Date : 2021-04-06 09:29 UTC (13 hours ago)
(HTM) web link (www.troyhunt.com)
(TXT) w3m dump (www.troyhunt.com)
| coatmatter wrote:
| Non-technical speculation, but based on my own experience as an
| ordinary Facebook user:
|
| I'm increasingly confident that this breach/leak has come about
| mostly through the privacy _search_ setting (buried in Facebook
| 's privacy settings -
| https://www.facebook.com/settings?tab=privacy -) which allows
| "Everyone" to search for a number in order to find your profile
| if so enabled.
|
| This is a bit like an option that PayID/Osko (instant bank
| transfers) in Australia allows - one could bash through random
| mobile numbers and discover more information than just the
| number. I've always found this option to be creepy because I
| don't people who might otherwise have my phone number
| legitimately to be able to facestalk me.
|
| Please note that this is separate to displaying contact info
| publicly on one's profile page - yes, there is a dizzying array
| of different privacy settings on Facebook. Would Mark Zuckerberg
| provide have ever displayed his phone number publicly? I doubt
| it. But would he have allowed others who already have his phone
| number to search for him on Facebook? I'd say almost certainly
| yes.
|
| I used to use Facebook more than I like to admit and I have
| provided my phone number to Facebook in the past, yet have
| managed to avoid being in this breach, whereas some people I know
| are in the data set. This means I'm quite sure that I'm not
| returning false negatives with the search.
| hendersoon wrote:
| Only ~32m of ~190m US FB accounts were in this breach, so it's
| not surprising if you live in that country and are not in the
| breach.
| ehsankia wrote:
| Looking at the full breakdown [0], a bunch of middle eastern
| countries have near 100% breach. It seems like they were the
| target, and all the other countries were just collateral
| damage maybe? Canada, US, UK, all sitting around 10-20%.
|
| [0] https://datastudio.google.com/u/0/reporting/afa08373-621e
| -4e...
| coatmatter wrote:
| This statistic isn't applicable to me.
| fatnoah wrote:
| I guess the good news is that I still have identity monitoring
| from that time where the federal government gave up my
| information, including SSN, phone numbers, finger and toe prints,
| etc.
| xibalba wrote:
| I've been pwned. Is it known when this breach occurred? I have
| seen a huge spike in spam calls over the last 3-4 months and now
| I'm wondering if it was bc of this breach.
| teddyh wrote:
| Links to the actual data (allegedly):
| https://pastebin.com/sq7UDyVb
| gmargari wrote:
| Thanks, I did a quick hack to find my Google contacts in leak
| file, so I can inform them:
| https://gist.github.com/gmargari/95976c58d2ef0c05cc1f03fc023...
| jaywalk wrote:
| Thanks, I was looking for that. Aside from linking my name to
| my cell phone number (which I really can't even assume is
| private anymore) there's nothing private in there for me.
| J_tt wrote:
| Seems to be missing Australia, I was curious to see what data
| had been leaked about me, since it seems to vary significantly.
| coatmatter wrote:
| This set is missing Australia yes, but not the other set Troy
| Hunt was sent - he covers this in his blog post and tweets.
| There are at least two sets floating around. The ones loaded
| into HIBP do contain Australian numbers - I've checked.
| Sommer wrote:
| One other attack vector with this data that I've not seen much
| chatter about is that the phone numbers (and other leaked data)
| are sufficient to create a Facebook Custom Audience and directly
| target the associated people with ads. Cross referencing these
| numbers (or pivot through names) with any external data source
| and you've got the capability to target specific voters, for
| example. Facebook made a lot of changes [eventually] to their
| Custom Audience abilities via user ID as a result of the
| Cambridge Analytica scandal, this leak makes it not too
| dissimilar in terms of how you could at least segment and direct
| target ads.
| HenryBemis wrote:
| I searched my number(s), no hits. I did a +/- a few numbers, and
| there is a hit. The message is though: "Oh no -- pwned!"
|
| The only information exposed to me is that the person with that
| number, has a FB profile. If I am to trust FB (which I don't -
| for nothing) is that FB has this person's number and lost it. I
| place no reliance to anything that FB states. For all I know that
| person is a WhatsApp user and the FB branch 'stole' the number
| and added that to their FB account (yes, I know this is not how
| data works, but this is how FB works).
|
| (semi-rant follows - apologies)
|
| There is a mention of 2FA/MFA in another comment. I wouldn't be
| surprised if FB already has a 'super profile', where all data by
| FB-WA-IG are merged. I believe that would be a nightmare to do,
| but hey, FB is good at nightmares.
|
| Edit: I feel this is a semi "Ashley Madison" moment. People who
| have a 'secret' FB profile may get busted by their BFs/GFs.
| samerjj wrote:
| As a Syrian who have used many throw-away accounts on FB, this is
| a life or death matter for many of us. I'm sure the Syrian regime
| will use this information to track activists. I have checked and
| there are 7 million leaked accounts from Syria, probably covers
| everyone who uses Facebook in the country. Facebook made it
| mandatory to provide the phone number and now that this is
| leaked, they bear the moral responsibility for all the people who
| will be affected by this.
| indigowind wrote:
| What's the legal recourse for users who have had their numbers
| leaked? Any group action possible?
|
| Could the US or EU fine them as well?
| benaadams wrote:
| > "One last note on the data load process: At the time of
| publishing this blog post, all phone numbers beginning with
| international codes 4, 6, 8 and 9 have completed loading. The
| other codes are in progress and may take several hours more
| before they're searchable."
|
| https://twitter.com/troyhunt/status/1379366099544797189
| woko wrote:
| Thanks, because the end of the blog post mentions 8 instead of
| 9:
|
| > At the time of publishing this blog post, all phone numbers
| beginning with international codes 4, 6, 8 and 8 have completed
| loading. The other codes are in progress and may take several
| hours more before they're searchable.
|
| So I was like: what about another 8?
|
| Edit: Actually, it is "4, 6, 7 and 8"! cf.
| https://twitter.com/troyhunt/status/1379377818618884098
| IG_Semmelweiss wrote:
| Curious if anyone had success in avoiding this, by inserting a
| fake number in their FB profile.
| drcongo wrote:
| I'm completely unsurprised that my phone number is in there
| despite the fact that I deleted and closed my account 10 years
| ago.
| shnp wrote:
| I deleted my phone number around mid-2018 and it's also part of
| the leak tying the phone number to my name and gender
|
| https://news.ycombinator.com/item?id=26708923
| hendersoon wrote:
| We don't know exactly when the data was exfiltrated, just
| that it ended in early 2019. It could have been taken at any
| point before that time.
| sm4rk0 wrote:
| Earliest date in one of the columns (last login?) is
| something around 2019-04-28.
| shnp wrote:
| Yeah it could be, will have to wait for more details first.
|
| I would not be surprised if FB kept that phone number with
| a "deleted" flag to this day though.
| milofeynman wrote:
| Similar experience. Class action?
| Crontab wrote:
| Couldn't it be there from someone who knows you? I was under
| the impression that Facebook grabbed people's contacts list on
| mobile apps.
