HaveIBeenPwned adds yesterday's Facebook breach
haveibeenpwned.com
haveibeenpwned.com
>500m Facebook records were leaked and <10m records have an email address — far more records are phone number but no email.
No interest in seeing other people's info, but I want to know if I'm affected.
There were links to a ufile folder with all the zips on here yesterday.
I took a peek, relieved I wasn't in there.
The pastebin with the links got taken down, although there's an archive.is mirror of it. The forum where it's from also has torrent magnet links.
>I took a peek, relieved I wasn't in there.
AFAIK it was publicly scraped data combined with the exploit to get phone numbers[1]. If you didn't have a public profile you're probably safe.
Uh, what?
After that, you'll find that the data is poorly and inconsistently encoded (lots of ugly BOMs), a bunch of files are split in weird ways (that I had to concatenate then give sensible names to). Figuring out what order they go in (they're not all split on a record boundary!) may take some translation, too. After that, a bunch of them have bad, broken CVS headers and you have to find something that can manage huge files to edit the first couple of lines.
Then you find that all of them use different delimiters (colon or comma), some of them quote each entry, and they each have a different set of data that doesn't match up at all. I'm still trying to figure out what the data in each file is and see if it can be normalized into one schema.
So it's about like downloading a phonebook for half the world with some extra mystery data that has no description where you have to guess what it even means.
Interestingly, I checked for a family member who deleted their FB a few years ago and they're not in there. It'd be interesting to see if there are any accounts that deleted before 2019 in the data or not. I suspect not, but this isn't enough of a test to prove it.
This is not particularly high quality data, I'm sure a lot of people didn't look at the data very much and just ignored a few lines of errors on import or did simple greps as you say because it's a pain in the rear to find editors that even can handle multi-GB files, etc. Even good converters like iconv can bomb out on, I think it was Qatar (which was also little endian UTF-16 with a BOM), etc.
But yes, it's all over the place. I love how one of them decided to number things 1, 2, III, 4, though maybe that was the translator, I dunno, I never learned to read Arabic letters...
Because yeah, let's just store a lot of data with commas in a CSV file, that won't make it obnoxious to parse or anything...
Unless you hire an attorney that knows these laws... because not even attorneys can know all laws.
Discussion here: https://news.ycombinator.com/item?id=26702473
It's also an interesting choice for a search tool for a quasi-public dataset.
Facebook then allows the person collecting phone numbers to search for the name of the user associated with a phone number (or email address).
I would recommend people check for themselves.
So I'm very interested about any insight you may have.
--
https://boards.4channel.org/g/thread/80982465#p80984158
> Anonymous 04/04/21(Sun)19:14:02 No.80984158▶>>80985592
> >>80984122
> That's because it's the austrian dump file. There's an update with the australian dump in the original raidforums thread, it's just missing from the pastebin index
--
https://boards.4channel.org/g/thread/80973470#p80985270
> Anonymous 04/04/21(Sun)21:15:35 No.80985270▶
> >>80985097
> they were mixed as one file. leaker was australian
--
I obviously have no citations of my own for this anecdata.
Regarding the first post, I went through approximately ~80 pages of "thanks", and one pair of mildly sore eyes later, was unable to find any "update". A torrent *was* posted somewhere around page 80 but this had the wrongly-named file in it. I have also seen a few TG groups that have renamed the file, but it's still the wrong one (like the GP described).
I can confirm that Austraiaia has an eclectic mix of Australia and Austria though - and also that grepping for 'Australia.*Austria\|Austria.*Australia' returns 170 results, grepping for 'Austria' returns 446375 results, and grepping for 'Australia' returns 408 results.
As far as seeing what was leaked, you could find the data yourself (but I'm uncomfortable giving instruction on how to get it). It would be nice if it was possible to extend the tool to be able to send the information for a number to the number (because that's the only way I can think of that demonstrates ownership of the data) but that can't be done for free and it therefore seems too complicated to set up.
Eagerly awaiting the news that Facebook takes security seriously.
