Have I Been Facebooked?
haveibeenfacebooked.com
haveibeenfacebooked.com
"This is old data that was previously reported on in 2019. We found and fixed this issue in August 2019" - FB
Facebook leak: Irish regulator probes 'old' data dump: https://www.bbc.com/news/technology-56639081
I hope https://NOYB.eu is aware of this breach.
Of course Facebook, or even FAANG, for that matter, would keep all of the data that they hoarded from EU citizens, illegally. It goes along well with the Silicon Valley mentality (I am culturally American and I am from the west coast of the US, so I understand what is going on here. I also hold EU citizenship...)
The number one rule is "don't get caught". The "move fast and break things" mantra still holds well for Facebook. So, no surprise that they were sloppy with things, and got caught.
If you want to check if you were caught up in being Facebooked (data leaked), the download to the data dumps are here: https://archive.is/MZqak
I am furious at the moment because I found my (fraternal) twin brother's info in the data dump files. :-(
I doubt it. They spent 7 years on a case against Facebook doing the absolute minimum necessary. NOYB are suing the Irish DPC in an attempt to get them to do their jobs. It’s a mess. Irish DPC apparently only investigated 83 GDPR cases and over 4000 “concluded without inquiry”. They only made 11 data protection decisions last year, compared to 600 by Spain whose data protection branch has a similar budget.
https://noyb.eu/en/dpc-cancels-parliamentary-hearing-eu-us-t...
https://noyb.eu/sites/default/files/2021-03/Letter%20Max%20S...
https://noyb.eu/en/facebooks-gdpr-bypass-reaches-austrian-su...
I donate to NOYB because they are actually the ones making sure this stuff is enforced.
There are great articles on the Financial Times about GDPR, tech regulation, emerging technologies, etc., that are on the spot. I remember one stating that all of the regulatory agencies for data protection in all of the respective EU countries were understaffed. It gave a great visual.
apparently both my ideas were wrong but good thing i don't use any facebook property, don't use whatsapp or isntagram and am a hermit. I had telegram since 2015 but since signal whatsapp thing happened, i stopped using it. :-/
Since the storage of data is so cheap, any company will archive data, for future profit.
Why did you believe any data will be deleted in the first place? Were you counting that government will take action if it finds out? Are there any case like this in the past.
I find it surprising even programmers believe their data will be deleted by the company.
Most people even programmers believe a company will delete their data. Whats your background? Are you a coder?
Ethics? Morals? That is what we would expect from "delete my account".
1(b) is 'withdrawal of consent', but note also 1(c), which refers to article 21, which allows subjects to object, and you should (as a controller) have 'compelling legitimate grounds' to continue processing (which is a higher standard than 'legitimate interests', which can be the basis for processing the data in the first place).
With that said my details do not appear to have leaked.
To clarify: in 2019 you could enter a phone number into Facebook search and it would show you whichever profile was associated with the number of it was set to public.
The “hackers” set up a script to go through every number sequentially: 15550000000, 15550000001, etc.
I would be very surprised if the original data doesn’t contains a LOT more information —- basically everything that can be found by publicly viewing your profile page.
Cleaning that up is a serious effort and requires operations on huge files that are very difficult for most software to deal with.
I can get all the phone numbers myself with a simple `cat * | cut -d ":" -f 1`
If that's literally all you want, yes, it's not that hard. But a non-trivial number of people decided to put commas or colons in their names and other nonsense like that, there are lots of commas in the hometown or location fields which makes parsing those a pain, etc.
There only ones that actually define the data are the 9 or so CSV files that have a header like:
id,phone,first_name,last_name,email,birthday,gender,locale,hometown,location,link
Those are what I looked at and those are super annoying because several have commas in both the first & last name. I don't know why, but a handful of people listed their names as some, guy, some, guy which I assume should be split into firstname: some, guy and lastname: some, guy. Then a lot of people have None for a birthday, some have something like May 8, and others have something like May 8, 1990. Both locale & hometown can be either None, or have several commas in them.
I had to reformat all that data and validate that each field made sense to parse it. There are helpful "Location" and "link" markers in the CSV but it's still super annoying to parse this stuff.
