533M Facebook users' phone numbers and personal data have been leaked online
businessinsider.com
businessinsider.com
So if that's the case, I think we should move beyond really even trying to think of this info as private or a marker of identity, and we need to move everyone to more secure forms of identity verification.
As has been pointed out on HN before, "identity theft" is a made-up concept to make it seem as if you had something stolen from you, when the real problem is banks and other service providers do an absolute shit job of identity verification. They're the ones at fault, and they try to shift the onus onto you to fix things when they screw up.
Indeed, a social security number is pretty much the only additional piece of data to the stuff above that one would need to open up a bank account in someone else's name, and those have been leaked plenty of times too.
The government needs to make harsher penalties for banks and others that can ruin your credit, etc. because they accept all this leaked info as "proof" of identity.
Then there is no "your social security number" or "your identity" for someone to open a bank account against. You open a bank account and they give you a bank card and you set an address and phone number. The day you open it, they shouldn't need to know who you are, because it's a new account with $0 in it. After that, the owner of the account is the person with that bank card who can be reached at the address and phone number given when the account was created.
Get rid of centralized identity and there is no centralized identity to steal.
Any time someone attempts to use your SSN to identify themselves as you, you should be notified and your authorization should be required for that use to be allowed.
And the higher the value of the authorization, the more care should be required.
Companies are able to do this already with 2 factor authentication. And I think we SORT of have that for change of address, as the Post Office both requires ID and notifies you by mail. Maybe that's really just one factor.
Allow people to require as many additional factors as they want. Confirming my identity in 6 ways when I decide to sell my house sounds good. 4 ways when I buy a car. One or none is fine when I make a $10 purchase. Let me decide.
And let them CHOOSE what organization manages authentication. A private company might do the job a lot more effectively than the Post Office.
Add human methods too. A call from a sibling or child might be one people could set up. Require validation by a notary public.
So now the government needs a way of contacting you. Suppose they have your address and phone number on file.
Then you lose your way a while and become homeless for two years. You can't afford a phone and no longer have the same address, and have lost your ID or it expired. You finally start to turn it around and go to open a bank account. The government contacts you how? How do they know it's you?
The answer is that it's a new account and you're not trying to prove anything about whether you're the same person who lived at the old address, so you shouldn't have to.
And once you have a bank account or a mortgage or such, you and the bank can arrange for any form(s) of authentication you like. It shouldn't have anything to do with the government, and it definitely shouldn't have anything to do with how you authenticate yourself to your job or your wireless carrier.
But the rest sounds plain wrong to me.
Your phone might get stolen, your name might change due to marriage, your address might change because you moved/got evicted. What now?
If someone steals your phone and password and bank card and ability to receive mail at your home address all at once then you're pretty screwed, but you're pretty screwed then regardless, right? That's the level of screwed where somebody else can also get a government ID in your name.
For example
123 Main St. Apt 45-WXYZ
Where "WXYZ" is different for each business, to pollute any data mining algorithms trying to collate my address across sites. In some cases when they use address resolving functions, it also helps to spell out your address e.g.
123 Main St. Apt FOURTY_FIVE WXYZ
Now, there is absolutely no reason it could not be OTP'd (or uniquely derived for each account).
Considering your phone number is more and more being used in 2FA ... if you were to ever change your number and someone else got it, this would pose a serious security risk if you failed to change over ALL of your internet accounts 2FA to the new number.
There are plently of other places we give our phone numbers to, which might not have anywhere near the protections that Facebook say they provide.
Lesson: Don't use your phone number for 2FA. Get a bunch of virtual numbers and redirect their SMS to your e-mail.
If U2F or TOTP is an option, use it. And use a physical key for TOTP, not some Google or Microsoft authenticator.
I live in the EU and I do operate under the assumption that banks take reasonable measures to ensure an account is linked to a legal identity.
I appreciate the pragmatic stance you take, and we should definitely move to more robust identification methods.
But making this case for better ID tech should IMHO not be confused with giving facebook and the others a pass. This should never have happened, and the very fact that we have a data trove this big is already a problem. That they don't seem to even attempt to protect that data is another one.
Close that shop up. The fines for this kind of stuff (and the other stunts they've pulled) should make it economically no longer viable to keep it open, really. The first time you fuck up this hard, the fines should hurt. This is not their first time.