| comeonseriously wrote:
| So, that begs the question: If _my_ phone number is in
| someone _else's_ contacts, is it still _my_ phone number?
| hnick wrote:
| It is still PII which sometimes has specific laws and rules
| around its use depending on where you are.
|
| If I give someone's social security number to a company
| that doesn't mean they can publish it on the front page
| just because the person it belongs to didn't hand it over.
| ghaff wrote:
| It's your phone number (or possibly also the phone number
| of the person who had it before you) but, like images of
| yourself, they're probably in tons of places that you don't
| control and never will.
| davidjohnstone wrote:
| My understanding is that all numbers in the dump correspond
| with Facebook accounts, so this shouldn't be the reason.
|
| Another option would be that someone else has that number
| listed for their account. Has Facebook always required
| confirmation that a number is valid? I saw one my friends'
| numbers in the data except the account had a different name.
| HatchedLake721 wrote:
| Did you deactivate or delete your facebook account?
|
| As I understand, deactivation is temporary, deletion erases all
| data.
|
| But if people did delete their accounts and Facebook didn't
| erase the private data, aren't there consequences to this?
| drcongo wrote:
| Full delete. I was very careful about it at the time.
| arcturus17 wrote:
| > As I understand, deactivation is temporary, deletion erases
| all data
|
| That's the problem, what we or regulators understand may well
| be very different to what actually happens
|
| > aren't there consequences to this
|
| A slap on the wrist at best, I'd bet my house on it
| snarfy wrote:
| 'Erases' all data, or sets the is_deleted flag.
| 2muchcoffeeman wrote:
| I got a bunch of spam phone calls today.
| gruez wrote:
| My experience is completely opposite to yours. I have a
| facebook account, phone number added and verified, profile
| privacy set to "friends only", but I can't find myself in the
| leaks.
| scrollaway wrote:
| My understanding of the dump is that it was scraped, thus
| it's non exhaustive by nature. There's only half a billion
| accounts in it after all, and Facebook has far more.
| nerbert wrote:
| If you're a EU citizen contact your local data protection
| authority and file a complaint. It literally takes 5 minutes.
| Nextgrid wrote:
| And Facebook will promptly ignore _that_ too:
| https://ruben.verborgh.org/facebook/
| lupire wrote:
| 1. That article is about downloading, not deleting.
|
| 2. You don't negotiate with Facebook, you norify the
| regulators so they can asses another billion-euro fine.
| zoobab wrote:
| How much money can you get as damages?
|
| Answer under the GDPR is probably: 0EUR.
| [deleted]
| verytrivial wrote:
| (/verytrivial cries in Brexitish ...)
| jeroenhd wrote:
| The UK hasn't abolished their implementation of the GDPR
| (yet?) so you should still be to file a complaint with the
| ICO (AFAIK; IANAL).
| eru wrote:
| I'm not sure citizenship is required?
| [deleted]
| dgellow wrote:
| Relevant links.
|
| "What should I do if I think that my personal data protection
| rights haven't been respected? "
|
| https://ec.europa.eu/info/law/law-topic/data-
| protection/refo...
|
| "European Data Protection Board Members"
|
| https://edpb.europa.eu/about-edpb/board/members_en
| divbzero wrote:
| Yes, please do this if you are protected by European
| regulations.
|
| I also wish we could do more to put pressure on Facebook
| and other bad players. Can't help thinking this is viewed
| internally as just more work for the legal department
| followed by an X billion euro "cost of doing business" fine
| after so many years.
| insiderreporter wrote:
| Mark Zuckerberg's phone number is there too.
| deepstack wrote:
| Yeah these companies that rely on user data will NEVER delete
| your data once you submit it to them (regardless if they say
| your data is deleted or account closed). For company like FB
| you are the product.
| rorykoehler wrote:
| Data leaks like this are positive in that regard because we
| can prove they haven't complied with GDPR quite easily if our
| deleted data comes up.
| pedrocr wrote:
| One thing I didn't find on the website was a way to get an email
| with the actual data that was leaked so I can evaluate what's at
| stake. Showing it online would be poor privacy but sending it to
| the email should solve that.
|
| Some of the leaks are from companies I don't even know, that work
| behind the scenes aggregating information. Particularly for those
| I'd like to see what was leaked. For the services I actually used
| directly I have a clearer idea.
| jaypeg25 wrote:
| I permanently deleted my Facebook account September 2019. My
| phone number was included in this data breach, which was
| apparently August 2019. So close. If only I got rid of it sooner.
| Tenoke wrote:
| Oddly enough even my email doesn't show up for the Facebook
| breach (possibly because I never added a number on Facebook, just
| whatsapp).
|
| It does show up for companies I've trusted more though - Dropbox,
| Linux Mint, XKCD (md5 really?), Forbes, etc.
| KMnO4 wrote:
| Hm, I already know phone number is leaked, but searching for it
| (XXXxxxXXXX) doesn't work.
|
| Once I prepended Canada's country code: (1XXXxxxXXXX) it worked.
|
| Maybe this can be fixed with some simple communication? Ie "No
| result --- ensure you enter your full phone number including
| country code"
| ricardobayes wrote:
| how do you know it was leaked? got spam?
| tartoran wrote:
| I searched the database and haven't been pawned but of course I
| know why, I never shared my phone number with FB and this
| confirms my idea that sharing anything with FB is a terrible
| idea, even the real name with correct spelling can cause issues.
| I urge everyone who wants to still hold a social media account to
| add an alternative spelling for their name. When info leaks or
| one gets unsolicited messages of any kind out it becomes very
| easy to backtrack to which social media account the leak is
| coming from. Perhaps one more reason (from the many) to disable
| that account.
| Maxburn wrote:
| This is excellent advice. Years ago I had a misspelling of my
| name on my drivers license. Very easy to find the source of all
| my junk mail after that!
| uyt wrote:
| The previous thread had an amazing trick that worked for me:
| https://news.ycombinator.com/item?id=26682325
|
| tl;dr; search your real phone number but exclude consecutive
| numbers to filter out auto-generated pages:
| "(212)555-1239" -1240 -1238
|
| Using this I was able to find all my info (and much more) on
| sites like: https://www.fastpeoplesearch.com/
|
| I expect many of these "people search" sites to link to your fb
| profile soon using this breach.
|
| I expect the more sophisticated ones to crawl all your social
| media accounts (twitter, chat apps, etc) by abusing the reverse
| look up using your phone number.
| beervirus wrote:
| > Facebook: In April 2021, a large data set of over 500 million
| Facebook users was made freely available for download.
| Encompassing approximately 20% of Facebook's subscribers, the
| data was allegedly obtained by exploiting a vulnerability
| Facebook advises they rectified in August 2019. The primary value
| of the data is the association of phone numbers to identities;
| whilst each record included phone, only 2.5 million contained an
| email address. Most records contained names and genders with many
| also including dates of birth, location, relationship status and
| employer.
|
| > Compromised data: Dates of birth, Email addresses, Employers,
| Genders, Geographic locations, Names, Phone numbers, Relationship
| statuses
|
| This is annoying, but I just can't get too worked up about it. I
| assume that anything I tell Facebook is already more or less
| public.