That said, the actual files are in fairly shabby shape and quite tedious to clean for DB import. They may have missed thousands of records.
Heck. Allow even prehashed phone number to be entered.
The only way to check without giving up personal info is to get the data and look locally, or perhaps search for so many phone numbers that yours is buried in the haystack.
(Assuming seeing hacked numbers are public already - but I don’t love this either)
What’s a secure way of searching without disclosure by either party? (Non troll question)
Download the original data set. US records are around a GB file.
I, too, am wary of Facebook but to other people, without reasoning provided, this sounds like FUD. Maybe at least link to an article explaining why they should be concerned anyway.
It's not like they care even a bit. And they wouldn't win any goodwill from it. If you have been zucked, you've been zucked, that is it.
Zuck: Just ask.
Zuck: I have over 4,000 emails, pictures, addresses, SNS
[Redacted Friend's Name]: What? How'd you manage that one?
Zuck: People just submitted it.
Zuck: I don't know why.
Zuck: They "trust me"
Zuck: Dumb f**s.
A good solution to this would be to put a hiring freeze on any ex-Facebooker and claim that if they can overlook Facebook's questionable practices, then they would be a danger for your company and its customers.
Hold employees responsible for the actions of their employer.
You could institute a "two year freeze" for any FB alum. A public statement by an ex-employee rebuking these practices would be enough to sidestep the hiring moratorium, but make them acknowledge how bad their employer is for privacy and democracy.
Especially after what they did with the last US election cycle.
Should we also institute public lynching of all employees of companies that had security breaches?
This isn't about a security breach. Facebook is a horrible company and has damaged the world with its unique stances on privacy and data gathering.
> Wow, you spend really a lot of effort on virtue signaling.
By what measure?
I really don't want anyone who is willing to sacrifice their morals around personal privacy and the integrity of our democracy working for me.
If and when I do get the opportunity to hire someone from Facebook to work for me, I will ask them why they worked at Facebook, what they think of the company's ethics, and if they did anything to make the company better for the world.
Perhaps some folks check their ethics at the door when they show up for work, but ethics matter. They don't become unimportant or irrelevant choices in light of our paycheck.
Choosing to work for Facebook says a lot about a person.
This idea sounds uncannily familiar for anyone from the former Soviet bloc.
I don’t particularly like Facebook or any big corporation FYI.
I don't like it, but it makes some level of sense from their perspective. We tend, globally, to prefer "gentle swat on the back of the hand" level penalties for companies that have behaved terribly.
GDPR allows for fines of up to 4% of global revenue. Unfortunately the agencies that are supposed to enforce it are too feeble to do so.
Interestingly my phone number seems to have been exposed but not my e-mail address. I don't recall providing my phone number to Facebook although I do recall explicitly being asked to. I do however use WhatsApp. I wonder if there's more to this.
Edit: Replying again- sorry. Thinking about this some more-- if the person were to concatenate the number with first last or something they could distribute the list and the person's name would be the salt. So 9195551212JohnDoe becomes $hash and user just has to know all the pieces to test locally.
One downside of a record-specific salt is nicknames e.g. john vs johnathan , or misspellings. (false negatives)
https://en.m.wikipedia.org/wiki/K-anonymity is likely a better approach to prevent that, which other similar sites like https://haveibeenpwned.com/ are already doing for the email addresses.
An adequately hashed set can be proved to be harmless because you can't revert to real data (as far as you know when downloading). Downloading the original set could be considered malicious by some governments (but idk/ not sure ianal).
Just enter your email and the site will tell you whether your email has been harvested by https://haveibeenfacebooked.com/
I could see the "big-data" value of that information if they managed to get a significant proportion of the population to check this website, but even that would be barely worth the effort.
Other than Troy Hunt being well known and building a reputation on being a white hat security guy.
In the world of data the only thing you can trust in absolute terms is encryption. Anything else involving people involves shades of grey.
We can be pretty sure the results are legit but yes of course it could be running malicious code and stealing phone numbers. Check the raw data if you are worried[2].
