Mark Zuckerberg's phone number appeared among the leaked data of Facebook users
businessinsider.com
businessinsider.com
However recently, I've noticed that I now get a couple of junk text every day or two whereas up until a few weeks ago, I don't think I'd ever had a single junk text.
I wonder if this is why.
I think this is a symptom of living in the US. Been receiving robocalls and text messages all the time since I moved here.
Consider signing up for the Do Not Call registry. Does not do much against the scammers but you will receive significantly fewer telemarketing calls.
I haven't looked into it recently, but it must be easy. Many games have SMS verification for accounts, and it seems that every person that streams those games has like 10 accounts.
I never gave Facebook my phone number.
I never had a Facebook app on any Android device, ever.
When I use Facebook, it's in a sandboxed browser that I never log into any other site with.
Facebook, for a time, started autofilling a prompt with my phone number, asking me to complete my account setup.
When Facebook has an app and all the people you know send their contacts to it, they don't need you to give them your phone number for them to have it.
The one I got late last night was pretending to be from the US Postal Service, prompting me to click on an anonymous link in order to "rescedule delivery"
In my field - politics - campaigns use tools like Hustle which are basically mechanical turk clickers to get around these rules. I'm thinking personally this will change...
This brings up the side issue that the act doesn’t ever mention text messages at all ... everyone has interpreted them to be covered as if they were phone calls, but that’s never been tested at the Supreme Court level.
The system will continue to not work when Congress does not do it's job.
As an example, if this law were written today, I'm not sure that cell phones would get special status. They were put in the same category as medical emergency lines, because "radiotelephones" were very rare and expensive to operate, whereas today every 12 year old has one.
The law essentially says "it is illegal to call someone using an autodialer, where an autodialer is a device that makes calls to phone numbers using a sequential or randomized algorithm." It's pretty clear then that automatically dialing from a prepared list of actual phone numbers is not against this law. If they wanted it to cover the latter case, they could have easily included that in the law, even 20+ years ago.
edit: but now I'm curious if franking privileges were ever extended to telegrams.
So how can we cause the email market to fail in a similar way? ;-)
Isn't it rather they was it is supposed to be? - "Everybody" uses messengers for communication. SMS has lost that battle. Whoever uses SMS does so due to a need.
How do you handle group chats? Especially with more than a couple of people? Is sending pictures and videos included with your plans too? If not how do you handle those? How about video calling? Sending a file e.g. an Excel file?
Let alone features like easily creating a vote/poll, a calendar event, a banner notification..
I get that most of these features may not be useful to everyone but surely they are to groups of teens and college students, demographics that have shown to often drive growth in communication apps.
Probably 80% have Facebook, 50% iMessage, 30% Discord 20% Twitter/Signal/Telegram/Whatsapp (pre-FB).
What messenger app can you depend on everyone having if not one of those three federated platforms?
Nearly all of my 40 something friends from the Midwest have both telegram and discord, however telegram is primarily used as its just better on mobile. We have groups for all kinds of topics, cars, garden, tv, movies, sports, politics (ewww), etc. If you aren't interested in lawncare simply leave or mute the group in remain in touch via other mutual groups. The only guy not in the group is someone who still prefers phone calls.
I've yet to not be able to convince someone that separate threads/groups is way better than a bulk text group.
In Australia a SIM card can be purchased retail, with unlimited texts for $5.
At 750~ texts sent you’ve already beat that wholesale rate. That’s approximately one an hour, over the month. I’d be surprised if they couldn’t pump much larger volumes.
You’re putting a lot of faith in telcos to care enough to put systems in place.
And spammers will burn through sims. They are looking for the most lax network for sending. Presumably the receiving network can block texts arriving, but wouldn’t actually stop a number on a competing network from being able to send messages (but would likely flag it to them).
And then there’s the time delay to be exploited. If it takes 3 days for a number to get blocked, can you send enough messages in that period to make it worthwhile?
Barely any, tho I get tons of "SSN been hacked" and "Lower your car insurance" scams, sometimes more than once a day.
Many of my spam texts seem to know what state I'm in despite my area code being assigned to a different state, so I'm guessing they get them from voter records, political donations, that sort of thing.
Even if you don't sign up for FB, they get your contact information from your friends. (That might just be WhatsApp, but at least one of the two gives people the "opportunity" to upload their contact list to find matches.)
Sure, FB knows a lot less about me than they could, but keeping off their radar entirely is effectively impossible.