The time to shutdown Facebook has past. Now we just have to suck it up and endure them and their effects like we do Cancer.
I am not from the US, but is this really all you need to "proof" your identity?
The most common thing I have seen in the EU when companies have a KYC requirement is that during the sign up process you will have a quick video call where you have show your ID card while they verify that your ID is legit.
Yes. I think the scary part is WHAT these identifiers are connected to. EG. your email being linked to a private antifa community, pro-Taiwan communities, adulteration meetups, etc.
Even if this info wouldn't be good enough to sign for official stuff it's still private and unique enough to target you though.
We should assume the leaked data doesn't go away; that instead people out there are consolidating Equifax data with Vastaamo data, adding data from Exchange hacks and the Accellion hack, to cross-reference with data from Facebook... it's like water flooding a levee now, instead of evaporating.
Not the first time I've harped here about this (ie: https://news.ycombinator.com/item?id=26604753, https://news.ycombinator.com/item?id=24586258), but I hope we start planning for that kind of future.
For example even though I am using a throwaway account, HN's logs might one day get compromised. So now they can join the IP address to other compromised sites that I was logged into using my usual email. And from my email they already have my name, SSN, address, phone number, usernames, passwords, etc, exposed from prior breaches. But now they know about my shitposts too.
It's risky if things go sideways, but HN doesn't require an email address for an account.
I don't trust in the government, but I think digital "personal data" should be only available for "confirmation" to companies that need it. Say, a government entity could have an API that allow you to send hashed personal data that they can verify is right. This way companies will ask the user for their data and hash it client-side. Then they can send the hashes (hashed with a custom provided salt to the entity (government, maybe private) who will basically reply with a True or False on the verification of the different data.
It may even be an interesting use case for a public blockcahin, where your personal data is stored in a Merkle Tree type of data structure, so that one can verify that certain pesonal data of a person is true, without disclosing the data.
For example Estonia has had famously and online identity stuff linked via a federal ID (in europe there are more republics then federations so it's easier to manage country-wise) [0] [1]
Or more familiar to me with a bigger sample is a movement in Poland which is gaining popularity - mojeID (myID) which is a Single Sign On system with major banks as providers (they really regligiously check the identities when you open a bank account) or the statebacked login.gov. The mojeID system allows other entities to use your actual identity as an authentication factor without having to keep that much data and pose risks - for example an online alcohol shop can verify the age. [2] [3]
[0]: https://en.wikipedia.org/wiki/Estonian_identity_card
[1]: https://e-estonia.com/solutions/e-identity/id-card/
Humans will error and enter data incorrectly so the hash would be different every time potentially despite being "correct" to a human at a glance?
You could standardise everything (lowercase etc) but I imagine there are country and regional edge cases such as capitalisation having meaning in a given language (I can imagine it being a thing but I don't know it for sure)
This sounds like a good use case for short brief documentation.
Equifax has more at stake than most. And they've been hacked. Repeatedly. The government has been hacked. Yahoo was COMPLETELY owned. I mean, if someone would put together a list, it would make for shocking reading. It's become so common, that we go, "Oh no! Anyway."
I think this demonstrates that user data can be managed safely and effectively.
Usually the incidents reports on user data leaks show that the company seemed to barely be trying - We need laws that force them (even small companies) to put serious effort into it.
Am I reading this wrong, or are you saying that activists would be more likely to leak data? Then I would wonder what kind of activists you have in mind.
Agreed that yes indeed it seems possible to build a security serious company, and that Google is (seems to be) a good example. (Now, there are other things I don't like about Google but I guess that's of topic.)
Ideological employees of big tech firms taking a sudden disliking to someone or some group and abusing privileged access is certainly a threat that ever larger numbers of people are talking seriously. In particular, it is a concern for industries that do things activists don't like, such as working with immigration control (though perhaps that's no longer an issue now Trump is gone).
- "How much money is currently owed in taxes to the government?"
- "Can't tell you that, we're not allowed to aggregate data".
There is no way to let a user find their friends on a service without such an API. Yet if you have such an API, someone can simply brute force all phone numbers worldwide (there are only 10^10), and now they have a database of all users...