[1] https://github.com/Fumaz/haveibeenfacebooked-api [2] https://archive.is/MZqak
No need to give out your phone number if you registered via email.
My concern is all the people that may have involuntarily signed up via whatsapp, with no email included but only a phone number.
I checked my phone # with the above site and it came up clean.
AFAIK most of the records in the leak didn't have an email attached.
Anyhow, my phone number had a hit and they showed my first and last initial and corresponding asterisks; seems legit.
For people saying "why enter your phone number into random site" -- not sure how much value a phone number provides without the accompanying information.
Edit: I just checked, seems like the form on the frontpage of HIBP also submits your complete email/phone number. Pretty sure I read about how you don't have to submit your personal data to validate against HIBP, not to long ago...
[0]: https://github.com/Fumaz/haveibeenfacebooked-api/blob/master...
Still, if I had to chose between hibf.com and hibp.com, I'd lean to hibp.com since Troy is a known name in the industry and has offered this service for a long time without any complaints.
So why enter your info on a random site? Because it may be the lowest (definitely not zero) risk way to check if your info is in the leak. If you wait or you build your own thing you may risk less, but balancing the risk with the certainty of obtaining an answer requires a real level of expertise.
Does seem like an easy way to collect phone numbers.
I purchased my first FB ad in late summer 2007. Not sure if that’s also when it opened up.
Like most things, it took a few years to really take off. They IPO'd in 2012, and then really had to prove they could turn a profit (and increase it over time). I've honestly not been a heavy enough Facebook user to be able to pin the transition to a particular point in time (and it was almost certainly a long period of time, pushing for more and more), but the transition of the "Like" widget on random pages from an image icon to a data collection tool was probably a good indication of the transition.
In any case, by... oh, 2014 or so at the latest, they'd definitely started showing their true colors. Engagement Uber Alles. Because ads.
Facebook, long ago, stopped being about connecting people (except that claiming this gets more people to join), and more about "keeping people on Facebook as long as they possibly could" - because that means more ad impressions, which means more money for Facebook.
They rely on every quirk in human psychology to keep people addicted ("engaged") and scrolling as long as possible. Intermittent reward, randomized ordering (the refresh throbber followed by "new" content), and driving people into toxic emotions and rabbit holes. Anger, outrage, and conspiracy rabbitholes are /great/ for keeping people on the site. They're terrible for the people involved (one could offer the handwaving parallel of a grocery store offering free heroin if you buy stuff there to keep people shopping), but profitable for Facebook.
They believe the entire internet is theirs to scrape user activity from (the "like" buttons were turned into data collection elements long ago, against the original promises made about them), so they can offer better-targeted advertisements to anyone who has a valid credit card. Foreign actor, scammer, seller-of-medical-nonsense, it's all fine - as long as they pay up properly.
And in a wide variety of cases of Facebook being fingered as directly responsible for enabling reprehensible behavior like genocides, their responses are consistently, "We are so, so sorry that you caught us doing that, and we promise to try harder not to get caught in the future." Genocide is extremely engaging, and as long as they can sell ads to people othering their neighbors and calling for violence against them, well, what's wrong?
The guiding principle of Facebook has been clearly demonstrated to be, "What's Good for Zuck is Good for Zuck!" Anything else is secondary (and mostly a concern in that if you don't do anything, people might get around to cancelling their accounts or no longer using Facebook).
I can, and do, apply these criticisms to a number of other properties on the internet, but the social media companies (companies who take user-generated content, repackage it, and algorithmically deliver it in optimally engaging order to other people, interleaved with ads) are the parts of the internet that are demonstrably ruining just about everything that people care about.
> They're not much more evil than any other publicly traded
Ok, that's basically my point, but people seem adamant that they are somehow exceptionally evil.
> content repackager
> companies who take user-generated content, repackage it
What do you mean by taking user-generated content and repackaging it? I understand that users often do this themselves, but what exactly is Facebook repackaging?
> "default location" for a lot of people to go when bored
For me this is HN
> keep people addicted
This does seem evil, if the product is causing the user harm.