| cwhiz wrote:
| Getting to the point where we're going to need phone, email, and
| SMS to be deny all by default. Can't reach me unless you're
| information is already in my contacts.
| mcculley wrote:
| I get a lot of value out of being reachable by people I do not
| yet know.
| gh123man wrote:
| As do I. This is a difficult problem to solve especially as
| the signal to noise becomes worse as abuse becomes more
| common.
|
| Ive had to wildcard block my area code (since I don't live
| there anymore) which captures 95% of my daily spam calls -
| but people can still leave a message to break through my wall
| if it's truly urgent. I don't see how this could work with
| SMS.
|
| Even message requests on facebook/messenger have problems
| where you are unlikely to even see the request unless you
| check regularly.
| cwhiz wrote:
| No one said it had to be by force.
| mcculley wrote:
| Maybe I misunderstood your use of the "we" in "we're".
| sethammons wrote:
| I found a novel solution by accident to this. I moved to a
| new area but kept my old number. 99% of my spam calls are
| from my phone's area code. If you are not a contact and a
| number comes up from that area code, it is spam. If it is my
| new area code, it is a person or business trying to reach me.
|
| You could likely get a far off area coded number.
| derwiki wrote:
| Yea ignoring unknown numbers from my home state is fairly
| effective at blocking spam calls.
| acheron wrote:
| Same (though "I moved to a new area" happened in 2004). At
| this point I've just blocked the entire old area code and
| neighboring ones, aside from existing contacts.
| panzagl wrote:
| Found the guy who bought the extended warranty for his car
| mcculley wrote:
| No, I have never bought an extended warranty. However, I
| did today make good money on a business transaction because
| a stranger was able to reach me.
| baby wrote:
| I already don't accept any calls. The robocall stuff in the US
| is out of control.
| 3pt14159 wrote:
| It's a hard problem to crack. Some legitimate places need to be
| able to call you without you knowing them ahead of time. Say
| your sibling was mugged in Mexico and the local little police
| station let them borrow the landline to call the only number
| they still remember without having to check their contacts in
| their phone. Are you not going to pick up?
|
| There are a lot of these little edge-cases. Journalists,
| lawyers representing class action suits, government id
| expiring, and so on.
| coldpie wrote:
| I'm in my 30s and I can't think of a single time I have ever
| received a phone call that I didn't expect. I get several
| spam calls every day. I would make the trade (and recently
| have, I block all unknown numbers now).
| reaperducer wrote:
| _I 'm in my 30s and I can't think of a single time I have
| ever received a phone call that I didn't expect._
|
| I've read that people not answering their phones is the
| number one reason that COVID contact tracing doesn't work.
|
| But your comment makes me think that you've never had food
| delivered. Never used an Uber. Never owned a business.
| Never bought or sold real estate. Never rented a place to
| live. Never went to a restaurant with a wait list. Never
| done a lot of things that are perfectly ordinary, and
| require allowing people to contact you when they have
| questions.
| nonameiguess wrote:
| Most delivery services with an app have messaging built-
| in so you don't need to rely on calls, but I also know
| when I'm expecting a delivery or a driver to pick me up,
| and if an unknown call comes from my area code (the one
| I'm actually in, not the one my phone number is in), I'll
| answer that. It's pretty easy to distinguish between
| times I might expect a call and all other times.
|
| For all those other things, though, I'm not sure why you
| need to answer unknown numbers. I've never owned my own
| business, but did manage a small business and we had
| dedicated business lines. No one needed to call my
| personal phone. For buying and selling real estate, there
| are agents that act as go-betweens and you can put their
| number on your contacts list. For renting, put the
| management company on your contacts list.
| reaperducer wrote:
| _Most delivery services with an app have messaging built-
| in so you don 't need to rely on calls_
|
| I've used dozens and dozens of delivery companies over
| the years, and the only delivery company I've found that
| doesn't have its people calling on phones is DoorDash,
| and even that uses SMS. Plus, most of the best places
| don't use services, they have their own people.
|
| _we had dedicated business lines_
|
| Doesn't help you when someone needs to contact you in an
| emergency, like the alarm company, or the landlord, or
| security, or the police, thousand other things.
|
| _For buying and selling real estate, there are agents
| that act as go-betweens and you can put their number on
| your contacts list._
|
| Sounds good in theory, but doesn't work in practice.
| There can be dozens and dozens of people and companies
| involved in such a transaction, and you can't predict who
| they all are.
|
| _For renting, put the management company on your
| contacts list._
|
| When the management company sends a vendor over to fix
| something, you don't know what number they'll call from.
|
| To "never" get an unexpected, important call sounds like
| a side effect of a quiet life. I envy you.
| benlivengood wrote:
| > Say your sibling was mugged in Mexico and the local little
| police station let them borrow the landline to call the only
| number they still remember without having to check their
| contacts in their phone. Are you not going to pick up?
|
| Just wait for the deepfaked voice call scammers. Their best
| bet is to work up the hierarchy; a tiny local police station
| knows how to get in touch with a bigger police station that
| can contact an embassy, etc.
|
| > There are a lot of these little edge-cases. Journalists,
| lawyers representing class action suits, government id
| expiring, and so on.
|
| All of these use-cases allow someone to spend the time to
| contact you via your preferred contact method, whatever that
| might be.
| duffyjp wrote:
| My iPhone is set to "Silence Unknown Callers." It's the
| perfect compromise. If a call is legitimate they'll leave a
| voicemail and I just call them back.
| macintux wrote:
| I discovered recently that my Verizon phone service's
| voicemail had been full for several months. I'm not sure
| how I was ever supposed to discover that, but I ignored
| what turned out to be an important phone call and got burnt
| because I assumed I'd get a voicemail.
| dalbasal wrote:
| Possibly, but we can't do that either. What we _need_ is some
| balance of both worlds. OOH, we do actually need to be
| contactable. OTOH, being too contactable means spam. I doubt
| there 's a perfect balance, but either extreme come with too
| many problems.
|
| Email has decent spam filtering, and I think that kind of cat-
| mouse system will persist. That said, there's "room" for more
| whitelisting.
| jerf wrote:
| "I doubt there's a perfect balance, but either extreme come
| with too many problems."
|
| In principle, "pay me a small fee if you're not on my list,
| if I put you on my list now it's free" would work well
| (optionally refund someone who contacts you out of the blue
| that you approve of), but there's a lot of both engineering
| and social details between where we are now and such a
| system.
|
| It doesn't take much cost friction to deter mass spamming. I
| don't think much problem would be left behind from the
| handful of overconfident spammers who think that they can
| bust the odds and it's worth 25 cents a message or something.
| biot wrote:
| This is nearly a few decades old (2004):
| https://craphound.com/spamsolutions.txt
| dalbasal wrote:
| This is one of those ideas that appeals to economists and
| nerds, but rarely works out irl.
|
| Artificially or intentionally aligning interests tends to
| be a "genie, make me a sandwich^" problem. There are lots
| of places where "reversing the charges," seems good in
| theory... but it never happens.
|
| Anyway, linkedin have something like this. In practice, it
| feels like a better quality of spam, rather than a solution
| to spam.