See Facebook "shadow profiles", data collected on persons either through third-party activity (though the profiled individual is on Facebook), OR on persons not using Facebook at all.
https://theconversation.com/shadow-profiles-facebook-knows-a...
https://www.dailydot.com/unclick/facebook-shadow-profiles-pr...
This makes me think of this one fascinating/frightening prospect I sense in respect to the vast collections of data of human behaviour which the big tech corporations have: The data that Google and Facebook posess are so rich that they'd allow very insightful analyses of human behaviour. I recon there are so many small questions about why people do what they do, how their whole personalities are wired, how they influence each other through internet/analog interactions, how societies develop dynamically through which mechanisms.
Many of these questions are being studied by scientists at universities but they usually don't have the same huge/rich data sets that the internet giants have.
So Facebook & Co have a huge advantage in understanding all these things about humans over public research. But whenever they actually do some analysis and get answers, the result is by default internal knowledge that remains unknown to the public. Also, most of their analyses will be driven by commercial interest, rather than seeking anwers to philosophical questions that don't promise financial returns.
There are many questions about our world that could have been answered since years, using all this data ... but they haven't been and might never be.
Letting some big company have the power of understanding how people tick better than any other agent in the world. A thrilling prospect.
I'm glad you're here to establish this objective fact for those of us who didn't know ;-)
My mom was recently told by a state elected representative that she would have to contact them through Facebook to provide feedback on legislation. This is not a “valid tradeoff” nor does it have to do with “entertainment”.
Complain loudly, and delete your fb account. Be a nuisance about it at club meetups.
Caving just makes it worse for the next guy.
The carriers are cracking down on sms spam. They are going to force registration of all businesses sending texts, not just with services like Twilio, but with them. And prices / rent-seeking from the carriers is going up - they are going to charge for each campaign/brand you run. So in the end you’ll see less spam, but texting will also cost more for companies that send them.
The initial rollout by AT&T was supposed to start 5/1, though that’s now been pushed back. Spammers are likely in their death throes, trying to get their last spam out before they get shut down or priced out.
If one really wanted to use a phone number for sign up, a disposable number such as a "burner" phone should work.
What does the email-only flow look like? Every time I've tried that I've been redirected to various kinds of "additional authorization" or "proof of identity" barriers and haven't been able to find a flow around them.
1. The website was originally created for students and sign up used to require a university email address.
> But for spam based on using phone number alone, it's gold. Not just SMS, there are heaps of services that just require a phone number these days and now there's hundreds of millions of them conveniently categorised by country with nice mail merge fields like name and gender.[2]
> Another general observation on this incident: I'm seeing extensive sharing of the data, both the entire corpus of countries and individual country files. Not just in hacking circles, but very broadly on social media too. This data is everywhere already.[3]
> New breach: Facebook had 2.5M addresses exposed in an incident that impacted 533M subscribers' phone numbers. Most records contained name and gender, many also included DoB, location, relationship status and employer. 65% were already in @haveibeenpwned[4]
> If we look at the data, email is rare, DoB is rare so the greatest impact here is the phone numbers. Even though it’s “only” 20% of FB users, the number is obviously substantial thus so is the impact[5]
[1]: https://twitter.com/troyhunt
[2]: https://twitter.com/troyhunt/status/1378485999781613569
[3]: https://twitter.com/troyhunt/status/1378513457209696256
[4]: https://twitter.com/haveibeenpwned/status/137855490210063565...
[5]: https://twitter.com/troyhunt/status/1378474534760685568
What's a good way to know if myself or my loved ones are in it?
"I’ve had a heap of queries about this. I’m looking into it and yes, if it’s legit and suitable for @haveibeenpwned it’ll be searchable there shortly."
I'm sure it will be.
> And no, I have no intention of adding phone number search in the foreseeable future. There's a User Voice suggestion for that and a comment from me which boils down to "much higher work and much lower value"
> I also can’t parse the, out with a regex like I can an email address as they don’t adhere to a consistent format. Further, the inconsistencies in format make searching difficult as they’d have to be “normalised” and that’s something that’s very country (and even region) specific.
https://haveibeenpwned.uservoice.com/forums/275398-general/s...
I made a Google search 8 hours ago. There were 10 pages hits of link spammers where you have won an Iphone, but they don't have the data. So, yes public interest seems big. I wonder why Google cannot catch those, after opening the first one I could recognize the rest from the address and the snippet. Google did not have a correct link that still had the data. Maybe they are not publishing those, getting bad reputation to big data is not exactly in their interest.