> They believe the entire internet is theirs to scrape user activity
I could see how this bothers people, though it doesn't bother me that much personally. Follow-up question: do you view Fullstory as evil?
> Facebook being fingered as directly responsible for enabling reprehensible behavior
To me, this is a sad misuse of a tool. But yes, efforts should be made to limit the tool's possibility for evil usage.
They are more directly responsible for keeping people in a mentally toxic {outraged, angry, upset} state than most other companies. Their reach far exceeds Twitter (2.5B active users vs about 180M for Twitter), so I'll consider them "more evil" in that they have a far greater reach. While I may have plenty of bones to pick with Google, Amazon, etc, they don't directly influence mental state for their own profit like Facebook does.
> What do you mean by taking user-generated content and repackaging it?
Facebook, Twitter, Instagram, Snapchat, YouTube, etc, do not (meaningfully) generate their own content (yes, you'll see an occasional Facebook blog post usually saying "We're sorry for getting caught this time..." but that's not their primary purpose). They take content that their end users generate (photos, posts, links, etc), and repackage it, reorder it, inject ads, and deliver it to other people.
This is distinct from other content producers (news sites, blogs, etc) in which the site owners/employees/etc are the primary generators of material. I write content for my blog, and while I host and deliver the occasional user comment, the primary purpose of my blog is for me to communicate my thoughts to other people. I also, after several years of experimentation, now do so in an ad-free manner, because the small returns weren't worth the hassle, and I'm increasingly opposed to an ad-supported internet, so I now self-host my content and pay my hosting fees out of pocket.
> For me this is HN
Yes, but HN doesn't matter. It is also neither ad supported or, to the best of my knowledge, a public company (at least the HN interface). It's exceedingly low bandwidth and I quite like it as a remnant of an old style of internet that no longer really exists.
> Follow-up question: do you view Fullstory as evil?
I don't know what Fullstory is, so have no opinion on it.
> But yes, efforts should be made to limit the tool's possibility for evil usage.
Or to respond meaningfully when it's demonstrated that the tool is being used for it. Facebook tends to the minimum required to look like they've done something, and when someone else points out that the people the filters are aimed at have trivially bypassed them by changing the spelling of a word, Facebook throws up their hands and says, "Well, moderation is hard, we can't afford humans, and AI sucks, so... sorry!"
If you're too big to have meaningful human moderation that can understand nuance, maybe you're just too big as a forum/site/community/etc.
I started to write a number of counterpoints, then I realized it might not get us anywhere together. Perhaps it comes down to the way that I view web services: it's just a platform. Since Facebook is such a large platform, the evil parts of human nature will certainly be evident there. I'm aware that the "it's just a platform" viewpoint isn't for everyone. With that said, it's hard for me to leave that camp without carrying a lot of cognitive dissonance with me.
Is Ethereum evil because Vitalik doesn't spawn a fork every time innocent people get scammed out of their money (why only do it once (DAO hack)?)? Is Bitcoin evil because it allows people to evade taxes, hurting society? Do you think government should moderate the internet once AI can handle that task? I hope these aren't seen as strawman scenarios.
All the numbers that I know for sure to be in the leak return "not found in the leak" on this site.
1) no indication that there's any rate limiting here beyond a 2 second cooldown (thanks for that, grenoire), but I only tested it using burp intruder community edition, and I only tested it on a set of numbers guaranteed to return false. If anyone wants to test a range with a known-leaked number in it, up to you.
2) it's very possible that if there is rate limiting, it acts invisibly.
But if there's no rate limiting as I suspect, someone can easily just iterate through this data set and extract every number (well, until cloudflare trips the requests). Alternatively, someone can request a large set of numbers that includes their own in order to fuzz the range their own number is in.
So far all the posts I've seen on HN that link directly or indirectly to places you can actually download it are to copies on ufile.io, which limits download speed to 500 Kbps if you aren't paying.
If you don't want your phone number leaked don't hand it over to a random website that pinky swears it won't keep it. It's maybe not a scam, but still...
Convince me why I should be!
People are saying you shouldn’t put a number in there because if it’s not already in there, you are leaking some kind of privileged information.