|
| ^Poof. you are now a sandwich.
| shuntress wrote:
| Sounds like a good idea on which to base an ISP startup.
|
| "Anyone not on your contact list will take $1 off your
| monthly bill for each phone call, SMS, or eMail they send
| to you (through our phone line & email servers)"
| cwhiz wrote:
| The "Hey" email service toes the line well for me. I'd prefer
| all of my communications were based on a similar idea.
| jillesvangurp wrote:
| My phone number (and some other details) were part of Nano
| Ledger's database that got stolen last year. So, some
| entrepreneurial scammer started calling me on a daily basis a
| few months ago. Really annoying. I'm well aware my phone number
| and email addresses are pretty much public information at this
| point. I actually put that on my web site even. But stuff like
| this makes me even less likely to answer unknown numbers.
| Hilariously, the scammer actually called me while I was giving
| a security briefing to our company about enabling 2FA. I put
| him on speaker and we had a good laugh while the guy insisted
| in broken English laced with expletives that he "had my money".
|
| A few months ago some criminals social engineered themselves
| past my bank's security as well. The first I learned about this
| was a funny conversation (by phone!) from an actual Deutsche
| Bank employee asking me if I recently changed my address and
| phone number and whether I opened ten new accounts. "eh
| no?!..." Basically their fraud detection system kicked in
| before these people did any damage. I made a point of not doing
| anything else than confirming information they already knew
| (like my old address, email address) and asked for an on site
| meeting to discuss things in more detail. I realized instantly
| I had no way of verifying anything I was being told on the
| phone and might very well be talking to a scammer. As it turns
| out this was for real and the person actually managed to find
| my "old phone number" in some archive. Otherwise all my contact
| information had already been changed by the scammers.
| Thankfully I answered that call. Apparently, this happened to
| several people.
|
| Basically, what happened was some persons just called the
| bank's help desk, asked them to reset my online banking access
| codes, and then somehow intercepted the pin codes (thanks
| Deutsche Post) before they reached me. The theory is that
| somehow the security of the distribution system was
| compromised. As far as I an tell, nobody broke into my building
| or mailbox. Then started they using them to change my address,
| etc. They got caught only when they created sub accounts and
| started transferring money.
| nonameiguess wrote:
| I've been called twice by my bank to warn me of possible
| fraudulent activity. Both times I hung up on them and called
| back at the bank's own public customer service line and asked
| them if that was really them calling. Once it was and once it
| was not, so I'm glad I was that careful.
| ricardobayes wrote:
| So they really had your money then?
| jillesvangurp wrote:
| The phone scammer, no. Just some idiot trying to get me to
| do stuff I should not be doing. Given how he conducted
| himself on the phone, he probably does not have a great
| conversion rate. People that do this are not exactly
| criminal master minds. But I guess some people get bullied
| into handing over their private keys, which I assume is
| what he was after. He clearly had some setup that auto
| dials numbers. After this, he apparently removed me from
| that list. So, tip: annoy the hell out of them and waste
| their time as much as you can when this happens to you.
| Putting him no speaker got a few giggles out of the team.
|
| The criminals that got into my account got too greedy. The
| bank's fraud detection system kicked in and rolled back the
| transactions. But at that point they had complete control
| over my account. Very scary. If they had been more subtle,
| they could have likely stolen quite a bit. So, also not
| criminal master minds probably.
| bitL wrote:
| I do that already. Prevented e.g. Hult MBA from pitching their
| exquisite high-end educational services...
| williesleg wrote:
| What do you expect? Passwords aren't security, they're a
| programming construct.
| polycaster wrote:
| I'm sure not to be the first one to point this out, but checking
| other people's emails is quite revealing. It's very much
| documenting in public which sort of websites about every person
| you know is visiting. Among them [1] "Baby Names", "Ashley
| Madison", "Adult FriendFinder", "diet.com". Want to profile your
| friends - there you are.
|
| I wonder if the benefits of haveibeenpwned outweights this.
|
| [1] https://haveibeenpwned.com/PwnedWebsites
| astura wrote:
| It's set up so that you have to prove you own the email address
| before knowing if you're included in "sensitive" breaches.
| moftz wrote:
| I did a lot of searching through the Ashley Madison dump back
| when it came out. It was pretty easy to find people living on
| my neighborhood that had accounts. They might not have done
| anything (it was just billing details after all) but any of
| that information could have easily been used to blackmail
| someone. There were also a whole bunch of people using .gov or
| .mil email addresses. Like if you are going to cheat on your
| wife, don't make it that easy for someone to realize that you
| can be exploited for government secrets.
| frb wrote:
| Funny that I never thought about this.
|
| Now I'm wondering how this actually plays with legislation such
| as CCPA or GDPR, as it is quite revealing even without the more
| delicate sites mentioned here.
| paranoidrobot wrote:
| Troy has covered this several times, but some sites, even
| showing in the PwnedWebsites list, are not viewable
| until/unless you confirm control of the email address or
| Domain.
|
| e: To be clear, the Ashley Madison, and Adult Friend Finder
| (both breaches) are denoted on the list as not being publicly
| searchable.
| nonameiguess wrote:
| I just checked myself and thankfully I've apparently only been
| in a few breaches, but of the ones listed, I only knowingly had
| accounts on LinkedIn and Dropbox. Nothing embarrassing because
| I'm smart enough to use burner accounts for embarrassing stuff,
| but I only even recognize last.fm and LuminPDF as services. I'm
| surprised last.fm still exists. I guess I might have signed up
| for it at some point and forgotten.
|
| My phone number isn't in here anywhere, so lucky me, but it
| doesn't make a difference. The State of Texas finally forced me
| to get a Texas driver's license in order to continue being able
| to vote, and the State of Texas sells your address and phone
| number to marketers once they have it, so my number is trash
| now anyway. 99 out of 100 texts and calls are either
| politicians or people claiming to want to buy one of my houses.
| I basically no longer use a phone except when my dad calls.
|
| I guess the plus side there is I'm somewhat immune from
| whatever location tracking can't be disabled since I don't even
| take my phone with me most of the time when I go anywhere, but
| that was an old habit from when I worked in a SCIF and couldn't
| bring a phone with me anyway.
| aboringusername wrote:
| Note to anyone that cares: Make your data as stale as possible:
| you can't change your address easily, sure. But you can recycle
| phone numbers (once a year, minimum). Change your credit/debit
| cards yearly (say to your bank you 'lost' it).
|
| When ordering online, always, always, always use a fake number,
| it's not required. Always use a fake name where possible. Sure,
| you need to provide that as a 'billing' address, but in some
| cases it stops other third parties getting that info (on eBay you
| can type a random name to ship to, I've had fun with this :) ).
|
| But lastly, LOL. Giving your data to facebook this is what you
| deserve, and for society accepting facebook as a standard part of
| life.
|
| When do we protest to delete the website?
| hnrodey wrote:
| >Change your credit/debit cards yearly (say to your bank you
| 'lost' it).
|
| Huge shoutout to/for privacy.com. Been using for over a year
| now and it's been a fantastic service.
