[HN Gopher] The Facebook phone numbers are now searchable in Hav...
       ___________________________________________________________________
        
       The Facebook phone numbers are now searchable in Have I Been Pwned
        
       Author : helb
       Score  : 493 points
       Date   : 2021-04-06 09:29 UTC (13 hours ago)
        
 (HTM) web link (www.troyhunt.com)
 (TXT) w3m dump (www.troyhunt.com)
        
       | coatmatter wrote:
       | Non-technical speculation, but based on my own experience as an
       | ordinary Facebook user:
       | 
       | I'm increasingly confident that this breach/leak has come about
       | mostly through the privacy _search_ setting (buried in Facebook
       | 's privacy settings -
       | https://www.facebook.com/settings?tab=privacy -) which allows
       | "Everyone" to search for a number in order to find your profile
       | if so enabled.
       | 
       | This is a bit like an option that PayID/Osko (instant bank
       | transfers) in Australia allows - one could bash through random
       | mobile numbers and discover more information than just the
       | number. I've always found this option to be creepy because I
       | don't people who might otherwise have my phone number
       | legitimately to be able to facestalk me.
       | 
       | Please note that this is separate to displaying contact info
       | publicly on one's profile page - yes, there is a dizzying array
       | of different privacy settings on Facebook. Would Mark Zuckerberg
       | provide have ever displayed his phone number publicly? I doubt
       | it. But would he have allowed others who already have his phone
       | number to search for him on Facebook? I'd say almost certainly
       | yes.
       | 
       | I used to use Facebook more than I like to admit and I have
       | provided my phone number to Facebook in the past, yet have
       | managed to avoid being in this breach, whereas some people I know
       | are in the data set. This means I'm quite sure that I'm not
       | returning false negatives with the search.
        
         | hendersoon wrote:
         | Only ~32m of ~190m US FB accounts were in this breach, so it's
         | not surprising if you live in that country and are not in the
         | breach.
        
           | ehsankia wrote:
           | Looking at the full breakdown [0], a bunch of middle eastern
           | countries have near 100% breach. It seems like they were the
           | target, and all the other countries were just collateral
           | damage maybe? Canada, US, UK, all sitting around 10-20%.
           | 
           | [0] https://datastudio.google.com/u/0/reporting/afa08373-621e
           | -4e...
        
           | coatmatter wrote:
           | This statistic isn't applicable to me.
        
       | fatnoah wrote:
       | I guess the good news is that I still have identity monitoring
       | from that time where the federal government gave up my
       | information, including SSN, phone numbers, finger and toe prints,
       | etc.
        
       | xibalba wrote:
       | I've been pwned. Is it known when this breach occurred? I have
       | seen a huge spike in spam calls over the last 3-4 months and now
       | I'm wondering if it was bc of this breach.
        
       | teddyh wrote:
       | Links to the actual data (allegedly):
       | https://pastebin.com/sq7UDyVb
        
         | gmargari wrote:
         | Thanks, I did a quick hack to find my Google contacts in leak
         | file, so I can inform them:
         | https://gist.github.com/gmargari/95976c58d2ef0c05cc1f03fc023...
        
         | jaywalk wrote:
         | Thanks, I was looking for that. Aside from linking my name to
         | my cell phone number (which I really can't even assume is
         | private anymore) there's nothing private in there for me.
        
         | J_tt wrote:
         | Seems to be missing Australia, I was curious to see what data
         | had been leaked about me, since it seems to vary significantly.
        
           | coatmatter wrote:
           | This set is missing Australia yes, but not the other set Troy
           | Hunt was sent - he covers this in his blog post and tweets.
           | There are at least two sets floating around. The ones loaded
           | into HIBP do contain Australian numbers - I've checked.
        
       | Sommer wrote:
       | One other attack vector with this data that I've not seen much
       | chatter about is that the phone numbers (and other leaked data)
       | are sufficient to create a Facebook Custom Audience and directly
       | target the associated people with ads. Cross referencing these
       | numbers (or pivot through names) with any external data source
       | and you've got the capability to target specific voters, for
       | example. Facebook made a lot of changes [eventually] to their
       | Custom Audience abilities via user ID as a result of the
       | Cambridge Analytica scandal, this leak makes it not too
       | dissimilar in terms of how you could at least segment and direct
       | target ads.
        
       | HenryBemis wrote:
       | I searched my number(s), no hits. I did a +/- a few numbers, and
       | there is a hit. The message is though: "Oh no -- pwned!"
       | 
       | The only information exposed to me is that the person with that
       | number, has a FB profile. If I am to trust FB (which I don't -
       | for nothing) is that FB has this person's number and lost it. I
       | place no reliance to anything that FB states. For all I know that
       | person is a WhatsApp user and the FB branch 'stole' the number
       | and added that to their FB account (yes, I know this is not how
       | data works, but this is how FB works).
       | 
       | (semi-rant follows - apologies)
       | 
       | There is a mention of 2FA/MFA in another comment. I wouldn't be
       | surprised if FB already has a 'super profile', where all data by
       | FB-WA-IG are merged. I believe that would be a nightmare to do,
       | but hey, FB is good at nightmares.
       | 
       | Edit: I feel this is a semi "Ashley Madison" moment. People who
       | have a 'secret' FB profile may get busted by their BFs/GFs.
        
       | samerjj wrote:
       | As a Syrian who have used many throw-away accounts on FB, this is
       | a life or death matter for many of us. I'm sure the Syrian regime
       | will use this information to track activists. I have checked and
       | there are 7 million leaked accounts from Syria, probably covers
       | everyone who uses Facebook in the country. Facebook made it
       | mandatory to provide the phone number and now that this is
       | leaked, they bear the moral responsibility for all the people who
       | will be affected by this.
        
       | indigowind wrote:
       | What's the legal recourse for users who have had their numbers
       | leaked? Any group action possible?
       | 
       | Could the US or EU fine them as well?
        
       | benaadams wrote:
       | > "One last note on the data load process: At the time of
       | publishing this blog post, all phone numbers beginning with
       | international codes 4, 6, 8 and 9 have completed loading. The
       | other codes are in progress and may take several hours more
       | before they're searchable."
       | 
       | https://twitter.com/troyhunt/status/1379366099544797189
        
         | woko wrote:
         | Thanks, because the end of the blog post mentions 8 instead of
         | 9:
         | 
         | > At the time of publishing this blog post, all phone numbers
         | beginning with international codes 4, 6, 8 and 8 have completed
         | loading. The other codes are in progress and may take several
         | hours more before they're searchable.
         | 
         | So I was like: what about another 8?
         | 
         | Edit: Actually, it is "4, 6, 7 and 8"! cf.
         | https://twitter.com/troyhunt/status/1379377818618884098
        
       | IG_Semmelweiss wrote:
       | Curious if anyone had success in avoiding this, by inserting a
       | fake number in their FB profile.
        
       | drcongo wrote:
       | I'm completely unsurprised that my phone number is in there
       | despite the fact that I deleted and closed my account 10 years
       | ago.
        
         | shnp wrote:
         | I deleted my phone number around mid-2018 and it's also part of
         | the leak tying the phone number to my name and gender
         | 
         | https://news.ycombinator.com/item?id=26708923
        
           | hendersoon wrote:
           | We don't know exactly when the data was exfiltrated, just
           | that it ended in early 2019. It could have been taken at any
           | point before that time.
        
             | sm4rk0 wrote:
             | Earliest date in one of the columns (last login?) is
             | something around 2019-04-28.
        
             | shnp wrote:
             | Yeah it could be, will have to wait for more details first.
             | 
             | I would not be surprised if FB kept that phone number with
             | a "deleted" flag to this day though.
        
           | milofeynman wrote:
           | Similar experience. Class action?
        