Rate limits can help defend, but considering many users might have 1000 phone numbers in their address book, you can't set the rate limit very low without impacting user experience. Attackers can reduce the search space dramatically by only checking phone numbers that resolve to an active line (using VoIP stuff to test a number).
The only real solution is for your app not to have a "Here is a list of your friends already in the app" screen... But as you can imagine that means you won't get any user growth or VC funding...
Also, at least some countries have longer phone numbers (Germany, the UK and China have 11-digit ones, for example), and the international public telecommunication numbering plan says plan-conforming numbers are limited to a maximum of 15 digits, excluding the international call prefix (https://en.wikipedia.org/wiki/E.164), so the search space, potentially, is a lot larger.
Canada and USA share the same numbering plan and that's sometimes overlooked.
I always "press 1" to interact with the 'your social has been criminally suspended blah blah' or 'card-services' robo-calls.
When I have time I share circular stories about my grand-kids that don't visit me anymore, but when I don't, I just respond in French with something like "Je pense vous etes une pamplemousse."
Most recently, one responded with "NO HABLOS ESPANOL". lordy lordy...
Facebook could have an API by which an app can prompt its user to show a list of all of that user’s friends who have the app installed. The app would only learn the identities of people whom the user explicitly selects, and phone numbers would not be part of that identity.
But for phone numbers, you about protecting Facebook API (which is publicly available via the internet) against arbitrary devices, which Facebook has no way to tell from legitimate ones
But in this case, it’s important to remember that phone companies used to regularly leak most of their customer’s phone numbers (and names) in the form of a telephone directory. So a question to consider is: suppose that the white pages were still commonly produced and contained most people’s numbers. How would you then feel about something like this.
Personally I feel like the problem with phone numbers being leaked is mostly the epidemic of spam calls (especially in the US) rather than some particular breach of privacy.
Aside: I think it is good to consider these counterfactuals in general for questions about information privacy, for example how would you feel if everyone’s tax returns were published publicly like they are in Sweden?
We still get spam on both numbers within short time frames - so I'd say it's likely spammers just auto-dial through.
As for public tax returns in Scandinavia, first of all it has guardrails - searches are recorded with your information when you lookup someone - and second, countries have different culture and History for a reason.
I think the comments I most agree with talk about the different security threats people face today with current usage of phones.
Now suddenly a “white pages of cell numbers” becomes a very convenient tool for getting in to people’s accounts.
We don’t have the option here — people provide their number to a service to be able to use it, and the numbers are then compromised, in breach of that contract and because of the service’s failures.
The two are not remotely alike, what the fuck are you even talking about.
If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html and sticking to the rules when posting here, we'd be grateful.
the security handbook[^1] has a chapter on that actually, and they basically say that role playing is the only way of not getting burned. Humans are excellent at role playing, and it can help you prevent a lot of catastrophe without having experienced them before.
Mark Zuckerberg probably spends more on personal and family security and privacy than Facebook spends on their users' security.
At this point I’m not really sure what it will take for companies, like Facebook, to understand that you need to not fuck around with peoples private data.
Ex, pay x amount per month in perpetuity for each piece of information about a user your keep. And have to pay the "net present value" of those payments if you lose the data.
Having to pay for hoarding user personal data changes the incentives from gobble up as much as possible, to instead only pay for a users data that is worth the cost to your business.
And as an extra incentive to not hold unneeded user data, know the costs you'd pay if it was breached.
Is there a trustworthy phone number version of https://haveibeenpwned.com?
An "exact" google search excluding adjacent phone numbers seems to work well for my numbers, and culls a lot (not all) of the autogen pages. So if your number was 212-555-1239, search Google with these strings:
"(212)555-1239" -1240 -1238
"212-555-1239" -1240 -1238You can also have more permanent proxy numbers for services or people that may need to get in touch with you long term.
Your existing cell number can be ported over to Twilio if you are patient.
The only problem is trying to use the number for 2fa. A growing number of banks (like Capital One) block Twilio services from recieving their SMS.
Can't say too much about trustworthyness though.
U could also just download the set from e.g. raid forum to check for yourself.
If you're in Europe, but don't share a language with a much poorer country, you're safe from these.
The odd thing is, the calls often come through having a caller ID very similar to my own number.
