Twitter used phone numbers provided for security to target ads (2019)
theverge.com
theverge.com
https://arstechnica.com/tech-policy/2020/08/twitter-faces-ft...
In any case, it does not help paranoid people like me, who are always reluctant to share a phone number as a recovery method (I use self-hosted email, it's the most reliable recovery method, but I understand it's not an option for most people).
Positives of downvoting - I get it, it filters out the non-sense. Negatives of downvoting - Leads to herd and mob mentality - "Oh this is downvoted, I must also think this is bad since others thought so as well. Plunk, another downvote! Take that!"
Especially right now when we have intense polarization and people are pulled away from centrist, ideological and sound perspectives into narratives, biases and prejudices.
I've raised this before, but IMO - Downvoting does more harm than good in the long term. Short term benefits are that we get rid of trolls, rude people and actually false information.
There are also laws against using data for some other purpose than it was collected for, but they're less well enforced, and it's pretty frequent that a sneaky T&C clause let's them use data for something else.
And since they don't believe they will get caught (probably due to their track record with getting away with everything) there is no reason to care either.
And they don't have to be as blatantly stupid to send ads to the numbers, they could do as facebook, use it for a shadow profile.
if(IsEUCitizen()) {
...;-)
By all means, use a throwaway number for signup / 2FA setup.
Does the phone number serve another purpose besides security? If it does, then any assurances during sugn up that the information provided will only be used for the purposes it is disclosed would be false. Knowingly false statements made to induce someone to sign up could be considered misrepresentation.
(Facebook has been caught doing that.)
A phone number, or an Android phone logged into the account
Twitter pretends it doesn't but it locks you out in ~5 minutes if you don't verify your phone number.
I would understand Fi having better protection because you have to manage it online through your Google account (and same for Google Voice users).
Not sure what a phone would be able to do about it.
Anyway, Google as your phone provider opens up a different can of worms. Instead of having an overly helpful support staff who can be tricked into doing things they shouldn't, now you have Google's algorithmic account bans and tie-in with Google Payments and no recourse for problems because the customer service is a robot that says "no". https://news.ycombinator.com/item?id=18886804
Nonexistent support is great in terms of resistance to social engineering, but sometimes you need support.
https://arstechnica.com/tech-policy/2019/07/ftc-fines-facebo...
> Additionally, the FTC said Facebook violated the earlier order by "misrepresenting" consumers' ability to opt out of facial recognition by using phone numbers provided for two-factor authentication for advertising purposes without notifying users and by storing user passwords without encryption.
For the developers out there reading this: please be the change you want to see, or at least try. If your company wants to add a user requirement like this, be the person who speaks up against it.
I presume there are privacy laws covering this?
And therefore the possibility of legal action on a large scale?
Websites that use 2FA Phone verification: Abuse of privacy? What's that? This is for your 'security' /s
Honestly, I avoid services or websites that do this kind of nonsense.
For example, could some of us:
1. Create a website or piece of software that we expect will be used by some employee of Facebook, Twitter, Microsoft, etc., from their employer's computers.
2. Include Terms of Service and/or clickwrap terms that tilted in our favor. E.g., enter a binding covenant to never perform telemetry of any kind, with clearly defined penalties. And the user also releases us from any obligations we have to them via previous agreements, such as the right to forced arbitration, or their pick of legal jurisdiction for lawsuits, or us covering their legal costs.
3. Once there's sufficient evidence that someone at one of these companies has accepted these terms, and violated them, drag them through the courts. Crowdsource our legal fees to prevent them from avoiding discovery, or settling out of court, or converting to class action and buying off the class's attorneys with an ineffective remedy.
I see several acceptable outcomes of this:
(a) A competent court establishes legal precedent that shrink-wrap licenses, and/or onerous EULAs / ToSs are unenforceable. And/or
(b) We get some measure of justice by causing major financial damage to the companies and individuals who abused our trust in the first place, and perhaps some court-ordered consent degrees that will hobble those companies for decades. Or, worst case:
(c) Those companies' lawyers wise up to the risk of their employees accepting such license terms. As a result, those companies become very risk-averse to letting their employees install software or visit unvetted websites. Which makes those companies less productive, and less capable of retaining technical talent that doesn't want to live under such restrictions. Thus planting the seeds of their death by a more agile competitor.
EDIT: `s/two/several` because I can't count.
Can we change this submission to that?