         | Crontab wrote:
         | Couldn't it be there from someone who knows you? I was under
         | the impression that Facebook grabbed people's contacts list on
         | mobile apps.
        
           | comeonseriously wrote:
           | So, that begs the question: If _my_ phone number is in
           | someone _else's_ contacts, is it still _my_ phone number?
        
             | hnick wrote:
             | It is still PII which sometimes has specific laws and rules
             | around its use depending on where you are.
             | 
             | If I give someone's social security number to a company
             | that doesn't mean they can publish it on the front page
             | just because the person it belongs to didn't hand it over.
        
             | ghaff wrote:
             | It's your phone number (or possibly also the phone number
             | of the person who had it before you) but, like images of
             | yourself, they're probably in tons of places that you don't
             | control and never will.
        
           | davidjohnstone wrote:
           | My understanding is that all numbers in the dump correspond
           | with Facebook accounts, so this shouldn't be the reason.
           | 
           | Another option would be that someone else has that number
           | listed for their account. Has Facebook always required
           | confirmation that a number is valid? I saw one my friends'
           | numbers in the data except the account had a different name.
        
         | HatchedLake721 wrote:
         | Did you deactivate or delete your facebook account?
         | 
         | As I understand, deactivation is temporary, deletion erases all
         | data.
         | 
         | But if people did delete their accounts and Facebook didn't
         | erase the private data, aren't there consequences to this?
        
           | drcongo wrote:
           | Full delete. I was very careful about it at the time.
        
           | arcturus17 wrote:
           | > As I understand, deactivation is temporary, deletion erases
           | all data
           | 
           | That's the problem, what we or regulators understand may well
           | be very different to what actually happens
           | 
           | > aren't there consequences to this
           | 
           | A slap on the wrist at best, I'd bet my house on it
        
             | snarfy wrote:
             | 'Erases' all data, or sets the is_deleted flag.
        
         | 2muchcoffeeman wrote:
         | I got a bunch of spam phone calls today.
        
         | gruez wrote:
         | My experience is completely opposite to yours. I have a
         | facebook account, phone number added and verified, profile
         | privacy set to "friends only", but I can't find myself in the
         | leaks.
        
           | scrollaway wrote:
           | My understanding of the dump is that it was scraped, thus
           | it's non exhaustive by nature. There's only half a billion
           | accounts in it after all, and Facebook has far more.
        
         | nerbert wrote:
         | If you're a EU citizen contact your local data protection
         | authority and file a complaint. It literally takes 5 minutes.
        
           | Nextgrid wrote:
           | And Facebook will promptly ignore _that_ too:
           | https://ruben.verborgh.org/facebook/
        
             | lupire wrote:
             | 1. That article is about downloading, not deleting.
             | 
             | 2. You don't negotiate with Facebook, you norify the
             | regulators so they can asses another billion-euro fine.
        
               | zoobab wrote:
               | How much money can you get as damages?
               | 
               | Answer under the GDPR is probably: 0EUR.
        
               | [deleted]
        
           | verytrivial wrote:
           | (/verytrivial cries in Brexitish ...)
        
             | jeroenhd wrote:
             | The UK hasn't abolished their implementation of the GDPR
             | (yet?) so you should still be to file a complaint with the
             | ICO (AFAIK; IANAL).
        
           | eru wrote:
           | I'm not sure citizenship is required?
        
           | [deleted]
        
           | dgellow wrote:
           | Relevant links.
           | 
           | "What should I do if I think that my personal data protection
           | rights haven't been respected? "
           | 
           | https://ec.europa.eu/info/law/law-topic/data-
           | protection/refo...
           | 
           | "European Data Protection Board Members"
           | 
           | https://edpb.europa.eu/about-edpb/board/members_en
        
             | divbzero wrote:
             | Yes, please do this if you are protected by European
             | regulations.
             | 
             | I also wish we could do more to put pressure on Facebook
             | and other bad players. Can't help thinking this is viewed
             | internally as just more work for the legal department
             | followed by an X billion euro "cost of doing business" fine
             | after so many years.
        
         | insiderreporter wrote:
         | Mark Zuckerberg's phone number is there too.
        
         | deepstack wrote:
         | Yeah these companies that rely on user data will NEVER delete
         | your data once you submit it to them (regardless if they say
         | your data is deleted or account closed). For company like FB
         | you are the product.
        
           | rorykoehler wrote:
           | Data leaks like this are positive in that regard because we
           | can prove they haven't complied with GDPR quite easily if our
           | deleted data comes up.
        
       | pedrocr wrote:
       | One thing I didn't find on the website was a way to get an email
       | with the actual data that was leaked so I can evaluate what's at
       | stake. Showing it online would be poor privacy but sending it to
       | the email should solve that.
       | 
       | Some of the leaks are from companies I don't even know, that work
       | behind the scenes aggregating information. Particularly for those
       | I'd like to see what was leaked. For the services I actually used
       | directly I have a clearer idea.
        
       | jaypeg25 wrote:
       | I permanently deleted my Facebook account September 2019. My
       | phone number was included in this data breach, which was
       | apparently August 2019. So close. If only I got rid of it sooner.
        
       | Tenoke wrote:
       | Oddly enough even my email doesn't show up for the Facebook
       | breach (possibly because I never added a number on Facebook, just
       | whatsapp).
       | 
       | It does show up for companies I've trusted more though - Dropbox,
       | Linux Mint, XKCD (md5 really?), Forbes, etc.
        
       | KMnO4 wrote:
       | Hm, I already know phone number is leaked, but searching for it
       | (XXXxxxXXXX) doesn't work.
       | 
       | Once I prepended Canada's country code: (1XXXxxxXXXX) it worked.
       | 
       | Maybe this can be fixed with some simple communication? Ie "No
       | result --- ensure you enter your full phone number including
       | country code"
        
         | ricardobayes wrote:
         | how do you know it was leaked? got spam?
        
       | tartoran wrote:
       | I searched the database and haven't been pawned but of course I
       | know why, I never shared my phone number with FB and this
       | confirms my idea that sharing anything with FB is a terrible
       | idea, even the real name with correct spelling can cause issues.
       | I urge everyone who wants to still hold a social media account to
       | add an alternative spelling for their name. When info leaks or
       | one gets unsolicited messages of any kind out it becomes very
       | easy to backtrack to which social media account the leak is
       | coming from. Perhaps one more reason (from the many) to disable
       | that account.
        
         | Maxburn wrote:
         | This is excellent advice. Years ago I had a misspelling of my
         | name on my drivers license. Very easy to find the source of all
         | my junk mail after that!
        
       | uyt wrote:
       | The previous thread had an amazing trick that worked for me:
       | https://news.ycombinator.com/item?id=26682325
       | 
       | tl;dr; search your real phone number but exclude consecutive
       | numbers to filter out auto-generated pages:
       | "(212)555-1239" -1240 -1238
       | 
       | Using this I was able to find all my info (and much more) on
       | sites like: https://www.fastpeoplesearch.com/
       | 
       | I expect many of these "people search" sites to link to your fb
       | profile soon using this breach.
       | 
       | I expect the more sophisticated ones to crawl all your social
       | media accounts (twitter, chat apps, etc) by abusing the reverse
       | look up using your phone number.
        
       | beervirus wrote:
       | > Facebook: In April 2021, a large data set of over 500 million
       | Facebook users was made freely available for download.
       | Encompassing approximately 20% of Facebook's subscribers, the
       | data was allegedly obtained by exploiting a vulnerability
       | Facebook advises they rectified in August 2019. The primary value
       | of the data is the association of phone numbers to identities;
       | whilst each record included phone, only 2.5 million contained an
       | email address. Most records contained names and genders with many
       | also including dates of birth, location, relationship status and
       | employer.
       | 
       | > Compromised data: Dates of birth, Email addresses, Employers,
       | Genders, Geographic locations, Names, Phone numbers, Relationship
       | statuses
       | 
       | This is annoying, but I just can't get too worked up about it. I
       | assume that anything I tell Facebook is already more or less
       | public.
        
