I have a feeling it's worse than that. (I haven't rigorously perused the ToS, if I'm wrong please lmk.)
Let's say your friend John has an iPhone and saves your name and # in their contacts. One day John installs the Facebook app & opens it. John is not technical and when the app requests permissions he taps 'Allow'. At that point AFAICT there's nothing stopping Facebook from snagging your name & number and populating a ghost profile, or corroborating a real one.
In other words, if you've ever shared your phone number to someone who uses the Facebook app who doesn't dutifully and consistently reject permissions prompts, it's probably already too late.
My only explanation for that was exactly that it had been farmed from a friends contact list.
You can tag someone that isn't on Facebook? I'm pretty sure the box use Facebook accounts...
There are no mutual friends or any other link it could make apart from linking my contact list with their number.
The bigger the network, the more value a user gets, and the deeper the lock in.
It has been shown over and over again that both Facebook and Google will go to extreme lengths to know about their users’ lives and target them with precision ads. They are advertising companies foremost.
What is the point of these products if not linked to my real identity? That’s the whole idea of them. I use Facebook and WhatsApp to talk to people who know me. That’s why they want to talk to me. If they didn’t know my identity they would want to talk to me.
Edit: Unfortunately it probably is their business. A poor choice of words.
For many purposes the companies don’t have to care your ”real” identity
Off the top example: If four of your friends are buying gifts for your baby shower, this is a signal that your other friends have the intent to buy baby gifts and could be marketed to.
Someone's going to say that's to cut down on fraud/increase security, right? Yet these services are going to (against many in the InfoSec world who are screaming "STOP DOING THAT") use SMS as a means of 2FA...
I'm a bit confused where the value add is for account security in making virtual telephone numbers such a hit or miss.
Get a password safe, and don't forget your complex passwords.
Yes, allowing someone to reset their password through a second factor is bad; but that's not 2FA, that's two independent 1FAs.