| avh02 wrote:
| > When ordering online, always, always, always use a fake
| number, it's not required
|
| Until something's gone wrong in the process and they need to
| call you to clarify/fix it. (happens regularly to me due to
| address suffixes not propagating correctly through crappy
| systems)
| ricardobayes wrote:
| This is region dependent. In spanish speaking countries they
| pretty much never use email. Everyone - including the courier
| will just call you.
| baby wrote:
| I change my phone number every year and I get spam calls all
| the time.
| shmoogy wrote:
| > When ordering online, always, always, always use a fake
| number, it's not required
|
| Don't do this if you order anything that doesn't ship small
| parcel. The freight company may need to contact you and it will
| complicate matters and delay your final delivery.
| bshep wrote:
| I do something similar when a site asks for my birthday, i used
| to pick a random date, but sonce its sometimes used to reset
| password or asks u to confirm i just use the first of january
| of the year i was born so i can make sure i remember what i
| put.
| vharuck wrote:
| When birthdate is tied to an account, I pick a random one and
| store it alongside the username and password in KeePass. Same
| as the "security questions"; I make up and store nonsensical
| answers. E.g. "Q: What was your mother's maiden name?" "A:
| Blueberry pie."
| wussboy wrote:
| I do the same thing but use KeePass' password generator to
| create the answers. My mother's maiden name will be
| something like "diejdJyt7ejHsud"
| hiq wrote:
| I do that as well, but I dread the moment I'll have to
| call support through no fault of my own and they'll ask
| me for the answers to some of these questions.
| teachtwolearn wrote:
| Just say, "it's a jumble of letters and numbers but I
| lost the USB drive where I stored all that stuff."
|
| Most of these systems still use people who have quotas to
| meet, and can see all of your account details in some
| sort of admin panel.
| benlivengood wrote:
| I mean, probably anyone could call and start reading off
| the letters from "correcthorsebatterystaple" and the
| support tech will go "oh yeah, you're one of those people
| who thinks they're clever with security; here are all
| your account details"
| wasmitnetzen wrote:
| Doesn't that kinda negate the goal of using a fake birth
| date? After all, they don't really care whether you give your
| real birth date, it's enough that it is the same on that
| other website they get your personal information from to
| correlate.
| KMnO4 wrote:
| I don't care if someone leaks my fake DOB in a Dropbox hack
| and then tries to reset my Netflix password.
|
| Websites that use my real DOB are usually linked to my
| identity, so I'm much more concerned with protecting them
| from, eg social engineering attacks [0].
|
| [0]: https://gizmodo.com/how-i-lost-my-50-000-twitter-
| username-15...
| bshep wrote:
| Yes this is my thought as well.
| cjflog wrote:
| I have been pwned. Also of note, while my phone number was on my
| Facebook account, it has had its visibility set to "only me" for
| years. Still leaked.
| weird-eye-issue wrote:
| Not really surprising. That just sounds like a UI option. You
| realize they still have to store it right?
| rwmj wrote:
| I'm slightly surprised to find that my number has apparently
| _not_ been pwned, given the huge uptick in spam calls that I 've
| been receiving which seems to be coincident with the Facebook
| leak.
| breakingcups wrote:
| Not all phone numbers have finished uploading, check the blog
| post for details.
| fudged71 wrote:
| Cool. Facebook leaked my Canadian phone number. As if I didn't
| get enough spam calls already. Time to declare phone call
| bankruptcy?
| [deleted]
| 2Gkashmiri wrote:
| surprising that "Pakistan" isn't even on the list of countries.
| Anyone knows why?
| vladmiller wrote:
| I deleted my facebook account almost two years ago and my number
| still show up on the search... too bad GDPR does not spread on my
| country.
| riscy wrote:
| Has Facebook made any public comments about this breach yet?
| argv_empty wrote:
| https://about.fb.com/news/2018/04/restricting-data-access/
| MangoCoffee wrote:
| i've stop using FB for 10 yrs now. i just check my number. not
| pwned.
| jhoechtl wrote:
| What a great service to gather phone numbers even from those who
| haven't been pawned!
| diegoperini wrote:
| I trust Troy more than I trust Facebook. His incentives are
| aligned with staying honest.
| intrasight wrote:
| Honest question: Why would you give your phone number to FB?
| Related to their app perhaps (which I don't have)?
| newscracker wrote:
| Over the years, many people who were stuck in the Facebook
| platform have been coerced by Facebook into providing a phone
| number to "verify" their account. The other choice given to
| them was (and is) to lose access to the account because
| Facebook believes it's a fake account or a spam account or a
| "violation of its community policy".
|
| In other cases, Facebook may get the phone number because
| someone uploaded their address book/contacts to it. This
| information shouldn't be in the user's public/private profile
| (even though Facebook would store it internally, use it to
| figure out other connections and "show relevant ads").
| invalidusernam3 wrote:
| I haven't used facebook in years, but if I remember correctly
| it was part of your account verification in some cases.
| Black101 wrote:
| I don't know but I never gave my phone number to Facebook (but
| I also never used the app, only the website).
| adamrezich wrote:
| my Facebook account got hacked/stolen a few months ago (didn't
| notice since I hardly ever use it), and Facebook won't give me
| back access to it even after providing photo ID etc., citing
| coronavirus-related labor shortages or some such bullshit. but
| hey, at least now HIBP has the hacker's phone number instead of
| any of mine!
| adler0901 wrote:
| I'm supposed to go to a random website and enter my phone number?
| luplex wrote:
| It's not at all a random website. haveibeenpwned is renowned.
| Your phone number is not uploaded to the server, instead your
| browser asks for a whole range of (hashed) phone numbers and
| checks locally if yours was one of them.
|
| The process is spelled out here:
| https://haveibeenpwned.com/Privacy
| beervirus wrote:
| HIBP is indeed probably just fine, but I'm not sure how the
| phone number searching works. "There's no k-anonymity
| implementation for phone numbers at this point in time."
|
| https://www.troyhunt.com/the-facebook-phone-numbers-are-
| now-...
| sb636 wrote:
| I tried fully deleting my Facebook account multiple times about 5
| years ago. Each time, it became clear that my information was
| never leaving. Friends were still able to pull up my account. My
| credentials were still being recognized and allowing me to login
| to an account I was told was now nonexistent.
|
| Now I see my phone number was part of the breach. I am so fed up
| with Facebook.
| nikbackm wrote:
| I just logged in to Facebook for the first time in years to check
| the data it has on me. Luckily I never added my phone number or
| address, so should hopefully be in the clear.
| layoutIfNeeded wrote:
| Haha, no. It's enough if one of your friends/relatives/etc. had
| allowed Facebook/Instagram/WhatsApp/etc. to scan their contact
| list. Your phone number is in there, just not shown, trust me.
|
| In fact Facebook used to show creepy suggestions when such
| cross-pollination of data occured, like "Click here to confirm
| that XXXXXX is your phone number!", but they stopped doing that
| a few years ago.
| Macha wrote:
| Did you ever set up SMS 2fa? Did any of your contacts use the
| Facebook app to sync their contacts (at least at one point a
| default behaviour)? Then Facebook has your number. I remember
| when I still used it being promoted by a bar at the top of the
| web UI "Is this your number?" With my actual number suggesting
| I add it to my profile, so I know they have mine.