Either way at this point I operate under the expectation that most information I input into a database may be leaked at some point. This is particularly rough for services that demand and track a lot of things, but it cannot be helped.
sqlite> select company, count(*) as c from usa where length(company) > 0 group by company order by c desc limit 10;
company c
---------------------------------------- ----------
Self-Employed 459119
Facebook 181013
Retired 71210
The Krusty Krab 61550
Hollister Co. 42304
U.S. Army 39682
Stay-at-home parent 33095
Walmart 31600
McDonald's 30792
Student 25326edit: found it :) >> https://www.youtube.com/watch?v=q7Ufkf0YVAk&t=290s
Probably SpongeBob fans.
I deleted my account when Facebook started asking for is verification of my name, that was absolutely unacceptable.
It's FLOSS. Available on Windows, Mac and Linux.
sqlite> select count(*) from usa where length(company) = 0;
22209703
sqlite> select count(*) from usa;
32315270if something sounds like a hyperbole, it probably is. In this case I believe you are mistaken, and the Yahoo breach of 2013 was the largest, with data leaked from over 3 billion accounts.
[0] https://www.nytimes.com/2017/10/03/technology/yahoo-hack-3-b...
99+% of every single person you meet has either FB, IG or WA installed on their phones and shares their phonebooks with them (assuming you live in [insert western country here]). There is also a very big chance at least some have your full name and address in their phonebook. Facebook not only knows who you are, but also who you are in contact with, when you meet new people and who they are. They also collect phone and text records with their apps so they also know the frequency that you have contact with them and they can even read the content of text messages (most people these permissions to the apps because it will automatically verify the associated phone number). Add all the location data, ssid/mac address collection and countless of other datapoints to it and they can draw out your entire life even when you don't use anything from facebook. There is no escape.
citation very much needed
Get a virtual phone number if any service requires a phone number from you. Don't submit to this nonsense.
They are like the credit companies, they have information on you whether you allow them to or not.
1. At https://www.facebook.com/USERNAME/about_contact_and_basic_in... - there's a contact info section where one can fill in a phone number (among other details) and set the visibility to Public/Friends/Friends except <group>/Only me/Custom/custom lists.
2. And https://www.facebook.com/settings?tab=privacy - there's a "How people can find and contact you" section that covers "Who can look you up using the phone number you provided?" with options of Everyone/Friends of Friends/Friends/Only me. I imagine it'd be very easy to select the wrong thing during setup due to the overwhelming number of things to read and click.
I suspect those who have set the latter, or both options to "Everyone" will most likely be in the "free" data dump (except perhaps for most Australian Facebook users, for now).
I feel the second setting is riskier, especially if you don't want employers or colleagues to be able to simply look you up on Facebook by phone number. For example, I could hypothetically display my phone number to "Everyone" on an incognito profile and no one should be able to just wander by and spot my profile and immediately figure out who I am (assuming this profile doesn't somehow get suggested to "Friends you might know" - big assumption, yes; but this would depend on how I complete my profile). Regardless, either one or both set to "Everyone" is a recipe for disaster.
I believe more people would have allowed number searching compared to those who just have their phones displayed to everyone on their contact info sections. In effect, it's a bit of a reverse phone book, plus extra.
I am doing the same boat...and was working fine until i lost & replaced my old phone. All conversations were lost, and this makes it challenging to use whatsapp for any non-group conversations (since I can't start any).
Quote: "WhatsApp, which was acquired by Facebook in 2014, does share some limited data with Facebook, including phone numbers. However, the firm has reassured users that messages will always be protected by end-t0-end encryption, which means neither WhatsApp or Facebook can see these private conversations"
Source: https://www.forbes.com/sites/carlypage/2021/01/15/whatsapp-d...
And since it's a Facebook controlled company a leak like this happening again isn't that improbable.
But Facebook has no history of lying right? /s
Someone scraped some public profiles. Someone then brute forced a poorly implemented "look up by phone number" feature. They linked the two datasets on the unique facebook user id.
Leaking data that is or was in the public domain is not much of a leak. The only noteworthy thing would be the leak of the non-public phone number, however that vulnerability has been widely known since 2019 (and has been resolved by Facebook), so there's nothing new here?