So is this breach related to reusing or having a weak password?
Or is it completely independent?
(Less, depending on the number of folks with multiple accounts, which FB seems to try to prevent?)
https://www.reddit.com/r/dataisbeautiful/comments/mjufnx/if_...
Also mildly entertaining to see some names that are probably test accounts now associated with Facebook people in Google as people try to see who they are.
"People just submitted it. I don't know why. They 'trust me'. Dumb f*cks."
I know Congress has tried calling upon him and just gave up.
Who would even assume that such a thing would not be outsourced if it were affiliated?
And "a priority incident" can't be a misrepresentation inasmuch as "priority" is inherently relative.
As a matter of "legal realism" people might be right that it would land you in prison if you are just Joe/Jane Schmoe. But I see absolutely no logical justification for that when companies do things at least as shady all the time without serious consequences.
It will be a more modern '867-5309', however instead of people searching for love it will be a consolidation of the collective hate for a single entity/person.
The spam I see and hear about is just random dialing from Albanian numbers, hoping that you’ll call back.
It might depend on your country, but I can’t think of a single service where you’re required to make a call anymore, it’s all online. There might be a few services for the elderly and handicaped, but again that’s you calling in.
It's the most identifiable thing about me other than my social security number. Even my driver's license number has changed more than my cell phone, and I don't always have a valid passport.
Determined person can use the various leaks and other data sources to collect more detailed profile of you (and millions of others). This will eventually allow them to setup more targeted and personalized spam or phishing campaigns.
We need to regulate this.
Remember all phone-numbers used to be in a public book called "Phone Book".
Yes they can, they can totally do that and if they do you're screwed. https://www.theverge.com/2021/3/15/22332315/sms-redirect-fla...
Edit: I forgot about haveibeenpwned.com. Any info about when they will add this leak?
Edit2: Haveibeenpwned added 2.5 million email addresses. But it's possible that my record doesn't have email.
So I think it's time to use UUIDs instead. They're hard to type, but you hardly ever need that.
What am I missing?
UUIDs are horrible. While a computer doesn't really care about the way an identifier looks, humans sometimes do need to look at them and operate on them (compare them, transcribe them, dictate them, recognize them).
It is true that it's difficult to compare and transcribe.
I could not find anything and then I encountered your comment. Apparently, your unbreakable long word makes the site very wide.
I didn't know comments can affect how wide the page borders are. Is this not bad UI? I am unsure who to ask.
There is a contact link in the footer too, you know.
But yeah, seems like bad UI. I would have thought overflow-wrap would be set on posts.
I've added whitespace to the GP comment now.
One of the annoying things is that there's a timestamp making up the 10th column that has ':' in it, but the delimiter for the fields is also ':', so it makes a clean import to a database a bit of a hassle as the file may need some processing, probably will just do a find and replace as all the time stamps seem to be 12:00:00 AM. The column holding the current employment is also problematic.
I'm assuming there's a better way w/ regex but I'm not great with regex. Could probably find that with a few minutes of google though, just replacing the pattern of :##: with -##- using numeric wildcards.
I only tested the Norway link in his post but that was legit.
(I first verified with Virustotal and then thought twice before opening the zip file.)
I need to know what I need to protect my family and in-laws against this time.
Edit:
- yes, I also immediately downloaded the "manifesto" of the mad bomber in Norway ten years ago, not because I admired him but because I despised him.
- Troy Hunt keeps downloading data sets with peoples personal details (logins even) and is not getting into any kind of newsworthy trouble.
There are things you should be very careful with, both in physics (don't hoard fissil material), chemistry (same with various poisons), biology (don't try to get hold of smallpox etc) - and data science (certain images are forbidden for what I think is good reasons), but I don't expect police to show up on my door because I have downloaded a publicly available data set and grepped relevant names from it and then forwarded the relevant lines to the ones I found.
Edit 2:
I also had a copy of MyDoom somewhere, I think on a disk that is broken now. Never got in trouble for that either despite telling people.
Maybe don't say it online under an identity that is strongly linked to a piece of meat that might be put punished ;-)
Those certain images you described are publicly available too. That doesn't make downloading them _legal_.
The fact is you've a dataset containing personal data of millions of people is obviously illegal -- why this didn't raise red flags in your mind is curious.
Edit: I'd certainly not expect police to kick your door in either, much like if you pirated a movie.
My point is: be careful.
If you half the number, it would be just 453,223,693 more than world population as of March 2020 according to Wikipedia’s article “World Population”.