       | cwhiz wrote:
       | Getting to the point where we're going to need phone, email, and
       | SMS to be deny all by default. Can't reach me unless you're
       | information is already in my contacts.
        
         | mcculley wrote:
         | I get a lot of value out of being reachable by people I do not
         | yet know.
        
           | gh123man wrote:
           | As do I. This is a difficult problem to solve especially as
           | the signal to noise becomes worse as abuse becomes more
           | common.
           | 
           | Ive had to wildcard block my area code (since I don't live
           | there anymore) which captures 95% of my daily spam calls -
           | but people can still leave a message to break through my wall
           | if it's truly urgent. I don't see how this could work with
           | SMS.
           | 
           | Even message requests on facebook/messenger have problems
           | where you are unlikely to even see the request unless you
           | check regularly.
        
           | cwhiz wrote:
           | No one said it had to be by force.
        
             | mcculley wrote:
             | Maybe I misunderstood your use of the "we" in "we're".
        
           | sethammons wrote:
           | I found a novel solution by accident to this. I moved to a
           | new area but kept my old number. 99% of my spam calls are
           | from my phone's area code. If you are not a contact and a
           | number comes up from that area code, it is spam. If it is my
           | new area code, it is a person or business trying to reach me.
           | 
           | You could likely get a far off area coded number.
        
             | derwiki wrote:
             | Yea ignoring unknown numbers from my home state is fairly
             | effective at blocking spam calls.
        
             | acheron wrote:
             | Same (though "I moved to a new area" happened in 2004). At
             | this point I've just blocked the entire old area code and
             | neighboring ones, aside from existing contacts.
        
           | panzagl wrote:
           | Found the guy who bought the extended warranty for his car
        
             | mcculley wrote:
             | No, I have never bought an extended warranty. However, I
             | did today make good money on a business transaction because
             | a stranger was able to reach me.
        
         | baby wrote:
         | I already don't accept any calls. The robocall stuff in the US
         | is out of control.
        
         | 3pt14159 wrote:
         | It's a hard problem to crack. Some legitimate places need to be
         | able to call you without you knowing them ahead of time. Say
         | your sibling was mugged in Mexico and the local little police
         | station let them borrow the landline to call the only number
         | they still remember without having to check their contacts in
         | their phone. Are you not going to pick up?
         | 
         | There are a lot of these little edge-cases. Journalists,
         | lawyers representing class action suits, government id
         | expiring, and so on.
        
           | coldpie wrote:
           | I'm in my 30s and I can't think of a single time I have ever
           | received a phone call that I didn't expect. I get several
           | spam calls every day. I would make the trade (and recently
           | have, I block all unknown numbers now).
        
             | reaperducer wrote:
             | _I 'm in my 30s and I can't think of a single time I have
             | ever received a phone call that I didn't expect._
             | 
             | I've read that people not answering their phones is the
             | number one reason that COVID contact tracing doesn't work.
             | 
             | But your comment makes me think that you've never had food
             | delivered. Never used an Uber. Never owned a business.
             | Never bought or sold real estate. Never rented a place to
             | live. Never went to a restaurant with a wait list. Never
             | done a lot of things that are perfectly ordinary, and
             | require allowing people to contact you when they have
             | questions.
        
               | nonameiguess wrote:
               | Most delivery services with an app have messaging built-
               | in so you don't need to rely on calls, but I also know
               | when I'm expecting a delivery or a driver to pick me up,
               | and if an unknown call comes from my area code (the one
               | I'm actually in, not the one my phone number is in), I'll
               | answer that. It's pretty easy to distinguish between
               | times I might expect a call and all other times.
               | 
               | For all those other things, though, I'm not sure why you
               | need to answer unknown numbers. I've never owned my own
               | business, but did manage a small business and we had
               | dedicated business lines. No one needed to call my
               | personal phone. For buying and selling real estate, there
               | are agents that act as go-betweens and you can put their
               | number on your contacts list. For renting, put the
               | management company on your contacts list.
        
               | reaperducer wrote:
               | _Most delivery services with an app have messaging built-
               | in so you don 't need to rely on calls_
               | 
               | I've used dozens and dozens of delivery companies over
               | the years, and the only delivery company I've found that
               | doesn't have its people calling on phones is DoorDash,
               | and even that uses SMS. Plus, most of the best places
               | don't use services, they have their own people.
               | 
               |  _we had dedicated business lines_
               | 
               | Doesn't help you when someone needs to contact you in an
               | emergency, like the alarm company, or the landlord, or
               | security, or the police, thousand other things.
               | 
               |  _For buying and selling real estate, there are agents
               | that act as go-betweens and you can put their number on
               | your contacts list._
               | 
               | Sounds good in theory, but doesn't work in practice.
               | There can be dozens and dozens of people and companies
               | involved in such a transaction, and you can't predict who
               | they all are.
               | 
               |  _For renting, put the management company on your
               | contacts list._
               | 
               | When the management company sends a vendor over to fix
               | something, you don't know what number they'll call from.
               | 
               | To "never" get an unexpected, important call sounds like
               | a side effect of a quiet life. I envy you.
        
           | benlivengood wrote:
           | > Say your sibling was mugged in Mexico and the local little
           | police station let them borrow the landline to call the only
           | number they still remember without having to check their
           | contacts in their phone. Are you not going to pick up?
           | 
           | Just wait for the deepfaked voice call scammers. Their best
           | bet is to work up the hierarchy; a tiny local police station
           | knows how to get in touch with a bigger police station that
           | can contact an embassy, etc.
           | 
           | > There are a lot of these little edge-cases. Journalists,
           | lawyers representing class action suits, government id
           | expiring, and so on.
           | 
           | All of these use-cases allow someone to spend the time to
           | contact you via your preferred contact method, whatever that
           | might be.
        
           | duffyjp wrote:
           | My iPhone is set to "Silence Unknown Callers." It's the
           | perfect compromise. If a call is legitimate they'll leave a
           | voicemail and I just call them back.
        
             | macintux wrote:
             | I discovered recently that my Verizon phone service's
             | voicemail had been full for several months. I'm not sure
             | how I was ever supposed to discover that, but I ignored
             | what turned out to be an important phone call and got burnt
             | because I assumed I'd get a voicemail.
        
         | dalbasal wrote:
         | Possibly, but we can't do that either. What we _need_ is some
         | balance of both worlds. OOH, we do actually need to be
         | contactable. OTOH, being too contactable means spam. I doubt
         | there 's a perfect balance, but either extreme come with too
         | many problems.
         | 
         | Email has decent spam filtering, and I think that kind of cat-
         | mouse system will persist. That said, there's "room" for more
         | whitelisting.
        
           | jerf wrote:
           | "I doubt there's a perfect balance, but either extreme come
           | with too many problems."
           | 
           | In principle, "pay me a small fee if you're not on my list,
           | if I put you on my list now it's free" would work well
           | (optionally refund someone who contacts you out of the blue
           | that you approve of), but there's a lot of both engineering
           | and social details between where we are now and such a
           | system.
           | 
           | It doesn't take much cost friction to deter mass spamming. I
           | don't think much problem would be left behind from the
           | handful of overconfident spammers who think that they can
           | bust the odds and it's worth 25 cents a message or something.
        
             | biot wrote:
             | This is nearly a few decades old (2004):
             | https://craphound.com/spamsolutions.txt
        
             | dalbasal wrote:
             | This is one of those ideas that appeals to economists and
             | nerds, but rarely works out irl.
             | 
             | Artificially or intentionally aligning interests tends to
             | be a "genie, make me a sandwich^" problem. There are lots
             | of places where "reversing the charges," seems good in
             | theory... but it never happens.
             | 
             | Anyway, linkedin have something like this. In practice, it
             | feels like a better quality of spam, rather than a solution
             | to spam.
             | 
             | ^Poof. you are now a sandwich.
        