| vmception wrote:
| I've been intentionally breaking my social graph since at
| least 2012.
|
| Looks like its worked here.
|
| When I make a Facebook account, usually for my living
| complex's community or a bunch of Gen-Xer's doing a burning
| man thing, I use a new email or new phone number for signup
| and one time passwords.
|
| I don't let it get access to my contacts, assuming I
| inadvertently installed the Facebook app on a phone.
|
| Doesn't look like they meaningfully go deeper than that.
|
| I find the social graph to be very fungible, so if I really
| ever want to recreate it I can just add my phone number or
| give any app access to my contacts. This knowledge also lets
| me not be married to any of these services.
|
| I'm very content downloading the account data and then
| deleting the account.
| antegamisou wrote:
| I have had the exact same experience. Interestingly, it took
| them a few tries to get to my actual number and they still
| carried on throwing other random phone numbers I did not
| recognize.
| jtylr wrote:
| Despite using 2FA and listing my number on my profile -
| albeit restricted to "just me", I don't appear in the data.
| It's not as simple as they just having a record of it
| somewhere.
| Etheryte wrote:
| Likewise, it seems there's more nuance to this leak. I
| checked the data out and a large number of my contacts have
| correct numbers in it. At the same time, numerous people
| don't appear in it, even if they do have a phone number on
| their profile.
| wccrawford wrote:
| I'm in the same situation and very surprised. I've sat here
| wondering if I'm entering my numbers wrong, or if I'm
| really not in it. I've read the blog post and I'm entering
| the 1 in front of my 10 digits, because I'm in the USA.
|
| My wife's number isn't in there, either. I'm just really
| surprised, because I checked facebook the other day and it
| said I was searchable by email and phone number.
|
| I even searched my email address, and a lot of other
| breaches show, but not Facebook.
|
| I guess I got lucky?
| ricardobayes wrote:
| US numbers are not uploaded yet
| wccrawford wrote:
| Ah, that makes sense then. I assumed they were because
| the instructions showed the US style specifically.
|
| Thanks!
| freebuju wrote:
| Try creating a new facebook account today. The site won't let
| you do that without verifying a phone number. The difficulty
| level increases if you try doing so behind a vpn. Same goes for
| other SM sites like Twitter.
| mimimi31 wrote:
| I don't think that's true. I created a Facebook account a few
| weeks ago and a Twitter account just yesterday, both without
| needing a phone number.
| teddyh wrote:
| By all accounts, anyone can _create_ an account, but then
| the account invariably quickly gets suspended, requiring a
| phone number for "verification".
| durnygbur wrote:
| Don't they have a "real person" policy now? ie. not only
| phone number but as well a requirement to upload a passport
| style photo. Concidentally on entrance to US a camera makes a
| high resolution photo of every traveller during passport
| control.
| nonameiguess wrote:
| I believe they have always had this policy, though it
| wasn't particularly well enforced when they opened up the
| platform to all comers. I actually had a Facebook account
| before I even first got a mobile phone at all, back in 2004
| when you needed a .edu email address to sign up, which just
| meant they were delegating identity verification to the
| university. I think people were fairly comfortable with it
| back then because the only other users who could see you
| were people from the same school and it just mimicked the
| physical "facebook" that universities already published and
| made available to everyone with directory listings
| including your official photo and the phone number and room
| number of your dorm if you lived on campus. There was no
| open network. You could only even search for people from
| your own school.
|
| Obviously, the platform has radically changed since then,
| but they have gotten a lot of mileage out of the illusion
| that you could freely share what you wanted because the
| only people who were going to see it were people who
| already knew you anyway, which was at least somewhat true
| at first.
| durnygbur wrote:
| Every time Facebook/Gmail/Google/Amazon/LinkedIn/Tinder/whoever
| asks me to give them phone number "just in case" my first and
| only thought is "hell no". I haven't been wrong a single time.
| 0x_rs wrote:
| Let's not forget the notable case of Twitter "accidentally"
| using your provided phone number for advertising purposes [0],
| and to this day still banning you after registration if you
| refuse to give it.
|
| [0]. https://www.eff.org/deeplinks/2019/10/twitter-
| uninentionally...
| Nextgrid wrote:
| Facebook did this as well.
| [deleted]
| finiteseries wrote:
| I've been using Twitter to follow some people who don't have
| blogs etc since last May, and haven't been banned yet.
|
| Lots of likes, no RTs or posts though.
| sneak wrote:
| Twitter also had staff who leaked Twitter account PII from
| the Twitter DB to spies from the Saudi government, who have a
| habit of killing journalists from time to time.
|
| https://www.buzzfeednews.com/article/alexkantrowitz/how-
| saud...
|
| Collecting this data is an accident (or murder?) waiting to
| happen.
| officeplant wrote:
| Haven't given them my number on any of my twitter accounts.
| Where does this banning rumor come from?
| sevencolors wrote:
| I've been using a MySudo phone number to use for signups when
| I'm forced to give out one. Has reduced the noise i get in my
| messages for my real number
|
| https://mysudo.com
| sodality2 wrote:
| Are they not blocked for being VoIP?
| sevencolors wrote:
| I've only run into one instance where they wanted a real
| number. (Coinbase) I think sites only block those when
| there's a reason to.
| codedokode wrote:
| Sadly, many companies now require a phone number to use their
| services. For example: Signal, Telegram, Whatsapp, social
| networks like Instagram and Vk. They don't like anonymous
| users. For some users, Google requires a phone number to sign
| up. Twitter requires a phone number if they see something
| "suspicious" in user's behaviour.
| lupire wrote:
| It's crazy the a phone number is a secret. The problem isn't
| having the phone numbers; it's all the terrible systems that
| only work if phone numbers are secret.
| hrktb wrote:
| Phone numbers are not secret. These service ask for it mostly
| to be sure to get the right one (checking is expensive)
| and/or to have plausible deniability of your contentment when
| they abuse it later.
| ricardobayes wrote:
| Not to mention whatsapp is actually broken. It's bound to your
| phone number and can't change it. If you change SIM, your
| account is wiped. AND the worst: your contacts are not notified
| so if they send a message to the old number, it will just
| silently fail. Absolutely horrible. I never understood how
| whatsapp could be phone-number bound and not account bound like
| everything else out there.
| hnick wrote:
| I feel like saying "after you!". What's that Google? No phone
| number? Oh...
| chrischen wrote:
| I'm so confused. I intentionally refused to give my phone number
| to facebook and it is not set in my profile, yet my number was
| pwned in this facebook breach. Is FB associating or storing my
| number without permission? I have a different number set for
| 2-factor and amazingly it was not pwned!
| coatmatter wrote:
| I think you may have allowed Facebook to allow other Facebook
| users to search for your profile via your number. Can you check
| my earlier comment at
| https://news.ycombinator.com/item?id=26712835 and let us know
| whether or not this is/was the case?
|
| > "Facebook Settings > Privacy > How people can find and
| contact you > Who can look you up using the phone number you
| provided?"
|
| Is/was it set to "Everyone"?