There are 3 top mobile operators in Russia: MTS, Beeline and Megaphone. Each of them has its own set of phone codes. Majority of MTS and better half of Megaphone numbers are not affected, but all Beeline codes are exposed.
Have you checked the other entries to see if they are mis-categorized?
The ones marked sensitive have more a pattern of "we don't want to be caught in a court caste about hosting the info" than a pattern of trying to improve privacy in the ways this thread is suggesting.
If you have the data itself, then lookup is as simple as 'grep' or 'ctrl-f'
So anyone who has the means to compromise someone they're looking up by having the data doesn't need the HaveIBeenPwned tool in the first place.
Moot point, IMHO.
...and that your friends deserve a better friend than someone who would look up their email addresses to embarrass them.
My public email address is not the one I use for logins anywhere.
When you register for notifications it sends out a verification email. That would be a good time to let you disable public lookup of your email address.
I also wish HIBP could securely disclose the snippet of information from a leak that's relevant to you. Knowing the password or hash characteristics, phone number, etc. could aid in mitigation, and seeing the raw impact might help motivate ordinary users to improve their security hygiene.
Suggested that idea to Troy in the past, and got the impression he's not amenable, largely due to the risks of hosting PII. Can't really blame him.
For anyone else who's hesitant to use the link, these are the three choices presented when you opt out: https://i.imgur.com/4lB2bSq.png
If you pick the first one, you can still use the notification service (https://haveibeenpwned.com/NotifyMe) to email yourself a private link to check what breaches include the address (past and current).
There's still a need gap to detect leaked file data online, Say after a ransomware attack our files end-up in pastebin[1]; currently there seems to be no way to know unless manually monitoring sites where leaked data is posted or for the attacker to themselves let you know.
[1] Added in my profile.
Did I give a fake DOB. Is it a previous address? Do they actually even have an address or is it just NULL for me? HIBP won't tell me.
99.99% of people would not go through this effort and lack the skill/knowledge, even if they were motivated against someone.
But I appreciate your point.
https://en.wikipedia.org/wiki/MongoDB_Inc.
PS Hello from the south island
Consider just how "excellent" MongoDB was as a database before they bought Wiretiger and made it default. Ahem.
Dumps should be made public, like exploits.
username and SHA/MD5 password dumps are more interesting to analyze though.
Have you found other leaks on btdb eu previously?
You seem to be throwing shade at a service and person you haven't researched and all behind a new account. Very brave of you.
The notion itself of revealing info about you to a 3rd party in order to verify that more info hasn't been leaked seems... conflictual at some level.
Your account presumably isn't new. Are you any braver?
It's not that hard to trust their honesty, the real question is will haveibeenpwned get pwned itself?
Email address A was a gmail address and is a single dictionary word. I moved away from it as a login email due to the tendency of people to blindly spam it and it being used as a throwaway email address when people sign up for accounts. At this point I've had to purge a half dozen accounts people created on Facebook using my gmail address. The most recent one was created 4 months ago. Due to a rapid succession of logins (South Africa and United States) geometrically far apart, it was flagged and disabled.
I started using a different email address for my Facebook login a little less than 2 years ago. It is a custom domain name.
Neither showed up in the Have I Been Pwned lookup tool under this Facebook breech.
So it would be nice to have a service where you put in a phone number and it will list what information is available for it. Like this:
[X] Phone Number
[X] Name
[X] Current location
[ ] Previous location
[ ] Current employer
[ ] Email address
[X] Birthday
[ ] Full date of birth (with year)So I did the same search on dehashed.com, and got no hits (the part before "@" gets hits, but I don't care about that).
If the data comes from dehashed.com, why don't I find my email there?
I'm interested in knowing what, if anything other than my email is in there, because if anything significant is there, maybe I can figure out where the leak originated.
If it's just my email, I don't care at all.
The cols (ive only loaded the US version) seem to be cell_phone | fb_id | first_name | last_name | gender | lives | from | releationship_status? | works_at | ?some year month maybe date sms was given | email | bday?
> Breach date: 1 August 2019
> Date added to HIBP: 4 April 2021
Host: db.facebook.com
User: production
Password: password
Please don’t change any data!