Where could I, or any Internet user, trivially download these details on 533M Facebook users prior to this dump? If nothing else, it seems extremely noteworthy that someone was not only able to obtain the data through scraping or some attack, but has shared with the world.
On Facebook. Literally. You can scrape any public profile info. It's against ToS, but it's not illegal (some caveats apply, see the hiQ Labs v. LinkedIn case for more info).
The only noteworthy thing is the phone number vuln. Except that's been known since 2019, so it's certainly not news.
>This is old data that was previously reported on in 2019. We found and fixed this issue in August 2019.
I've been pwned 33 times. At this point, it's just noise. My passwords are all unique (password manager). Honest question - What should I worry about?
I guess I could envision a scenario where you're being investigated, and these leaks provide a roadmap of services to subpoena.
Hopefully this disaster will be the catalyst for better data privacy controls.
Is doing so legal?
If the answer to both of those questions are yes... I'd like to take a peak. Mostly to check whether or not some numbers I know haven't been directly give to fb are there.
So, can I assume this leak is related to this strange event?
Search for :YourFirstName:YourLastName:YourGender
It's the same as how unsympathetic people ask why fat people don't just stop eating, or drug users stop getting high, or the cyberbullied don't just turn off their phone.
It's a lot more complicated than "just don't use facebook".
I wonder if my phone number still persists (aka "soft delete")
I'm slightly concerned about this myself. I'm also seriously ticked off with Zuckerberg and co. I can tolerate the fact that internally they do scumbaggy things with my data. I tend to have less forbearance when they let my data out into the wild.
Well the biggest offender now has leaked the data of hundreds of millions of users who have attached their phone numbers and full names.
Now let's see if the users REALLY care this time that when they signed up to Mark Zuckerbergs website, it wasn't a good idea to sign up with a phone number in order to 'stop bots'. They did not learn with the Cambridge Analytica scandal, are they finally going to learn?
A lot of password reset flows work via username + SMS using "we've sent a code to your phone number (xxx) xxx-xx12". This database unmasks that phone number, so my assumption is this makes sms hijacking more viable, but perhaps someone more knowledgeable can weigh in.
Does Facebook allow password resets like this, and can that be disabled?
Absolutely not
[0] - https://venturebeat.com/2011/08/09/hacker-group-anonymous-th...
(Easy enough for me to say, I never gave FB my phone number in the first place, I've never logged into FB on my phone, and I'm not in any of these files.)
The cats sorta out of the bag, but one can dream.
Long story short, regulators already have more than enough evidence about Facebook's lack of GDPR compliance so they could've already imposed large fines if they wanted to. The fact that it hasn't happened yet shows there's no motivation to actually enforce the regulation.
But Facebook have enough money and lawyers to ensure a plea deal is agreed. We work out as nothing more than a slap on the wrist.
All the big tech companies budget for these fines. You'll often see it called out at earnings where they allocate funds for a particular fine in a given quarter even though the investigation isn't finalised.
I use Facebook a LOT less nowadays though. Here's what I do:
- removed all of the apps from my mobile devices. - only check it on VPN, with Firefox, using Facebook Containers. - log out each time and do not use the "save this browser" feature. - unlock origin & pihole are active on the VPN too.
I have managed to completely ruin its targeted ads for me. It's been an amusing experiment.
I still use it less because it is a HUGE memory & resource hog and eventually makes my browser window slow to a crawl.
Facebook/Google (et al) farms data from everyone! There really is no escaping it in today's unregulated privacy free-for-all.
Friends/family/associates will provide your personal info in their contact/meta data.
Companies (and their 3rd parties) you've done business with willingly sell/provide your personal info.
Everyone I know uses messaging apps and contacts me that way.
I can’t believe Apple hasn’t offered a way to white list when your phone rings.
update: oh no, "...the data was scraped due to a vulnerability that the company patched in 2019."
A quick google indicates "maybe": https://about.fb.com/news/2020/06/may-cib-report/
Like for real, it took me 2mins to find the leak myself...
I haven't checked the content myself, but this tg channel is usually legit
https://raidforums.com/Thread-SELLING-Free-FaceBook-533M-rec...
However, the comments in that forum suggest that it's not "free" and/or not there.
Regrettably, I was forced to create a FB account for work.