             | shuntress wrote:
             | Sounds like a good idea on which to base an ISP startup.
             | 
             | "Anyone not on your contact list will take $1 off your
             | monthly bill for each phone call, SMS, or eMail they send
             | to you (through our phone line & email servers)"
        
           | cwhiz wrote:
           | The "Hey" email service toes the line well for me. I'd prefer
           | all of my communications were based on a similar idea.
        
         | jillesvangurp wrote:
         | My phone number (and some other details) were part of Nano
         | Ledger's database that got stolen last year. So, some
         | entrepreneurial scammer started calling me on a daily basis a
         | few months ago. Really annoying. I'm well aware my phone number
         | and email addresses are pretty much public information at this
         | point. I actually put that on my web site even. But stuff like
         | this makes me even less likely to answer unknown numbers.
         | Hilariously, the scammer actually called me while I was giving
         | a security briefing to our company about enabling 2FA. I put
         | him on speaker and we had a good laugh while the guy insisted
         | in broken English laced with expletives that he "had my money".
         | 
         | A few months ago some criminals social engineered themselves
         | past my bank's security as well. The first I learned about this
         | was a funny conversation (by phone!) from an actual Deutsche
         | Bank employee asking me if I recently changed my address and
         | phone number and whether I opened ten new accounts. "eh
         | no?!..." Basically their fraud detection system kicked in
         | before these people did any damage. I made a point of not doing
         | anything else than confirming information they already knew
         | (like my old address, email address) and asked for an on site
         | meeting to discuss things in more detail. I realized instantly
         | I had no way of verifying anything I was being told on the
         | phone and might very well be talking to a scammer. As it turns
         | out this was for real and the person actually managed to find
         | my "old phone number" in some archive. Otherwise all my contact
         | information had already been changed by the scammers.
         | Thankfully I answered that call. Apparently, this happened to
         | several people.
         | 
         | Basically, what happened was some persons just called the
         | bank's help desk, asked them to reset my online banking access
         | codes, and then somehow intercepted the pin codes (thanks
         | Deutsche Post) before they reached me. The theory is that
         | somehow the security of the distribution system was
         | compromised. As far as I an tell, nobody broke into my building
         | or mailbox. Then started they using them to change my address,
         | etc. They got caught only when they created sub accounts and
         | started transferring money.
        
           | nonameiguess wrote:
           | I've been called twice by my bank to warn me of possible
           | fraudulent activity. Both times I hung up on them and called
           | back at the bank's own public customer service line and asked
           | them if that was really them calling. Once it was and once it
           | was not, so I'm glad I was that careful.
        
           | ricardobayes wrote:
           | So they really had your money then?
        
             | jillesvangurp wrote:
             | The phone scammer, no. Just some idiot trying to get me to
             | do stuff I should not be doing. Given how he conducted
             | himself on the phone, he probably does not have a great
             | conversion rate. People that do this are not exactly
             | criminal master minds. But I guess some people get bullied
             | into handing over their private keys, which I assume is
             | what he was after. He clearly had some setup that auto
             | dials numbers. After this, he apparently removed me from
             | that list. So, tip: annoy the hell out of them and waste
             | their time as much as you can when this happens to you.
             | Putting him no speaker got a few giggles out of the team.
             | 
             | The criminals that got into my account got too greedy. The
             | bank's fraud detection system kicked in and rolled back the
             | transactions. But at that point they had complete control
             | over my account. Very scary. If they had been more subtle,
             | they could have likely stolen quite a bit. So, also not
             | criminal master minds probably.
        
         | bitL wrote:
         | I do that already. Prevented e.g. Hult MBA from pitching their
         | exquisite high-end educational services...
        
       | williesleg wrote:
       | What do you expect? Passwords aren't security, they're a
       | programming construct.
        
       | polycaster wrote:
       | I'm sure not to be the first one to point this out, but checking
       | other people's emails is quite revealing. It's very much
       | documenting in public which sort of websites about every person
       | you know is visiting. Among them [1] "Baby Names", "Ashley
       | Madison", "Adult FriendFinder", "diet.com". Want to profile your
       | friends - there you are.
       | 
       | I wonder if the benefits of haveibeenpwned outweights this.
       | 
       | [1] https://haveibeenpwned.com/PwnedWebsites
        
         | astura wrote:
         | It's set up so that you have to prove you own the email address
         | before knowing if you're included in "sensitive" breaches.
        
         | moftz wrote:
         | I did a lot of searching through the Ashley Madison dump back
         | when it came out. It was pretty easy to find people living on
         | my neighborhood that had accounts. They might not have done
         | anything (it was just billing details after all) but any of
         | that information could have easily been used to blackmail
         | someone. There were also a whole bunch of people using .gov or
         | .mil email addresses. Like if you are going to cheat on your
         | wife, don't make it that easy for someone to realize that you
         | can be exploited for government secrets.
        
         | frb wrote:
         | Funny that I never thought about this.
         | 
         | Now I'm wondering how this actually plays with legislation such
         | as CCPA or GDPR, as it is quite revealing even without the more
         | delicate sites mentioned here.
        
         | paranoidrobot wrote:
         | Troy has covered this several times, but some sites, even
         | showing in the PwnedWebsites list, are not viewable
         | until/unless you confirm control of the email address or
         | Domain.
         | 
         | e: To be clear, the Ashley Madison, and Adult Friend Finder
         | (both breaches) are denoted on the list as not being publicly
         | searchable.
        
         | nonameiguess wrote:
         | I just checked myself and thankfully I've apparently only been
         | in a few breaches, but of the ones listed, I only knowingly had
         | accounts on LinkedIn and Dropbox. Nothing embarrassing because
         | I'm smart enough to use burner accounts for embarrassing stuff,
         | but I only even recognize last.fm and LuminPDF as services. I'm
         | surprised last.fm still exists. I guess I might have signed up
         | for it at some point and forgotten.
         | 
         | My phone number isn't in here anywhere, so lucky me, but it
         | doesn't make a difference. The State of Texas finally forced me
         | to get a Texas driver's license in order to continue being able
         | to vote, and the State of Texas sells your address and phone
         | number to marketers once they have it, so my number is trash
         | now anyway. 99 out of 100 texts and calls are either
         | politicians or people claiming to want to buy one of my houses.
         | I basically no longer use a phone except when my dad calls.
         | 
         | I guess the plus side there is I'm somewhat immune from
         | whatever location tracking can't be disabled since I don't even
         | take my phone with me most of the time when I go anywhere, but
         | that was an old habit from when I worked in a SCIF and couldn't
         | bring a phone with me anyway.
        
       | aboringusername wrote:
       | Note to anyone that cares: Make your data as stale as possible:
       | you can't change your address easily, sure. But you can recycle
       | phone numbers (once a year, minimum). Change your credit/debit
       | cards yearly (say to your bank you 'lost' it).
       | 
       | When ordering online, always, always, always use a fake number,
       | it's not required. Always use a fake name where possible. Sure,
       | you need to provide that as a 'billing' address, but in some
       | cases it stops other third parties getting that info (on eBay you
       | can type a random name to ship to, I've had fun with this :) ).
       | 
       | But lastly, LOL. Giving your data to facebook this is what you
       | deserve, and for society accepting facebook as a standard part of
       | life.
       | 
       | When do we protest to delete the website?
        
         | hnrodey wrote:
         | >Change your credit/debit cards yearly (say to your bank you
         | 'lost' it).
         | 
         | Huge shoutout to/for privacy.com. Been using for over a year
         | now and it's been a fantastic service.
        