That’s not true.
So putting your phone into a website also ties it to your identity.
What's the worst they can do with it? Call me all hours of the day trying to sell me an extended factory warranty for my free Medicare brace that, by the way, has a Security Number that is under arrest by the Security Administration because it made fraudulent IRS payments with iTunes gift cards to lower my student loan payments because I didn't listen when Microsoft called about my Windows Virus?
Oh, wait, sorry, it hung up on me after dialing because their call center was full. Even if they answer, they just won't play anymore - as soon as they think you might be messing with them (or just aren't going to buy whatever they're selling), they hang up. Twenty years ago, you could have an hour long conversation with the credit card people if you were bored...
Even with spam blockers in place, that sort of garbage is the bulk of the calls my phones get. At least for my personal phone, I live in a different area code from where the phone is (insert XKCD about your area code being where you lived in 2002), so anything that's my phone's area code and not in my contact list is clearly unwelcome.
Phone numbers just aren't a large space to randomly dial looking for valid numbers if you're on a scum VOIP gateway, and clearly the scammers and spammers already have lists of what might be worth calling.
In a world where
your bank thinks that SMS is good enough for 2FA...
phone number plus other info is good enough for credit reporting agencies to send out your complete file...
Variations of this theme.
Also, this dump is once more confirmation that Facebook owns lots of data about its users, and doesn't care to protect that data, or to give its users the ability to control personal information. Why should they care? They suffer no consequences for this lack.
And, certainly, Facebook suffers no consequences. A while back, some people noticed that if a company was in the news for a catastrophic data breech, their stock tended to climb immediately afterwards. No such thing as bad press coverage, at least in the age of the trading algorithms!
I found FastPeopleSearch.com, which not only had my current phone number and physical address, but my previous cell phone number, land lines (from back when those were a thing), my Vonage phone number, and previous addresses, all dating about 20 years. If you know my name, you can get a lot more... thanks to these aggregators of public records.
You can attempt to have yourself removed but there are a lot of these types of sites.
Of course, if you take "a" phone number, and use the google search technique, you'll find one of those sites like FastPeopleSearch and learn a lot more about who the phone number belongs to. But presumably anyone who's trying to make use of all this information could do all that without the Facebook breach, if they automate the process.
Of course, the Facebook breach ties a bunch of information to a phone number in a, perhaps, tidy package?
no problemo
https://www.thenewseachday.com/private-facebook-phone-number...
The view of the sensitivity of phone numbers and home address as PII has changed with this trend too.
That being said, I think the cat is out of the bag on this one so maybe that wouldn’t be the end of the world.
What's the harm in publishing a list of phone numbers, without any other info attached? I can generate a list of all phone numbers in north america by iterating through all the digits.
[1] https://en.wikipedia.org/wiki/List_of_North_American_Numberi...
So there's some ambiguity or incompleteness somewhere.
Searches use partial data from multiple fields to find matches.
- i trust my browser and site owner version : text in clear
- i barely trust site owners ( if a match is found they still have access the fact that I've verified that number ) :
hash each phone address hashed ie using bcrypt and using a composed salt ( ie : site address + email in the account + phone address ) so rainbow table will be impossible to use ( this because phone numbers are low entropy and even without rainbow table IMO are not that very secure )
than ask user for the hashed version in the text field ( also write a linux terminal style command that can be used to hash given salt and hashing , or redirect to a trusted hasher service online (multiple links can be provided ) )
both text fields can be provided to allow the user a choice
Maybe I can finally get my last couple of friends to switch to Signal.
They should instead hash your number client side and test the hash.
I'd use that but not searching by phone number.
Has Facebook ever been safe to use?
AFAIK there isn't much awareness about this leak amongst most of FB's userbase: Less tech-savvy and 40yrs ++.
:: squints ::
I'll grant you, this is much more problematic for some than me. But for me, this is, roughly, analogous to my actual LinkedIn, Github, or Hacker News profile, which link to my resume (which has my phone number), combined with a squint at my age and a guess.
There's a lot worse that could be leaked.