| chrischen wrote:
| Yes, but my number is not set to the one that was pwned!
| ClearAndPresent wrote:
| Troy says: " At the time of publishing this blog post, all phone
| numbers beginning with international codes 4, 6, 8 and 8 have
| completed loading."
|
| Interestingly, several cellphone numbers I know to be present in
| one set of leak data which start with international code 4 are
| not detected by HaveIBeenPwned.
| notyourday wrote:
| This is very strange. I definitely have a phone number associated
| with a facebook account because at some point in the past I used
| FB 2FA. I have not deleted that number. I have tried it in
| several different formats, including + country code, leading
| country code, with and without dashes and I am getting "Good
| news" message.
| Madzen__ wrote:
| Considering Facebook has ~2.7 billion users and this breach
| only contains 533million there are many people not in it.
|
| Troy also mentioned not having processed all numbers yet
| aswell, but you could check the dump yourself. Downloading
| country spesific dumps does not take a long time.
| floatingatoll wrote:
| If your phone number begins with 40% of the digits 0-9, then
| you'll have a chance to find it on the site.
|
| Please review the footnote of the post, just above the comments,
| before assuming that your HIBP negative result is valid.
| devgoldm wrote:
| Found my number on there too even though I've deleted Facebook
| for at least 5 or 6 years now -_- Not sure when I gave them my
| number either, I hope it wasn't scraped from someone else's
| contact list... At least it makes sense why I received a bunch of
| spam calls over the weekend.
|
| Anyway it's probably good practice to recycle your number every
| few years, and not use it for 2FA to make switching numbers a lot
| easier. Who knows what services I'll be locked out of once I
| change, let's hope not too many.
| hnrodey wrote:
| I've had the same phone number for somewhere around 17 years. I
| kept this number even as I moved across the country (US).
| Cd00d wrote:
| I thought this was the norm. I've had the same number for 20
| years now, though have moved through many different area
| codes since. But, I must be the odd one, because I get asked
| regularly why I have the area code I do, and the answer
| "because that's where I was living in 2001" doesn't seem
| satisfactory.
| lupire wrote:
| > At least it makes sense why I received a bunch of spam calls
| over the weekend.
|
| Really?
|
| Every phone number is already known to anyone who wants to get
| it.
| scrose wrote:
| I can't imagine telling everyone I know that I'm changing my
| number every couple years, and I'm not even calling/messaging a
| lot of people nowadays. I have a family member who did
| something similar(not on purpose) and I still have 3 of her
| numbers and still get confused which is the working one.
| 52-6F-62 wrote:
| I had a company phone about 6 or 7 years ago for a company I
| worked for at the time. When I was on my way out they
| unilaterally revoked my company-provided cellphone after
| convincing me I should get rid of my old private number for
| theirs.
|
| I'll never do that again. It happened shortly after ditching
| social media and I just about all of my contact info and I
| haven't been in touch with some old friends because of that
| since then.
|
| Even if you had the time to transfer your contacts, etc,
| something will inevitably get missed.
|
| Hell, I've updated family and friends to an email address
| I've been using for closer to a decade and they still email
| the old one...
| devgoldm wrote:
| I know exactly what you mean, there's only so many times you
| can append "New" on the end of a contact name!
|
| A good chunk of people will probably communicate mostly on
| platforms like WhatsApp/Telegram/Discord/whatever that don't
| need numbers at all or facilitate switching of numbers
| without your contacts having to do anything. I don't think
| that will constitute anywhere near the majority of people
| across the world though, switching numbers will definitely be
| a pain for most.
| rsync wrote:
| "Anyway it's probably good practice to recycle your number
| every few years, and not use it for 2FA to make switching
| numbers a lot easier."
|
| Ironically Twilio of all places forced SMS 2FA on all accounts
| earlier this year.
|
| As in, one day you could no longer log into your twilio account
| without giving them a phone number. You are locked out until
| you do.
|
| Ironic in a few ways ...
|
| First, twilio numbers are _not_ mobile numbers - they are voip
| numbers - and cannot be used for most 2FA authentication
| services because they cannot receive messages from short codes.
| So it 's ironic that twilio forces you to use a non-twilio
| number for their 2FA.
|
| Second, many twilio use-cases (like mine) involve building a
| twilio infrastructure to replace my existing phones/numbers ...
| and now that is broken from the bottom up because I have to use
| a mobile phone with a fixed provider just to use twilio.
|
| The bottom line is: none of this is for me or my safety and
| security. Twilio has a spam problem and that spam problem is
| very hard to solve. Forced pairings of physical phones and SIM
| cards is just a desperate way to throw sand in those gears to
| slow it down a little bit.
| QUFB wrote:
| I have had a Twilio account for years, and have always used
| the proprietary MFA implementation from their Authy app. I
| don't remember being forced to switch to SMS MFA.
| glitcher wrote:
| In my limited experience, I've had more phone spam plus wrong
| number calls right after changing phone numbers due to the
| number being recycled.
| ada1981 wrote:
| I was pwned.
| edf13 wrote:
| Interestingly www.TroyHunt.com is blocked by Quad9 DNS!
| coatmatter wrote:
| Fixed now.
| yosito wrote:
| A note for people with US numbers who aren't finding their info:
|
| > And finally, one last note on the data load process: At the
| time of publishing this blog post, all phone numbers beginning
| with international codes 4, 6, 8 and 8 have completed loading.
| The other codes are in progress and may take several hours more
| before they're searchable.
|
| US numbers begin with international code 1, and it seems that
| they aren't yet searchable.
|
| I was surprised that mine hadn't come up, since I've had a few
| Facebook accounts over the years with my phone number, and this
| explains it.
| nohuck13 wrote:
| Thanks.
|
| For anybody getting a miss and wondering if they messed up the
| formatting, my US number is coming up now, formatted with a
| vanilla +1-123-456-7890.
| heleninboodler wrote:
| My US number also came up when entered as 12345678901
| (1-prefixed but with no extra formatting or chars)
| [deleted]
| untouchable wrote:
| According to the edit at the bottom of the post, "1" is now
| complete.
| PostThisTooFast wrote:
| You gave a real phone number to Facebook?
|
| Egads.
| harmeswoul12 wrote:
| The data would have been either from abuse of API's by third
| party apps or find your friend. From the dataset, it seems to be
| exclusively limited to the data immediately viewable on your
| profile, hence the reason so few emails appeared in this leak.
| [deleted]
| [deleted]
| rpaddock wrote:
| After my wife's suicide (See the documentary Pain Warriors) I
| took over Karen's FB account as my own, and I changed the name on
| the account. Long before this breach I have been getting SMS Spam
| addressing me as Karen, on a number that did not exist when she
| was alive.
|
| FB data can be the only possible source of that spam.
|
| The spam is always trying to sell male enhancement products to
| 'Karen'. Anyone know how to stop this SMS spam crap?
| magsnus wrote:
| Sorry for your loss. Right now I'm pretty happy that I scrubbed
| all information of my FB account months ago. If only people
| could stop using messenger so I could delete it.