         | avh02 wrote:
         | > When ordering online, always, always, always use a fake
         | number, it's not required
         | 
         | Until something's gone wrong in the process and they need to
         | call you to clarify/fix it. (happens regularly to me due to
         | address suffixes not propagating correctly through crappy
         | systems)
        
           | ricardobayes wrote:
           | This is region dependent. In spanish speaking countries they
           | pretty much never use email. Everyone - including the courier
           | will just call you.
        
         | baby wrote:
         | I change my phone number every year and I get spam calls all
         | the time.
        
         | shmoogy wrote:
         | > When ordering online, always, always, always use a fake
         | number, it's not required
         | 
         | Don't do this if you order anything that doesn't ship small
         | parcel. The freight company may need to contact you and it will
         | complicate matters and delay your final delivery.
        
         | bshep wrote:
         | I do something similar when a site asks for my birthday, i used
         | to pick a random date, but sonce its sometimes used to reset
         | password or asks u to confirm i just use the first of january
         | of the year i was born so i can make sure i remember what i
         | put.
        
           | vharuck wrote:
           | When birthdate is tied to an account, I pick a random one and
           | store it alongside the username and password in KeePass. Same
           | as the "security questions"; I make up and store nonsensical
           | answers. E.g. "Q: What was your mother's maiden name?" "A:
           | Blueberry pie."
        
             | wussboy wrote:
             | I do the same thing but use KeePass' password generator to
             | create the answers. My mother's maiden name will be
             | something like "diejdJyt7ejHsud"
        
               | hiq wrote:
               | I do that as well, but I dread the moment I'll have to
               | call support through no fault of my own and they'll ask
               | me for the answers to some of these questions.
        
               | teachtwolearn wrote:
               | Just say, "it's a jumble of letters and numbers but I
               | lost the USB drive where I stored all that stuff."
               | 
               | Most of these systems still use people who have quotas to
               | meet, and can see all of your account details in some
               | sort of admin panel.
        
               | benlivengood wrote:
               | I mean, probably anyone could call and start reading off
               | the letters from "correcthorsebatterystaple" and the
               | support tech will go "oh yeah, you're one of those people
               | who thinks they're clever with security; here are all
               | your account details"
        
           | wasmitnetzen wrote:
           | Doesn't that kinda negate the goal of using a fake birth
           | date? After all, they don't really care whether you give your
           | real birth date, it's enough that it is the same on that
           | other website they get your personal information from to
           | correlate.
        
             | KMnO4 wrote:
             | I don't care if someone leaks my fake DOB in a Dropbox hack
             | and then tries to reset my Netflix password.
             | 
             | Websites that use my real DOB are usually linked to my
             | identity, so I'm much more concerned with protecting them
             | from, eg social engineering attacks [0].
             | 
             | [0]: https://gizmodo.com/how-i-lost-my-50-000-twitter-
             | username-15...
        
               | bshep wrote:
               | Yes this is my thought as well.
        
       | cjflog wrote:
       | I have been pwned. Also of note, while my phone number was on my
       | Facebook account, it has had its visibility set to "only me" for
       | years. Still leaked.
        
         | weird-eye-issue wrote:
         | Not really surprising. That just sounds like a UI option. You
         | realize they still have to store it right?
        
       | rwmj wrote:
       | I'm slightly surprised to find that my number has apparently
       | _not_ been pwned, given the huge uptick in spam calls that I 've
       | been receiving which seems to be coincident with the Facebook
       | leak.
        
         | breakingcups wrote:
         | Not all phone numbers have finished uploading, check the blog
         | post for details.
        
       | fudged71 wrote:
       | Cool. Facebook leaked my Canadian phone number. As if I didn't
       | get enough spam calls already. Time to declare phone call
       | bankruptcy?
        
       | [deleted]
        
       | 2Gkashmiri wrote:
       | surprising that "Pakistan" isn't even on the list of countries.
       | Anyone knows why?
        
       | vladmiller wrote:
       | I deleted my facebook account almost two years ago and my number
       | still show up on the search... too bad GDPR does not spread on my
       | country.
        
       | riscy wrote:
       | Has Facebook made any public comments about this breach yet?
        
         | argv_empty wrote:
         | https://about.fb.com/news/2018/04/restricting-data-access/
        
       | MangoCoffee wrote:
       | i've stop using FB for 10 yrs now. i just check my number. not
       | pwned.
        
       | jhoechtl wrote:
       | What a great service to gather phone numbers even from those who
       | haven't been pawned!
        
         | diegoperini wrote:
         | I trust Troy more than I trust Facebook. His incentives are
         | aligned with staying honest.
        
       | intrasight wrote:
       | Honest question: Why would you give your phone number to FB?
       | Related to their app perhaps (which I don't have)?
        
         | newscracker wrote:
         | Over the years, many people who were stuck in the Facebook
         | platform have been coerced by Facebook into providing a phone
         | number to "verify" their account. The other choice given to
         | them was (and is) to lose access to the account because
         | Facebook believes it's a fake account or a spam account or a
         | "violation of its community policy".
         | 
         | In other cases, Facebook may get the phone number because
         | someone uploaded their address book/contacts to it. This
         | information shouldn't be in the user's public/private profile
         | (even though Facebook would store it internally, use it to
         | figure out other connections and "show relevant ads").
        
         | invalidusernam3 wrote:
         | I haven't used facebook in years, but if I remember correctly
         | it was part of your account verification in some cases.
        
         | Black101 wrote:
         | I don't know but I never gave my phone number to Facebook (but
         | I also never used the app, only the website).
        
       | adamrezich wrote:
       | my Facebook account got hacked/stolen a few months ago (didn't
       | notice since I hardly ever use it), and Facebook won't give me
       | back access to it even after providing photo ID etc., citing
       | coronavirus-related labor shortages or some such bullshit. but
       | hey, at least now HIBP has the hacker's phone number instead of
       | any of mine!
        
       | adler0901 wrote:
       | I'm supposed to go to a random website and enter my phone number?
        
         | luplex wrote:
         | It's not at all a random website. haveibeenpwned is renowned.
         | Your phone number is not uploaded to the server, instead your
         | browser asks for a whole range of (hashed) phone numbers and
         | checks locally if yours was one of them.
         | 
         | The process is spelled out here:
         | https://haveibeenpwned.com/Privacy
        
           | beervirus wrote:
           | HIBP is indeed probably just fine, but I'm not sure how the
           | phone number searching works. "There's no k-anonymity
           | implementation for phone numbers at this point in time."
           | 
           | https://www.troyhunt.com/the-facebook-phone-numbers-are-
           | now-...
        
       | sb636 wrote:
       | I tried fully deleting my Facebook account multiple times about 5
       | years ago. Each time, it became clear that my information was
       | never leaving. Friends were still able to pull up my account. My
       | credentials were still being recognized and allowing me to login
       | to an account I was told was now nonexistent.
       | 
       | Now I see my phone number was part of the breach. I am so fed up
       | with Facebook.
        
       | nikbackm wrote:
       | I just logged in to Facebook for the first time in years to check
       | the data it has on me. Luckily I never added my phone number or
       | address, so should hopefully be in the clear.
        
         | layoutIfNeeded wrote:
         | Haha, no. It's enough if one of your friends/relatives/etc. had
         | allowed Facebook/Instagram/WhatsApp/etc. to scan their contact
         | list. Your phone number is in there, just not shown, trust me.
         | 
         | In fact Facebook used to show creepy suggestions when such
         | cross-pollination of data occured, like "Click here to confirm
         | that XXXXXX is your phone number!", but they stopped doing that
         | a few years ago.
        
         | Macha wrote:
         | Did you ever set up SMS 2fa? Did any of your contacts use the
         | Facebook app to sync their contacts (at least at one point a
         | default behaviour)? Then Facebook has your number. I remember
         | when I still used it being promoted by a bar at the top of the
         | web UI "Is this your number?" With my actual number suggesting
         | I add it to my profile, so I know they have mine.
        