After a leak: ok that's life
There are risks: stalking, sim-swapping and phishing via company info.
(before you post a link to enforcementtracker.com please first compare the fine amounts with Facebook's revenue)
Not having the data encrypted at rest seems to me a different infraction than the previous ones. The scale also matters, and that it isn't the first infraction.
And as I read it, not encrypting at rest is a breach of Article 6 and fined under Article 83 (5) (https://www.privacy-regulation.eu/en/article-83-general-cond...), which puts the fine limit at 4% of the annual turn-over.
Yes, it doesn't mean they have to fine as much, but the point remains, that this is in the category of the most severe infractions.
The sooner we get rid of the cancer that FB is, the better. I didn’t share my contact book with FB apps either. It was probably her—a person in her 70s, not necessarily experienced with tech.
The main reason this company exists, or that ad tech can maintain a facade of not being a mainly bullshit industry with made up metrics, is the lack of informed consent.
It’s almost funny how we accept the current situation as normal. Because, I think that we’ll look back at these times with disbelief of reckless we were and how cheap we’d sell ourselves.
I wouldn't throw the elder person under the bus on this one, the tactics are sophisticated, and honestly, just a precursor to what will happen with AR.
To give a bit more of how it's implemented (at least how I would propose it in iOS), Insta/FB/Whats queries available wifi SSIDs as a background process (or whatever they have for notifications/networking etc), and does the same to your therapist since you both have insta / fb / whats ... and based on the signal strength, can say with confidence you two were in the same room because XYZ Wifi strength is -Xdb just like yours (walls are strong signal augmenters), and you are both there for some time based on the background thread timestamp.
what's making it possible is the lack of privacy regulation. People by and large don't care enough about privacy,it's too diffuse, too complicated, the damage to oneself and others is too intangible etc.
Only way to end this is to destroy the business models that make it possible. What stands in the way of it is the mindset that this somehow harms innovation. (Innovating who can drive the titanic faster into the iceberg isn't innovation), that the government has no right to regulate private companies, and so on. The main problem is that people are trying to incrementally fix a broken thing, as Peter Ducker said
"There’s a difference between doing things right and doing the right thing. Doing the right thing is wisdom, and effectiveness. Doing things right is efficiency. The curious thing is the righter you do the wrong thing the wronger you become. If you’re doing the wrong thing and you make a mistake and correct it you become wronger. So it’s better to do the right thing wrong than the wrong thing right. Almost every major social problem that confronts us today is a consequence of trying to do the wrong things righter"
There should also be transparency of who has the consent right (data licensee and sublicensee)
And there should be a way to make easy consequences for people not having it
Release forms and licenses are used this way, data should inherit that. (Both systems should be better)
What about your phone number? Does your therapist have it? Maybe your therapist granted Instagram/Facebook access to her contacts?
Or maybe you yourself granted Instagram access and your therapist is in your phone's contact list?
I'm no attorney, but isn't there a doctor-patient confidentiality breach (in the U.S.) if a psychologist/iatrist's rolodex gets Facebooked out to the ad tech bidding systems?
Exactly, the industry is built on a foundation of obfuscating the myriad ways in which they are using people's personal data. Uninformed consent is the cornerstone of their business model.
I know it’s not easy if you are addicted to it but it’s doable.
Cases like yours is why we created https://yourdigitalrights.org/d/facebook.com, which makes its dead simple to send such requests. Free & open source.
So what? What's the harm?
People sure like to write emotionally charged posts arguing for privacy, but they're always suspiciously low on details on what bad things (actually) happened.
Even in this case with phone numbers and other data leaked, so what? What harm do data leaks cause?
Seems like making a fuss about nothing.
> How are we still ok with this shit?
We're ok with a lot of shit. I think if we were to make a list of shit this would rank pretty low.
This may sound extremely cynical but at this point it's the only way for the non-technical folk to understand the implications of giving away your privacy so that you can share cat pictures with other people.
Very strange to wish harm upon your friends with the hope that that will convince them to join your side in a political fight! I would suggest instead that you only wish that if it becomes a painful experience, they would realize why and renegotiate their relationship with FB. Typically wishing pain on your friends is not a good stance.
I think most normal people acknowledge that so many companies know their phone number and name that they may be past caring.