|
| But I have a similar, but unrelated to FB, problem in that
| every month I get an offer to work as a nurse in Norway from
| different agencies. I figured they scraped some "find the
| number"-site here in Sweden long ago and since my mothers name
| was on my bill I guess my number somehow came up under her
| name.
|
| It's been annoying for years but since my mother had a some
| (non-corona) medical problems last year it has been downright
| infuriating at times. Anyone know how to make it stop when
| there is a bunch of different agencies messaging you?
| gmargari wrote:
| Would you mind elaborating on how you "scrubbed" information
| from your fb account? It's been years since I closed my
| account but I know (e.g. see this article) this is not
| enough, so I consider reenabling it only to delete all my
| info, and then finally (?) deleting it.
| magsnus wrote:
| I deleted everything, going through every page and my whole
| timeline etc pressing delete on everything. I considered
| changing my number etc. to nonsense and wait a week and the
| delete it but I figured facebook are probably versioning
| that stuff anyway.
|
| Right now my profile picture is a plastic duck, there are
| no photos and no information apart from my name and my
| throwaway-email adress (which I hope is hidden from the
| world via settings).
|
| There is also a "privacy page" there where you can check
| what information they have saved about you and if you
| forgot to delete something. I would probably have done it
| this way first if I where to delete my FB-account but for
| now I need messenger.
|
| If you are running firefox you should also install
| "facebook container" even if you don't have an account. :)
| darcien wrote:
| My deepest condolences.
|
| I think it's pretty hard to stop incoming spam when the number
| itself has been made public.
|
| The only options I know would be: a. Play whack and mole,
| report the number to the authority in your country that handles
| this kind of spam activity. b. Use some kind of mobile
| application that filter out the spam SMS. This one is kinda hit
| and miss, since the number data is coming from community
| reports, so some spam might pass the filter. And there might be
| some false positives from the spam filter.
|
| I also would like to hear if there's alternative solution for
| this problem, other than changing the phone number itself.
| atlanta90210 wrote:
| Very sorry for your loss and thank you for sharing.
| legohead wrote:
| If you are in the US you can register at donotcall.gov
|
| It's not perfect, but it has had an impact on the amount of
| spam I receive.
| ct0 wrote:
| My phone has an option called Do Not Disturb mode. I have set a
| schedule to turn it on everyday from 12AM to 11:59PM. What Do
| Not Disturb will do is block (silence the notification or
| ringer) every message or call from someone that is not in your
| phone book. While unfortunately you'll still get the spam SMS,
| but you wont get the alert.
|
| The only way I can see striking back at these spam calls is to
| pick up the call and waste their time, because its expensive.
| Also if I pick up that means someone else is not getting
| scammed. I try to get as far along in the scam process as
| possible.
| officeplant wrote:
| I enjoy the pixel line of phones having google assistant
| answer spam calls for me. Sometimes its fun to watch the
| conversation they attempt to have with the assistant.
| GoblinSlayer wrote:
| At least here human operators apparently are paid for call
| duration and they will prolong the call up to 15 minutes and
| you don't need to say anything.
| mdp2021 wrote:
| If you only mean "how not to be bothered" (instead of radical
| actual solutions of legal nature etc.), and the sender is a
| recurring number, very probably your phone OS has an option to
| reject calls and/or messages from specific numbers.
| input_sh wrote:
| There was a spammer that bothered me, I blocked the number,
| and started receiving spam from adjacent ones (same number,
| just the last digit increasing by 1). Had to block 5-6 for
| them to go away.
| hypertele-Xii wrote:
| Can I sue Facebook for leaking my number? Serious question.
| kube-system wrote:
| What damages have you incurred?
| bogwog wrote:
| Identity theft most likely, and the consequences arising from
| that.
| kube-system wrote:
| What is the monetary amount, and do you have evidence of
| the theft?
| bogwog wrote:
| I'm speaking hypothetically of course, I haven't actually
| been affected by this leak (so far).
|
| But that doesn't seem hard to prove at all. At the very
| least, you could claim that Facebook's leak forced you to
| pay for identity theft protection/monitoring as a very
| reasonable precaution, and whatever that cost you would
| be the damages.
|
| Then of course there's the possibility that someone did
| actually steal your identity and used it to drain money
| from your accounts, or simply caused you to waste a bunch
| of time hunting down for example fake accounts opened
| using your information, credit cards, etc.
|
| And I'm not a lawyer, but I'm pretty sure somewhere in
| all this fuckupery you can throw in some punitive
| damages.
| VBprogrammer wrote:
| I have noticed an uptick in the number of scam calls and texts
| I've been receiving over the last few days. No surprise that my
| number was included in this dataset.
| nixass wrote:
| Is it just me or... why do people even share their phone number
| with Facebook? What did you use it for? It wasn't mandatory or
| anything. Why the Pikachu faces?
| fishbacon wrote:
| It is very convenient for your friends/family to be able to get
| your phone number from your facebook profile.
|
| I have used it a few times to contact people for whom immediate
| contact was preferable to facebook post/message.
| inetknght wrote:
| Your comment is disingenuous. Facebook has been around for
| nearly two decades. There's plenty of time there for people to
| make mistakes and _try_ to fix them. Unfortunately they 're
| competing with their contacts who re-add those same mistakes
| and also competing with Facebook's own incentives to not delete
| data.
|
| It'll be fun if/when any of these numbers can prove they
| requested Facebook to delete their data under GDPR.
| rwmj wrote:
| I believe their app uploads the address books of other people
| and those address books might contain your phone number and
| other details.
| astura wrote:
| My number is on my profile, so that my friends can contact me
| shall they lose my number. Less important now that messenger
| exists and we can access it any time, but I put it there before
| it existed. It's come in handy in the past.
|
| I also don't consider my phone number "sensitive" information I
| want to keep secret - it's already quasi-public and something I
| give out when I want people to be able to contact me.
|
| I grew up looking people up in the physical phone book when I
| lost their number, fwiw.
| wyldfire wrote:
| Many companies present you with the opportunity to "Protect
| Your Account" with SMS, and for that protection they 'just'
| need your phone number.
|
| Turns out the phone number is the best unique identifier and is
| the perfect key for joining up lots of disparate sources of
| data. It's the kind of thing that you could either sell
| directly or use as an index to determine things like your
| estimated income.
|
| It wouldn't surprise me if Facebook has had multiple technical
| methods for devising/stealing and disingenuous "protect your
| account" campaigns for willingly turning over users phone
| numbers.
| javagram wrote:
| I have my phone number and mailing address on my Facebook, set
| to friends only.
|
| Why not? When I grew up, we had a phone book listing everyone's
| name and address and phone number so you could find them to
| contact.
|
| I consider all of this essentially public information and would
| rather make it easier for people I know to contact me. If it
| gets lost in a breach, whatever. I already get plenty of junk
| mail because I give to charities and they sell my address.
| nonameiguess wrote:
| In addition to other reasons already given, I'm not sure if
| this is still the case because I haven't used Facebook in a
| while, but back in the day, the only options for 2FA were code
| generator in the Facebook app itself or SMS. So if you didn't
| want to have the Facebook app on your phone, giving them a
| phone number was the only way to enable 2FA.
___________________________________________________________________
(page generated 2021-04-06 23:01 UTC)