           | vmception wrote:
           | I've been intentionally breaking my social graph since at
           | least 2012.
           | 
           | Looks like its worked here.
           | 
           | When I make a Facebook account, usually for my living
           | complex's community or a bunch of Gen-Xer's doing a burning
           | man thing, I use a new email or new phone number for signup
           | and one time passwords.
           | 
           | I don't let it get access to my contacts, assuming I
           | inadvertently installed the Facebook app on a phone.
           | 
           | Doesn't look like they meaningfully go deeper than that.
           | 
           | I find the social graph to be very fungible, so if I really
           | ever want to recreate it I can just add my phone number or
           | give any app access to my contacts. This knowledge also lets
           | me not be married to any of these services.
           | 
           | I'm very content downloading the account data and then
           | deleting the account.
        
           | antegamisou wrote:
           | I have had the exact same experience. Interestingly, it took
           | them a few tries to get to my actual number and they still
           | carried on throwing other random phone numbers I did not
           | recognize.
        
           | jtylr wrote:
           | Despite using 2FA and listing my number on my profile -
           | albeit restricted to "just me", I don't appear in the data.
           | It's not as simple as they just having a record of it
           | somewhere.
        
             | Etheryte wrote:
             | Likewise, it seems there's more nuance to this leak. I
             | checked the data out and a large number of my contacts have
             | correct numbers in it. At the same time, numerous people
             | don't appear in it, even if they do have a phone number on
             | their profile.
        
             | wccrawford wrote:
             | I'm in the same situation and very surprised. I've sat here
             | wondering if I'm entering my numbers wrong, or if I'm
             | really not in it. I've read the blog post and I'm entering
             | the 1 in front of my 10 digits, because I'm in the USA.
             | 
             | My wife's number isn't in there, either. I'm just really
             | surprised, because I checked facebook the other day and it
             | said I was searchable by email and phone number.
             | 
             | I even searched my email address, and a lot of other
             | breaches show, but not Facebook.
             | 
             | I guess I got lucky?
        
               | ricardobayes wrote:
               | US numbers are not uploaded yet
        
               | wccrawford wrote:
               | Ah, that makes sense then. I assumed they were because
               | the instructions showed the US style specifically.
               | 
               | Thanks!
        
         | freebuju wrote:
         | Try creating a new facebook account today. The site won't let
         | you do that without verifying a phone number. The difficulty
         | level increases if you try doing so behind a vpn. Same goes for
         | other SM sites like Twitter.
        
           | mimimi31 wrote:
           | I don't think that's true. I created a Facebook account a few
           | weeks ago and a Twitter account just yesterday, both without
           | needing a phone number.
        
             | teddyh wrote:
             | By all accounts, anyone can _create_ an account, but then
             | the account invariably quickly gets suspended, requiring a
             | phone number for "verification".
        
           | durnygbur wrote:
           | Don't they have a "real person" policy now? ie. not only
           | phone number but as well a requirement to upload a passport
           | style photo. Concidentally on entrance to US a camera makes a
           | high resolution photo of every traveller during passport
           | control.
        
             | nonameiguess wrote:
             | I believe they have always had this policy, though it
             | wasn't particularly well enforced when they opened up the
             | platform to all comers. I actually had a Facebook account
             | before I even first got a mobile phone at all, back in 2004
             | when you needed a .edu email address to sign up, which just
             | meant they were delegating identity verification to the
             | university. I think people were fairly comfortable with it
             | back then because the only other users who could see you
             | were people from the same school and it just mimicked the
             | physical "facebook" that universities already published and
             | made available to everyone with directory listings
             | including your official photo and the phone number and room
             | number of your dorm if you lived on campus. There was no
             | open network. You could only even search for people from
             | your own school.
             | 
             | Obviously, the platform has radically changed since then,
             | but they have gotten a lot of mileage out of the illusion
             | that you could freely share what you wanted because the
             | only people who were going to see it were people who
             | already knew you anyway, which was at least somewhat true
             | at first.
        
       | durnygbur wrote:
       | Every time Facebook/Gmail/Google/Amazon/LinkedIn/Tinder/whoever
       | asks me to give them phone number "just in case" my first and
       | only thought is "hell no". I haven't been wrong a single time.
        
         | 0x_rs wrote:
         | Let's not forget the notable case of Twitter "accidentally"
         | using your provided phone number for advertising purposes [0],
         | and to this day still banning you after registration if you
         | refuse to give it.
         | 
         | [0]. https://www.eff.org/deeplinks/2019/10/twitter-
         | uninentionally...
        
           | Nextgrid wrote:
           | Facebook did this as well.
        
             | [deleted]
        
           | finiteseries wrote:
           | I've been using Twitter to follow some people who don't have
           | blogs etc since last May, and haven't been banned yet.
           | 
           | Lots of likes, no RTs or posts though.
        
           | sneak wrote:
           | Twitter also had staff who leaked Twitter account PII from
           | the Twitter DB to spies from the Saudi government, who have a
           | habit of killing journalists from time to time.
           | 
           | https://www.buzzfeednews.com/article/alexkantrowitz/how-
           | saud...
           | 
           | Collecting this data is an accident (or murder?) waiting to
           | happen.
        
           | officeplant wrote:
           | Haven't given them my number on any of my twitter accounts.
           | Where does this banning rumor come from?
        
         | sevencolors wrote:
         | I've been using a MySudo phone number to use for signups when
         | I'm forced to give out one. Has reduced the noise i get in my
         | messages for my real number
         | 
         | https://mysudo.com
        
           | sodality2 wrote:
           | Are they not blocked for being VoIP?
        
             | sevencolors wrote:
             | I've only run into one instance where they wanted a real
             | number. (Coinbase) I think sites only block those when
             | there's a reason to.
        
         | codedokode wrote:
         | Sadly, many companies now require a phone number to use their
         | services. For example: Signal, Telegram, Whatsapp, social
         | networks like Instagram and Vk. They don't like anonymous
         | users. For some users, Google requires a phone number to sign
         | up. Twitter requires a phone number if they see something
         | "suspicious" in user's behaviour.
        
         | lupire wrote:
         | It's crazy the a phone number is a secret. The problem isn't
         | having the phone numbers; it's all the terrible systems that
         | only work if phone numbers are secret.
        
           | hrktb wrote:
           | Phone numbers are not secret. These service ask for it mostly
           | to be sure to get the right one (checking is expensive)
           | and/or to have plausible deniability of your contentment when
           | they abuse it later.
        
         | ricardobayes wrote:
         | Not to mention whatsapp is actually broken. It's bound to your
         | phone number and can't change it. If you change SIM, your
         | account is wiped. AND the worst: your contacts are not notified
         | so if they send a message to the old number, it will just
         | silently fail. Absolutely horrible. I never understood how
         | whatsapp could be phone-number bound and not account bound like
         | everything else out there.
        
         | hnick wrote:
         | I feel like saying "after you!". What's that Google? No phone
         | number? Oh...
        
       | chrischen wrote:
       | I'm so confused. I intentionally refused to give my phone number
       | to facebook and it is not set in my profile, yet my number was
       | pwned in this facebook breach. Is FB associating or storing my
       | number without permission? I have a different number set for
       | 2-factor and amazingly it was not pwned!
        
         | coatmatter wrote:
         | I think you may have allowed Facebook to allow other Facebook
         | users to search for your profile via your number. Can you check
         | my earlier comment at
         | https://news.ycombinator.com/item?id=26712835 and let us know
         | whether or not this is/was the case?
         | 
         | > "Facebook Settings > Privacy > How people can find and
         | contact you > Who can look you up using the phone number you
         | provided?"
         | 
         | Is/was it set to "Everyone"?
        
           | chrischen wrote:
           | Yes, but my number is not set to the one that was pwned!
        
       | ClearAndPresent wrote:
       | Troy says: " At the time of publishing this blog post, all phone
       | numbers beginning with international codes 4, 6, 8 and 8 have
       | completed loading."
       | 
       | Interestingly, several cellphone numbers I know to be present in
       | one set of leak data which start with international code 4 are
       | not detected by HaveIBeenPwned.
        
       | notyourday wrote:
       | This is very strange. I definitely have a phone number associated
       | with a facebook account because at some point in the past I used
       | FB 2FA. I have not deleted that number. I have tried it in
       | several different formats, including + country code, leading
       | country code, with and without dashes and I am getting "Good
       | news" message.
        
         | Madzen__ wrote:
         | Considering Facebook has ~2.7 billion users and this breach
         | only contains 533million there are many people not in it.
         | 
         | Troy also mentioned not having processed all numbers yet
         | aswell, but you could check the dump yourself. Downloading
         | country spesific dumps does not take a long time.
        
       | floatingatoll wrote:
       | If your phone number begins with 40% of the digits 0-9, then
       | you'll have a chance to find it on the site.
       | 
       | Please review the footnote of the post, just above the comments,
       | before assuming that your HIBP negative result is valid.
        
       | devgoldm wrote:
       | Found my number on there too even though I've deleted Facebook
       | for at least 5 or 6 years now -_- Not sure when I gave them my
       | number either, I hope it wasn't scraped from someone else's
       | contact list... At least it makes sense why I received a bunch of
       | spam calls over the weekend.
       | 
       | Anyway it's probably good practice to recycle your number every
       | few years, and not use it for 2FA to make switching numbers a lot
       | easier. Who knows what services I'll be locked out of once I
       | change, let's hope not too many.
        
         | hnrodey wrote:
         | I've had the same phone number for somewhere around 17 years. I
         | kept this number even as I moved across the country (US).
        
           | Cd00d wrote:
           | I thought this was the norm. I've had the same number for 20
           | years now, though have moved through many different area
           | codes since. But, I must be the odd one, because I get asked
           | regularly why I have the area code I do, and the answer
           | "because that's where I was living in 2001" doesn't seem
           | satisfactory.
        
         | lupire wrote:
         | > At least it makes sense why I received a bunch of spam calls
         | over the weekend.
         | 
         | Really?
         | 
         | Every phone number is already known to anyone who wants to get
         | it.
        
         | scrose wrote:
         | I can't imagine telling everyone I know that I'm changing my
         | number every couple years, and I'm not even calling/messaging a
         | lot of people nowadays. I have a family member who did
         | something similar(not on purpose) and I still have 3 of her
         | numbers and still get confused which is the working one.
        
           | 52-6F-62 wrote:
           | I had a company phone about 6 or 7 years ago for a company I
           | worked for at the time. When I was on my way out they
           | unilaterally revoked my company-provided cellphone after
           | convincing me I should get rid of my old private number for
           | theirs.
           | 
           | I'll never do that again. It happened shortly after ditching
           | social media and I just about all of my contact info and I
           | haven't been in touch with some old friends because of that
           | since then.
           | 
           | Even if you had the time to transfer your contacts, etc,
           | something will inevitably get missed.
           | 
           | Hell, I've updated family and friends to an email address
           | I've been using for closer to a decade and they still email
           | the old one...
        
           | devgoldm wrote:
           | I know exactly what you mean, there's only so many times you
           | can append "New" on the end of a contact name!
           | 
           | A good chunk of people will probably communicate mostly on
           | platforms like WhatsApp/Telegram/Discord/whatever that don't
           | need numbers at all or facilitate switching of numbers
           | without your contacts having to do anything. I don't think
           | that will constitute anywhere near the majority of people
           | across the world though, switching numbers will definitely be
           | a pain for most.
        
         | rsync wrote:
         | "Anyway it's probably good practice to recycle your number
         | every few years, and not use it for 2FA to make switching
         | numbers a lot easier."
         | 
         | Ironically Twilio of all places forced SMS 2FA on all accounts
         | earlier this year.
         | 
         | As in, one day you could no longer log into your twilio account
         | without giving them a phone number. You are locked out until
         | you do.
         | 
         | Ironic in a few ways ...
         | 
         | First, twilio numbers are _not_ mobile numbers - they are voip
         | numbers - and cannot be used for most 2FA authentication
         | services because they cannot receive messages from short codes.
         | So it 's ironic that twilio forces you to use a non-twilio
         | number for their 2FA.
         | 
         | Second, many twilio use-cases (like mine) involve building a
         | twilio infrastructure to replace my existing phones/numbers ...
         | and now that is broken from the bottom up because I have to use
         | a mobile phone with a fixed provider just to use twilio.
         | 
         | The bottom line is: none of this is for me or my safety and
         | security. Twilio has a spam problem and that spam problem is
         | very hard to solve. Forced pairings of physical phones and SIM
         | cards is just a desperate way to throw sand in those gears to
         | slow it down a little bit.
        
           | QUFB wrote:
           | I have had a Twilio account for years, and have always used
           | the proprietary MFA implementation from their Authy app. I
           | don't remember being forced to switch to SMS MFA.
        
         | glitcher wrote:
         | In my limited experience, I've had more phone spam plus wrong
         | number calls right after changing phone numbers due to the
         | number being recycled.
        
       | ada1981 wrote:
       | I was pwned.
        
       | edf13 wrote:
       | Interestingly www.TroyHunt.com is blocked by Quad9 DNS!
        
         | coatmatter wrote:
         | Fixed now.
        
       | yosito wrote:
       | A note for people with US numbers who aren't finding their info:
       | 
       | > And finally, one last note on the data load process: At the
       | time of publishing this blog post, all phone numbers beginning
       | with international codes 4, 6, 8 and 8 have completed loading.
       | The other codes are in progress and may take several hours more
       | before they're searchable.
       | 
       | US numbers begin with international code 1, and it seems that
       | they aren't yet searchable.
       | 
       | I was surprised that mine hadn't come up, since I've had a few
       | Facebook accounts over the years with my phone number, and this
       | explains it.
        
         | nohuck13 wrote:
         | Thanks.
         | 
         | For anybody getting a miss and wondering if they messed up the
         | formatting, my US number is coming up now, formatted with a
         | vanilla +1-123-456-7890.
        
           | heleninboodler wrote:
           | My US number also came up when entered as 12345678901
           | (1-prefixed but with no extra formatting or chars)
        
         | [deleted]
        
         | untouchable wrote:
         | According to the edit at the bottom of the post, "1" is now
         | complete.
        
         | PostThisTooFast wrote:
         | You gave a real phone number to Facebook?
         | 
         | Egads.
        
       | harmeswoul12 wrote:
       | The data would have been either from abuse of API's by third
       | party apps or find your friend. From the dataset, it seems to be
       | exclusively limited to the data immediately viewable on your
       | profile, hence the reason so few emails appeared in this leak.
        
       | [deleted]
        
       | [deleted]
        
       | rpaddock wrote:
       | After my wife's suicide (See the documentary Pain Warriors) I
       | took over Karen's FB account as my own, and I changed the name on
       | the account. Long before this breach I have been getting SMS Spam
       | addressing me as Karen, on a number that did not exist when she
       | was alive.
       | 
       | FB data can be the only possible source of that spam.
       | 
       | The spam is always trying to sell male enhancement products to
       | 'Karen'. Anyone know how to stop this SMS spam crap?
        
         | magsnus wrote:
         | Sorry for your loss. Right now I'm pretty happy that I scrubbed
         | all information of my FB account months ago. If only people
         | could stop using messenger so I could delete it.
         | 
         | But I have a similar, but unrelated to FB, problem in that
         | every month I get an offer to work as a nurse in Norway from
         | different agencies. I figured they scraped some "find the
         | number"-site here in Sweden long ago and since my mothers name
         | was on my bill I guess my number somehow came up under her
         | name.
         | 
         | It's been annoying for years but since my mother had a some
         | (non-corona) medical problems last year it has been downright
         | infuriating at times. Anyone know how to make it stop when
         | there is a bunch of different agencies messaging you?
        
           | gmargari wrote:
           | Would you mind elaborating on how you "scrubbed" information
           | from your fb account? It's been years since I closed my
           | account but I know (e.g. see this article) this is not
           | enough, so I consider reenabling it only to delete all my
           | info, and then finally (?) deleting it.
        
             | magsnus wrote:
             | I deleted everything, going through every page and my whole
             | timeline etc pressing delete on everything. I considered
             | changing my number etc. to nonsense and wait a week and the
             | delete it but I figured facebook are probably versioning
             | that stuff anyway.
             | 
             | Right now my profile picture is a plastic duck, there are
             | no photos and no information apart from my name and my
             | throwaway-email adress (which I hope is hidden from the
             | world via settings).
             | 
             | There is also a "privacy page" there where you can check
             | what information they have saved about you and if you
             | forgot to delete something. I would probably have done it
             | this way first if I where to delete my FB-account but for
             | now I need messenger.
             | 
             | If you are running firefox you should also install
             | "facebook container" even if you don't have an account. :)
        
         | darcien wrote:
         | My deepest condolences.
         | 
         | I think it's pretty hard to stop incoming spam when the number
         | itself has been made public.
         | 
         | The only options I know would be: a. Play whack and mole,
         | report the number to the authority in your country that handles
         | this kind of spam activity. b. Use some kind of mobile
         | application that filter out the spam SMS. This one is kinda hit
         | and miss, since the number data is coming from community
         | reports, so some spam might pass the filter. And there might be
         | some false positives from the spam filter.
         | 
         | I also would like to hear if there's alternative solution for
         | this problem, other than changing the phone number itself.
        
         | atlanta90210 wrote:
         | Very sorry for your loss and thank you for sharing.
        
         | legohead wrote:
         | If you are in the US you can register at donotcall.gov
         | 
         | It's not perfect, but it has had an impact on the amount of
         | spam I receive.
        
         | ct0 wrote:
         | My phone has an option called Do Not Disturb mode. I have set a
         | schedule to turn it on everyday from 12AM to 11:59PM. What Do
         | Not Disturb will do is block (silence the notification or
         | ringer) every message or call from someone that is not in your
         | phone book. While unfortunately you'll still get the spam SMS,
         | but you wont get the alert.
         | 
         | The only way I can see striking back at these spam calls is to
         | pick up the call and waste their time, because its expensive.
         | Also if I pick up that means someone else is not getting
         | scammed. I try to get as far along in the scam process as
         | possible.
        
           | officeplant wrote:
           | I enjoy the pixel line of phones having google assistant
           | answer spam calls for me. Sometimes its fun to watch the
           | conversation they attempt to have with the assistant.
        
           | GoblinSlayer wrote:
           | At least here human operators apparently are paid for call
           | duration and they will prolong the call up to 15 minutes and
           | you don't need to say anything.
        
         | mdp2021 wrote:
         | If you only mean "how not to be bothered" (instead of radical
         | actual solutions of legal nature etc.), and the sender is a
         | recurring number, very probably your phone OS has an option to
         | reject calls and/or messages from specific numbers.
        
           | input_sh wrote:
           | There was a spammer that bothered me, I blocked the number,
           | and started receiving spam from adjacent ones (same number,
           | just the last digit increasing by 1). Had to block 5-6 for
           | them to go away.
        
       | hypertele-Xii wrote:
       | Can I sue Facebook for leaking my number? Serious question.
        
         | kube-system wrote:
         | What damages have you incurred?
        
           | bogwog wrote:
           | Identity theft most likely, and the consequences arising from
           | that.
        
             | kube-system wrote:
             | What is the monetary amount, and do you have evidence of
             | the theft?
        
               | bogwog wrote:
               | I'm speaking hypothetically of course, I haven't actually
               | been affected by this leak (so far).
               | 
               | But that doesn't seem hard to prove at all. At the very
               | least, you could claim that Facebook's leak forced you to
               | pay for identity theft protection/monitoring as a very
               | reasonable precaution, and whatever that cost you would
               | be the damages.
               | 
               | Then of course there's the possibility that someone did
               | actually steal your identity and used it to drain money
               | from your accounts, or simply caused you to waste a bunch
               | of time hunting down for example fake accounts opened
               | using your information, credit cards, etc.
               | 
               | And I'm not a lawyer, but I'm pretty sure somewhere in
               | all this fuckupery you can throw in some punitive
               | damages.
        
       | VBprogrammer wrote:
       | I have noticed an uptick in the number of scam calls and texts
       | I've been receiving over the last few days. No surprise that my
       | number was included in this dataset.
        
       | nixass wrote:
       | Is it just me or... why do people even share their phone number
       | with Facebook? What did you use it for? It wasn't mandatory or
       | anything. Why the Pikachu faces?
        
         | fishbacon wrote:
         | It is very convenient for your friends/family to be able to get
         | your phone number from your facebook profile.
         | 
         | I have used it a few times to contact people for whom immediate
         | contact was preferable to facebook post/message.
        
         | inetknght wrote:
         | Your comment is disingenuous. Facebook has been around for
         | nearly two decades. There's plenty of time there for people to
         | make mistakes and _try_ to fix them. Unfortunately they 're
         | competing with their contacts who re-add those same mistakes
         | and also competing with Facebook's own incentives to not delete
         | data.
         | 
         | It'll be fun if/when any of these numbers can prove they
         | requested Facebook to delete their data under GDPR.
        
         | rwmj wrote:
         | I believe their app uploads the address books of other people
         | and those address books might contain your phone number and
         | other details.
        
         | astura wrote:
         | My number is on my profile, so that my friends can contact me
         | shall they lose my number. Less important now that messenger
         | exists and we can access it any time, but I put it there before
         | it existed. It's come in handy in the past.
         | 
         | I also don't consider my phone number "sensitive" information I
         | want to keep secret - it's already quasi-public and something I
         | give out when I want people to be able to contact me.
         | 
         | I grew up looking people up in the physical phone book when I
         | lost their number, fwiw.
        
         | wyldfire wrote:
         | Many companies present you with the opportunity to "Protect
         | Your Account" with SMS, and for that protection they 'just'
         | need your phone number.
         | 
         | Turns out the phone number is the best unique identifier and is
         | the perfect key for joining up lots of disparate sources of
         | data. It's the kind of thing that you could either sell
         | directly or use as an index to determine things like your
         | estimated income.
         | 
         | It wouldn't surprise me if Facebook has had multiple technical
         | methods for devising/stealing and disingenuous "protect your
         | account" campaigns for willingly turning over users phone
         | numbers.
        
         | javagram wrote:
         | I have my phone number and mailing address on my Facebook, set
         | to friends only.
         | 
         | Why not? When I grew up, we had a phone book listing everyone's
         | name and address and phone number so you could find them to
         | contact.
         | 
         | I consider all of this essentially public information and would
         | rather make it easier for people I know to contact me. If it
         | gets lost in a breach, whatever. I already get plenty of junk
         | mail because I give to charities and they sell my address.
        
         | nonameiguess wrote:
         | In addition to other reasons already given, I'm not sure if
         | this is still the case because I haven't used Facebook in a
         | while, but back in the day, the only options for 2FA were code
         | generator in the Facebook app itself or SMS. So if you didn't
         | want to have the Facebook app on your phone, giving them a
         | phone number was the only way to enable 2FA.
        
       ___________________________________________________________________
       (page generated 2021-04-06 23:01 UTC)